Malware

Generic.MSIL.Bladabindi.91368951 information

Malware Removal

The Generic.MSIL.Bladabindi.91368951 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.91368951 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Guard pages use detected – possible anti-debugging.
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself

How to determine Generic.MSIL.Bladabindi.91368951?


File Info:

name: 4EBB89FDADF11B2C79B7.mlw
path: /opt/CAPEv2/storage/binaries/1b9506e0fcea4a7bb746be90141547c2b1808d7ed2fcf00dd63d6a55a811b428
crc32: 4E384BBA
md5: 4ebb89fdadf11b2c79b74090938bf4f7
sha1: b974c3d491fe2115345e92e0bcec29d44f5a969b
sha256: 1b9506e0fcea4a7bb746be90141547c2b1808d7ed2fcf00dd63d6a55a811b428
sha512: fded49196c19f881ddb7b8bc0af6c12ce7a93f293215151291977852200d19b173c3bc96a6171b18f2ffc2b0f2706189986f0c78b90d3e832a3f2925a6f267e0
ssdeep: 1536:0GHL1C8gerqjnmX+ykm4dtVkixnVR1upqv:jHLJrqjnmX+2Mt3nVRgq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14293F74D33E15065E2FD4AB3A870B2804FBAF0471742934D49E1A9B61B33AD88F54DBB
sha3_384: 5f84598b6e7dbcebcbdc2d69b8f2392932cef7ae15cc1699ac0208a93aba217ee0120482da86f93746e2326d1718982d
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-29 08:13:53

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.91368951 also known as:

BkavW32.AIDetectNet.01
ElasticWindows.Trojan.Njrat
DrWebBackDoor.BladabindiNET.25
MicroWorld-eScanGeneric.MSIL.Bladabindi.91368951
FireEyeGeneric.mg.4ebb89fdadf11b2c
CAT-QuickHealTrojan.YakbeexMSIL.ZZ4
ALYacGeneric.MSIL.Bladabindi.91368951
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusEmailWorm ( 00555f371 )
K7GWEmailWorm ( 00555f371 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.34806.fiW@a8hbE1
CyrenW32/Trojan.BVX.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.R
TrendMicro-HouseCallBackdoor.MSIL.BLADABINDI.SMJJ
ClamAVWin.Packed.Generic-9795615-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.91368951
AvastWin32:KeyloggerX-gen [Trj]
TencentTrojan.Win32.Bladabindi.16000442
Ad-AwareGeneric.MSIL.Bladabindi.91368951
EmsisoftGeneric.MSIL.Bladabindi.91368951 (B)
VIPREGeneric.MSIL.Bladabindi.91368951
TrendMicroBackdoor.MSIL.BLADABINDI.SMJJ
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusTrojan.MSIL.Bladabindi
AviraTR/Dropper.Gen
MicrosoftBackdoor:MSIL/Bladabindi.BN
ArcabitGeneric.MSIL.Bladabindi.D5722DF7
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataMSIL.Backdoor.Agent.AXJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.RL_Generic.C3443154
Acronissuspicious
McAfeeTrojan-FIDH!4EBB89FDADF1
MalwarebytesSimbot.Backdoor.Stealer.DDS
APEXMalicious
RisingBackdoor.njRAT!1.D4D6 (CLASSIC)
MAXmalware (ai score=84)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.LX!tr
AVGWin32:KeyloggerX-gen [Trj]
Cybereasonmalicious.dadf11

How to remove Generic.MSIL.Bladabindi.91368951?

Generic.MSIL.Bladabindi.91368951 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment