Malware

Generic.MSIL.Bladabindi.96526C6F malicious file

Malware Removal

The Generic.MSIL.Bladabindi.96526C6F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.96526C6F virus can do?

  • Uses Windows utilities for basic functionality
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the Njrat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Generic.MSIL.Bladabindi.96526C6F?


File Info:

name: B045DF870BEAF75A0509.mlw
path: /opt/CAPEv2/storage/binaries/29482660abef7056f0a78e8c9c264c143d04401920a7d1848b84c75c20cbc9f7
crc32: F45FFBCB
md5: b045df870beaf75a050949dfa1755037
sha1: 121babb5319f934e26a9bfbecfc50d9d09b81734
sha256: 29482660abef7056f0a78e8c9c264c143d04401920a7d1848b84c75c20cbc9f7
sha512: 887f782a7a677beaf7c2034bb54ab2e28172c354d6149e2c102648c841000972e97a36eadfe5d5a5a211f3783720a09314d8a57d6e53aec82d1877d39c76122a
ssdeep: 384:DZLZvjluAczvU8oHvloNFzTWK45ioTHJu3Wi2V9laJSEkLDOHYCFXPzlpmIMxTZf:DpZvjlu3vU8h+i8pVX1mF7s715
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C9E2F70537AA4703C62D03B94926471647F1CE434537EB5F1CD9F4ED1DBB7848A81AAB
sha3_384: 23e972a97daedfc5167efaec3f862eadd2f7a2c9ff448766653cbedd7063125b1147f6f62bd8942738d9fa602609f86e
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-08-05 16:19:40

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: k.exe
LegalCopyright:
OriginalFilename: k.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Generic.MSIL.Bladabindi.96526C6F also known as:

MicroWorld-eScanGeneric.MSIL.Bladabindi.96526C6F
CAT-QuickHealTrojan.GenericFC.S6059376
ALYacGeneric.MSIL.Bladabindi.96526C6F
Cylanceunsafe
ZillyaWorm.Bladabindi.Win32.7859
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004b99501 )
K7GWTrojan ( 004b99501 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZemsilF.36348.cm0@a89h12i
VirITTrojan.Win32.Dnldr25.PBI
CyrenW32/MSIL_Agent.CP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Autorun.Agent.LW
APEXMalicious
ClamAVWin.Trojan.Generic-6417450-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.96526C6F
SUPERAntiSpywareBackdoor.NJRat/Variant
AvastMSIL:Agent-CIB [Trj]
TencentTrojan.Win32.Bladabindi.16000442
EmsisoftGeneric.MSIL.Bladabindi.96526C6F (B)
BaiduMSIL.Backdoor.Bladabindi.a
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader25.15762
VIPREGeneric.MSIL.Bladabindi.96526C6F
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
FireEyeGeneric.mg.b045df870beaf75a
SophosMal/Bladabi-T
IkarusWorm.MSIL.Autorun
JiangminTrojanSpy.Agent.aaxh
GoogleDetected
AviraTR/ATRAPS.Gen
MicrosoftBackdoor:MSIL/Bladabindi.BO
XcitiumBackdoor.MSIL.Bladabindi.BSS@7pzdvl
ArcabitGeneric.MSIL.Bladabindi.96526C6F
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.Bladabindi.AV
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/NjRAT01.Exp
Acronissuspicious
McAfeeTrojan-FIGN
MAXmalware (ai score=85)
VBA32Trojan.MSIL.Bladabindi.Heur
MalwarebytesGeneric.Malware.AI.DDS
RisingBackdoor.njRAT!1.D4D6 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-CIB [Trj]
DeepInstinctMALICIOUS

How to remove Generic.MSIL.Bladabindi.96526C6F?

Generic.MSIL.Bladabindi.96526C6F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment