Malware

Generic.MSIL.Bladabindi.A1C1D326 information

Malware Removal

The Generic.MSIL.Bladabindi.A1C1D326 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.A1C1D326 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.A1C1D326?


File Info:

name: F6E197A1E5239B5C9038.mlw
path: /opt/CAPEv2/storage/binaries/77bef8becde2aef90cb02095f1752a713abaac74b8ac0470b1841a53bd1e6a8c
crc32: 6B9EA6C5
md5: f6e197a1e5239b5c903861e32ea8ff35
sha1: 7f31b3ab8dd64ecd5a6990c85dadc17e5a1a397f
sha256: 77bef8becde2aef90cb02095f1752a713abaac74b8ac0470b1841a53bd1e6a8c
sha512: edaa7fb873480bf9d76b693671aece64b4c2c310e006bcce2ae7d8cd08c695ef637b79f0a2b2e5401abc5dfd0f157d832411f12438a452dcbd1f448575480118
ssdeep: 6144:0oOcC5jODNl4SIQJdN3eLFROvA964250QEluD5o5/svyaY6q0UCtztIF:0oO3jOyQh3eqo980QEl1ayB6qfm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B2B4AD1ADA8CE905C64587F5D482B6708234CE047D228B6E240CBF665F727CB6E27B77
sha3_384: c161668a8625c9bbc767222fbdba4b52eab3bb21d294d30952ab9c530ad1b2eac3519758b713b94eb787990ec5bdff60
ep_bytes: ff25004043006c000000002000007470
timestamp: 2022-02-01 20:42:19

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: k.exe
LegalCopyright:
OriginalFilename: k.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Generic.MSIL.Bladabindi.A1C1D326 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGeneric.MSIL.Bladabindi.A1C1D326
FireEyeGeneric.mg.f6e197a1e5239b5c
CylanceUnsafe
VIPREBackdoor.MSIL.Bladabindi.a (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000001c1 )
BitDefenderGeneric.MSIL.Bladabindi.A1C1D326
K7GWTrojan ( 7000001c1 )
Cybereasonmalicious.1e5239
BitDefenderThetaGen:NN.ZemsilF.34212.Gu1@aauGt9b
CyrenW32/MSIL_Agent.BTF.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.DF
BaiduMSIL.Backdoor.Bladabindi.a
TrendMicro-HouseCallBKDR_BLADABI.SMC
ClamAVWin.Dropper.njRAT-7436651-0
KasperskyHEUR:Trojan.MSIL.Gorgon.gen
RisingBackdoor.Njrat!1.D4D6 (CLASSIC)
Ad-AwareGeneric.MSIL.Bladabindi.A1C1D326
EmsisoftGeneric.MSIL.Bladabindi.A1C1D326 (B)
ZillyaWorm.AutoRun.Win32.240141
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SophosML/PE-A + Mal/VMProtBad-A
APEXMalicious
GDataMSIL.Trojan-Spy.Bladabindi.BQ
AviraTR/Dropper.Gen
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.351DE01
ArcabitGeneric.MSIL.Bladabindi.A1C1D326
MicrosoftBackdoor:MSIL/Bladabindi.BO
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.RL_Bladabi.C4160976
VBA32Trojan.MSIL.Gorgon
ALYacGeneric.MSIL.Bladabindi.A1C1D326
MalwarebytesBackdoor.NJRat
IkarusPUA.VMProtect
PandaTrj/GdSda.A
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Agent.LI!tr
AVGMSIL:Agent-CIB [Trj]
AvastMSIL:Agent-CIB [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.MSIL.Bladabindi.A1C1D326?

Generic.MSIL.Bladabindi.A1C1D326 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment