Malware

Should I remove “Generic.MSIL.Bladabindi.B4A493E5”?

Malware Removal

The Generic.MSIL.Bladabindi.B4A493E5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.B4A493E5 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the njRat malware family
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.B4A493E5?


File Info:

name: 7F8053ABA03AA75DDA85.mlw
path: /opt/CAPEv2/storage/binaries/5298eabec01e99fa60e6e5978d024245d381a5902b4ddba112952256388ece75
crc32: CF10118C
md5: 7f8053aba03aa75dda85db8b41165297
sha1: 0b3206075e447d08e766f4d382e328d915ba1ef3
sha256: 5298eabec01e99fa60e6e5978d024245d381a5902b4ddba112952256388ece75
sha512: a32572bc4088a3f0835326b695cf50b22d8a4b007005468cc9b55a78a471e424c8425431263d2ecd42a8e99bffb1302e65aa72ee0086e589629611105b2a7691
ssdeep: 384:hslUlEvOEJ8xWwYJOMiOBZEdj1567gtwi5HhbQmRvR6JZlbw8hqIusZzZ6w:ieEvwIlLMRpcnuQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15BB22A0E3FB9C856C5AC177486A5965003B091470423EE2FCDC564DBAFB3BD92D48AF9
sha3_384: 3750bfd3de8c5fce0f54016d128cda1db17d525d75ed0763421d5c7f7b3064104c4fadb54a1240ce813db96f5744aebc
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-11 22:56:02

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.B4A493E5 also known as:

BkavW32.FamVT.binANHb.Worm
Elasticmalicious (high confidence)
ClamAVWin.Dropper.njRAT-7436651-0
CAT-QuickHealBackdoor.Bladabindi.AL3
McAfeeTrojan-FIGN
MalwarebytesBackdoor.NJRat
VIPREBackdoor.MSIL.Bladabindi.a (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.Bladabindi.B4A493E5
K7GWTrojan ( 700000121 )
Cybereasonmalicious.ba03aa
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Bladabindi.AU.gen!Eldorado
ESET-NOD32MSIL/Bladabindi.BH
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.Disfa.dtznyx
ViRobotBackdoor.Win32.Bladabindi.Gen.A
MicroWorld-eScanGeneric.MSIL.Bladabindi.B4A493E5
AvastMSIL:Agent-DRD [Trj]
Ad-AwareGeneric.MSIL.Bladabindi.B4A493E5
EmsisoftTrojan.Bladabindi (A)
ComodoBackdoor.MSIL.Bladabindi.A@566ygc
DrWebTrojan.DownLoader23.25967
ZillyaTrojan.Disfa.Win32.27264
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
FireEyeGeneric.mg.7f8053aba03aa75d
SophosML/PE-A + Troj/DotNet-P
IkarusTrojan.MSIL.Bladabindi
GDataMSIL.Backdoor.Bladabindi.AV
JiangminTrojanDropper.Autoit.dce
AviraTR/Dropper.Gen7
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASBOL.A8F4
KingsoftHeur.SSC.1608499.1216.(kcloud)
ArcabitGeneric.MSIL.Bladabindi.B4A493E5
MicrosoftBackdoor:MSIL/Bladabindi
AhnLab-V3Win-Trojan/Zbot.24064
Acronissuspicious
VBA32Trojan.MSIL.Disfa
ALYacGeneric.MSIL.Bladabindi.B4A493E5
TACHYONBackdoor/W32.DN-NjRat.24064.Y
CylanceUnsafe
TrendMicro-HouseCallBKDR_BLADABI.SMC
RisingBackdoor.Njrat!1.9E49 (CLASSIC)
YandexTrojan.Agent!28GjWDalpXI
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_100%
FortinetMSIL/Agent.LI!tr
BitDefenderThetaGen:NN.ZemsilF.34084.bmW@aCBx@Vc
AVGMSIL:Agent-DRD [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.MSIL.Bladabindi.B4A493E5?

Generic.MSIL.Bladabindi.B4A493E5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment