Malware

Generic.MSIL.Bladabindi.E515A91A (file analysis)

Malware Removal

The Generic.MSIL.Bladabindi.E515A91A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.E515A91A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the Njrat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.E515A91A?


File Info:

name: 0A4F6CD4018D5D5E067F.mlw
path: /opt/CAPEv2/storage/binaries/ddd4134e82926c8521eb6edea74a050363ea9b818b0428ab6e259a27eca8bed0
crc32: 85D8FC6C
md5: 0a4f6cd4018d5d5e067f3dab0f1fab7f
sha1: ffc9a5a2bff9fcad1b422aeb2f312086a5d06460
sha256: ddd4134e82926c8521eb6edea74a050363ea9b818b0428ab6e259a27eca8bed0
sha512: 891e0810b0cf5187640552d8bcceaab31996a693af99445ff0b1ae0a03ece2fc8325a944dbfc44b2a8c7023158f5b615fa6c3dec14e983c33ef95cd5d01bf001
ssdeep: 384:5CbsiDFT95hL5YyUvDB/ROC4a6IXlrAF+rMRTyN/0L+EcoinblneHQM3epzXgNrj:YZv5zUvDBDl6OlrM+rMRa8NuuHt
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T198F2294D7BE1856CC5FE067B05B2E4130776E04F5E23D90D8EE6A4AA37636C18F50AE2
sha3_384: 69fe17cad1ba7a5454175449da2a51588ba8ea4f924cd50e5eda634eccf6782a9a13c405085f0375f65bab7fb54fb16c
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-11-12 08:15:44

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.E515A91A also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGeneric.MSIL.Bladabindi.E515A91A
FireEyeGeneric.mg.0a4f6cd4018d5d5e
CAT-QuickHealTrojan.GenericFC.S19436243
ALYacGeneric.MSIL.Bladabindi.E515A91A
MalwarebytesBackdoor.NJRat
ZillyaTrojan.Bladabindi.Win32.37874
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.4018d5
BitDefenderThetaGen:NN.ZemsilF.34784.ciW@aCOkI1n
VirITTrojan.Win32.DownLoader21.BPQW
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AR
BaiduMSIL.Backdoor.Bladabindi.a
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.E515A91A
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
AvastMSIL:Bladabindi-JK [Trj]
TencentTrojan.Msil.Bladabindi.fa
Ad-AwareGeneric.MSIL.Bladabindi.E515A91A
EmsisoftGeneric.MSIL.Bladabindi.E515A91A (B)
ComodoTrojWare.MSIL.Spy.Agent.CP@4pqytu
F-SecureTrojan.TR/ATRAPS.Gen
DrWebTrojan.DownLoader22.5085
VIPREGeneric.MSIL.Bladabindi.E515A91A
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Bbindi-W
APEXMalicious
GDataMSIL.Trojan-Spy.Bladabindi.BQ
AviraTR/ATRAPS.Gen
MAXmalware (ai score=82)
ArcabitGeneric.MSIL.Bladabindi.E515A91A
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:MSIL/njRAT.RDSA!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Korat.R213361
Acronissuspicious
McAfeeTrojan-FIGN
VBA32Downloader.MSIL.gen
ZonerTrojan.Win32.84773
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
IkarusTrojan.MSIL.Bladabindi
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.E515A91A?

Generic.MSIL.Bladabindi.E515A91A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment