Malware

What is “Generic.MSIL.Bladabindi.EA4A6C14”?

Malware Removal

The Generic.MSIL.Bladabindi.EA4A6C14 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.EA4A6C14 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the njRat malware family
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.EA4A6C14?


File Info:

name: 3C0C556FF3C9A3329347.mlw
path: /opt/CAPEv2/storage/binaries/2bfae4a30797d4b64f129a2edb5340a31628edb5c7370fa427ff9484a0ce2ec2
crc32: 4DF93B70
md5: 3c0c556ff3c9a33293473f88ed1e1406
sha1: f053e012e68c6030502833403cbce54fa274d2c6
sha256: 2bfae4a30797d4b64f129a2edb5340a31628edb5c7370fa427ff9484a0ce2ec2
sha512: 28898af9ceb61b46ce177eb1d3478ec398abf58629a75c442151bdceae41d0083bb46156d98aceeed21acc52d2e18de32abf1ad34bf40910768199bd868338d1
ssdeep: 384:ImevEiTblvpWNcZ0y8fJCtTHVGLkC+xlrAF+rMRTyN/0L+EcoinblneHQM3epzXR:1eBTZ38fJCtT0d+LrM+rMRa8NuK6t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E4032B4D7FE18168C5FD057B05B2D412077AE04B6E23DA1E8EF664AA37636C18B50EF2
sha3_384: 139a161707a70683ac4036fae5b10ecf1527780a4b57a14cd9bedbfc0867f9459854f42e4fef8074d0686b84a2306fd1
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-08-12 13:51:17

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.EA4A6C14 also known as:

BkavW32.AIDetectNet.01
DrWebTrojan.MulDrop6.35381
MicroWorld-eScanGeneric.MSIL.Bladabindi.EA4A6C14
FireEyeGeneric.mg.3c0c556ff3c9a332
CAT-QuickHealBackdoor.Bladabindi.B3
ALYacGeneric.MSIL.Bladabindi.EA4A6C14
MalwarebytesBackdoor.NJRat
ZillyaTrojan.Bladabindi.Win32.72266
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.ff3c9a
BitDefenderThetaGen:NN.ZemsilF.34592.cmW@aSReF3b
VirITTrojan.Win32.DownLoader21.BPQW
CyrenW32/MSIL_Troj.AP.gen!Eldorado
SymantecBackdoor.Ratenjay!gen3
ElasticWindows.Trojan.Njrat
ESET-NOD32a variant of MSIL/Bladabindi.AR
APEXMalicious
ClamAVWin.Packed.Bladabindi-7994427-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.EA4A6C14
NANO-AntivirusTrojan.Win32.Autoruner2.ebrjyu
AvastMSIL:Bladabindi-JK [Trj]
TencentTrojan.Msil.Bladabindi.fa
Ad-AwareGeneric.MSIL.Bladabindi.EA4A6C14
TACHYONBackdoor/W32.DN-NjRat.37888.AE
EmsisoftWorm.Bladabindi (A)
ComodoTrojWare.MSIL.Spy.Agent.CP@4pqytu
BaiduMSIL.Backdoor.Bladabindi.a
VIPREGeneric.MSIL.Bladabindi.EA4A6C14
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Backdoor.nm
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Bbindi-W
IkarusTrojan.MSIL.Bladabindi
GDataMSIL.Trojan-Spy.Bladabindi.BQ
JiangminTrojanDropper.Autoit.dce
WebrootW32.Gen.BT
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASBOL.A8F4
ArcabitGeneric.MSIL.Bladabindi.EA4A6C14
ViRobotBackdoor.Win32.Agent.37888.AL
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi.B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Korat.R207428
Acronissuspicious
McAfeeTrojan-FIGN
MAXmalware (ai score=85)
CylanceUnsafe
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Bladabindi.AS!tr
AVGMSIL:Bladabindi-JK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.EA4A6C14?

Generic.MSIL.Bladabindi.EA4A6C14 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment