Malware

What is “Generic.MSIL.Bladabindi.FD676319”?

Malware Removal

The Generic.MSIL.Bladabindi.FD676319 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.MSIL.Bladabindi.FD676319 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • CAPE detected the njRat malware family
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Generic.MSIL.Bladabindi.FD676319?


File Info:

name: C269C3BACBA635732908.mlw
path: /opt/CAPEv2/storage/binaries/7b797804337e648eceda209805e79af552129870413cd3b776b8eddcfe5542f4
crc32: 844CADFA
md5: c269c3bacba635732908e21a0d48afad
sha1: fe713c540778ff4700a41e2797668754cb378288
sha256: 7b797804337e648eceda209805e79af552129870413cd3b776b8eddcfe5542f4
sha512: 714eba609ba2c4a0dd3f455eb451595b8f455ae485f1f3a178d63c016e392819e4df5778c3405f7074bc76ebadb932ac2ac65e1a95c8ad47707794e34463dc83
ssdeep: 768:gjMXjwpJbb2zxxO56eqvPisfv8yQmIDUu0tiNEj:3kKdisvQVkbj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4E21B6DFBEA4466D1BD0AB50571950007B8D103E523F77E4ECA24A62B6F3C84B88DF2
sha3_384: 5d11837f477e03b9999341b1eabaefe8b62d7ec332ceffc8883e80e2eeb43d314c2e90511c7f307d950ea595b51bc846
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-07-30 10:00:23

Version Info:

0: [No Data]

Generic.MSIL.Bladabindi.FD676319 also known as:

BkavW32.AIDetectNet.01
ElasticWindows.Trojan.Njrat
CynetMalicious (score: 100)
CAT-QuickHealTrojan.GenericFC.S20328680
McAfeeBackDoor-NJRat!C269C3BACBA6
MalwarebytesGeneric.Trojan.Malicious.DDS
ZillyaTrojan.Bladabindi.Win32.99141
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.acba63
BaiduMSIL.Backdoor.Bladabindi.a
VirITBackdoor.Win32.Bladabindi.XIP
CyrenW32/MSIL_Bladabindi.A.gen!Eldorado
SymantecMSIL.Trojan!gen2
ESET-NOD32a variant of MSIL/Bladabindi.AS
APEXMalicious
ClamAVWin.Packed.Generic-9795615-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGeneric.MSIL.Bladabindi.FD676319
NANO-AntivirusTrojan.Win32.Gen8.ecsqgn
MicroWorld-eScanGeneric.MSIL.Bladabindi.FD676319
TencentTrojan.Msil.Bladabindi.fb
Ad-AwareGeneric.MSIL.Bladabindi.FD676319
SophosML/PE-A + Mal/Bladabi-D
ComodoBackdoor.MSIL.Bladabindi.BA@7oej5x
F-SecureTrojan.TR/Dropper.Gen7
DrWebBackDoor.Bladabindi.15771
VIPREGeneric.MSIL.Bladabindi.FD676319
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.BackdoorNJRat.nm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.c269c3bacba63573
EmsisoftGeneric.MSIL.Bladabindi.FD676319 (B)
SentinelOneStatic AI – Malicious PE
GDataMSIL.Trojan-Spy.Bladabindi.BQ
JiangminTrojan/Refroso.dep
AviraTR/Dropper.Gen7
MAXmalware (ai score=85)
Antiy-AVLTrojan[Backdoor]/MSIL.Bladabindi.as
ArcabitGeneric.MSIL.Bladabindi.FDDA51DF
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:MSIL/Bladabindi
AhnLab-V3Trojan/Win32.Bladabindi.R130484
Acronissuspicious
VBA32Trojan.Downloader
ALYacGeneric.MSIL.Bladabindi.FD676319
TACHYONBackdoor/W32.DN-NjRat.32256
CylanceUnsafe
PandaTrj/GdSda.A
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.AvsMofer.dd6520
IkarusTrojan.MSIL.Bladabindi
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.LI!tr
BitDefenderThetaGen:NN.ZemsilF.34806.bmW@a4swTQb
AVGMSIL:Bladabindi-JK [Trj]
AvastMSIL:Bladabindi-JK [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Generic.MSIL.Bladabindi.FD676319?

Generic.MSIL.Bladabindi.FD676319 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment