Malware

How to remove “Marsilia.89611”?

Malware Removal

The Marsilia.89611 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Marsilia.89611 virus can do?

  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Marsilia.89611?


File Info:

name: 52F991E0FE817A8B2DF4.mlw
path: /opt/CAPEv2/storage/binaries/eb81992f96e09191e64c79fcfa2aab4d52c7f2985ba2af7717043f478149340b
crc32: 18CC8D7D
md5: 52f991e0fe817a8b2df42a83a2eb19f8
sha1: b90da62af0f3735869f6e2a13e0ad3de979f5a4a
sha256: eb81992f96e09191e64c79fcfa2aab4d52c7f2985ba2af7717043f478149340b
sha512: 66f73d0a58a93ef91c211780057e5402fc337077a6524aceb822d0f05e73d6e93628c3987a311c26efb4975d565eb01d60757dd3db62dad5f3fc5776afbc5187
ssdeep: 3072:H4ZZ1zyAaywf6drwkYKdu8mUsizYdReIth:HOdanf6drwkYKdsizYyI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T183E3B68C7BE1AF25CB890730D053550497609D2C3F936387AA6B7CB4297326BBD6588F
sha3_384: 3aa0428985db4692a61334bb125f695f9713fd1043f01876b83dd094e12c481d3411c513a00a8cf1330e1c74bf4bd756
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-11-08 16:20:36

Version Info:

0: [No Data]

Marsilia.89611 also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Marsilia.89611
FireEyeGeneric.mg.52f991e0fe817a8b
SkyhighBehavesLike.Win32.AdwareDoma.ch
ALYacGen:Variant.Marsilia.89611
Cylanceunsafe
ZillyaTrojan.Bladabindi.Win32.154062
SangforSuspicious.Win32.Save.a
AlibabaTrojan:MSIL/Bladabindi.0a5e324d
K7GWTrojan ( 700000121 )
K7AntiVirusTrojan ( 700000121 )
BitDefenderThetaGen:NN.ZemsilF.36802.imW@aOSvK8l
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of MSIL/Bladabindi.CG
APEXMalicious
TrendMicro-HouseCallTrojan.MSIL.MSIL.USBLDI24
AvastWin32:RATX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Marsilia.89611
NANO-AntivirusTrojan.Win32.Bladabindi.kdkxcj
TencentMalware.Win32.Gencirc.13f67943
EmsisoftGen:Variant.Marsilia.89611 (B)
BaiduMSIL.Backdoor.Bladabindi.a
F-SecureTrojan.TR/Dropper.Gen7
DrWebTrojan.MulDrop24.13046
VIPREGen:Variant.Marsilia.89611
TrendMicroTrojan.MSIL.MSIL.USBLDI24
Trapminesuspicious.low.ml.score
SophosTroj/Bbindi-W
MAXmalware (ai score=80)
GDataGen:Variant.Marsilia.89611
GoogleDetected
AviraTR/Dropper.Gen7
VaristW32/MSIL_Kryptik.KBL.gen!Eldorado
Antiy-AVLTrojan/MSIL.Bladabindi
Kingsoftmalware.kb.c.1000
XcitiumTrojWare.MSIL.Bladabindi.BGS@7lngf6
ArcabitTrojan.Marsilia.D15E0B
ViRobotTrojan.Win.Z.Bladabindi.144896
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftBackdoor:Win32/Bladabindi!ml
AhnLab-V3Trojan/Win32.Agent.C210949
McAfeeBackDoor-FDNN!52F991E0FE81
MalwarebytesBackdoor.NJRat
PandaTrj/Chgt.AD
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
IkarusBackdoor.MSIL
FortinetMSIL/Bladabindi.CG!tr
AVGWin32:RATX-gen [Trj]
DeepInstinctMALICIOUS
alibabacloudRansomWare:MSIL/Bladabindi.AS

How to remove Marsilia.89611?

Marsilia.89611 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment