Malware

What is “ML/PE-A + Mal/Bladabi-O”?

Malware Removal

The ML/PE-A + Mal/Bladabi-O is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What ML/PE-A + Mal/Bladabi-O virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • CAPE detected the SpyGate malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Deletes executed files from disk
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Collects information to fingerprint the system

How to determine ML/PE-A + Mal/Bladabi-O?


File Info:

name: 4D58C8833B6BD81C8671.mlw
path: /opt/CAPEv2/storage/binaries/95ccda4a6997ba434f34469192c72227786de036d642baa882ac0a40d6d615c0
crc32: B373A7DB
md5: 4d58c8833b6bd81c86717da3c6fca30e
sha1: 0644c56c4c0503b961f81eb85ed05e8ff9df7f1c
sha256: 95ccda4a6997ba434f34469192c72227786de036d642baa882ac0a40d6d615c0
sha512: 0980b98f73ff84f660c495a80ab08fe0816fa716b81ba033fcdc0d29da2865613cd8b3f1812be6b2b879e2fa927d5e4d4893e369c30990b9d875826c8ecbd1c1
ssdeep: 1536:U/BmvfbW6FhRjOcR3hPoaEgem+x2AvXjO7HUEotQtGDewbWeP:U/29jL3hPo/FvXS7EQtGDDa+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T118A34B493BD46D21DAFE5FB90472050583B1D16F9A13EB8E1CC148E91BB7B844E42AE7
sha3_384: f6af60af52b8c774c842f40a1a7c5d125ea8410f0ab7a6e7bc56b118c1264bd42f417889510d5ef49b5cac31a9e1f714
ep_bytes: ff250020400000000000000000000000
timestamp: 2015-10-26 04:22:12

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Stub.exe
LegalCopyright:
OriginalFilename: Stub.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

ML/PE-A + Mal/Bladabi-O also known as:

BkavW32.AIDetectNet.01
LionicTrojan.Win32.Generic.m25O
MicroWorld-eScanGen:Heur.MSIL.Krypt.!cdmip!.2
ClamAVWin.Dropper.njRAT-7400469-0
FireEyeGeneric.mg.4d58c8833b6bd81c
CAT-QuickHealBackdoor.Bladabindi.AL3
ALYacGen:Heur.MSIL.Krypt.!cdmip!.2
CylanceUnsafe
ZillyaWorm.Bladabindi.Win32.11264
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
AlibabaTrojanPSW:MSIL/Mintluks.cb62cf0a
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduMSIL.Backdoor.Bladabindi.a
VirITTrojan.Win32.MSIL.JTO
CyrenW32/MSIL_Bladabindi.Z.gen!Eldorado
SymantecTrojan.Spygate
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.AT
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.MSIL.Krypt.!cdmip!.2
NANO-AntivirusTrojan.Win32.Agent.edqjjw
SUPERAntiSpywareTrojan.Agent/Gen-Keylogger
AvastMSIL:KillAV-B [Trj]
TencentTrojan.Win32.Bladabindi.16000442
Ad-AwareGen:Heur.MSIL.Krypt.!cdmip!.2
EmsisoftGen:Heur.MSIL.Krypt.!cdmip!.2 (B)
ComodoTrojWare.MSIL.Keylogger.A@57jrow
DrWebTrojan.PWS.Siggen1.12069
VIPREGen:Heur.MSIL.Krypt.!cdmip!.2
TrendMicroBKDR_BLADABI.SMC
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
Trapminemalicious.high.ml.score
SophosML/PE-A + Mal/Bladabi-O
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.biicj
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASBOL.A8F4
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftPWS:MSIL/Mintluks.A
ArcabitTrojan.MSIL.Krypt.!cdmip!.2
ViRobotTrojan.Win32.Z.Agent.98304.RU
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Backdoor.Bladabindi.AV
GoogleDetected
AhnLab-V3Trojan/Win32.Blocker.C228012
Acronissuspicious
McAfeeGenericRXDB-LZ!4D58C8833B6B
MalwarebytesBackdoor.InfoStealer
TrendMicro-HouseCallBKDR_BLADABI.SMR
RisingBackdoor.njRAT!1.9E49 (CLASSIC)
YandexTrojan.Krypt!9Zie+Fv6Olc
IkarusTrojan-PWS.MSIL
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/SpyPSW.AVQ!tr
BitDefenderThetaGen:NN.ZemsilF.34592.gm0@aCoM8ao
AVGMSIL:KillAV-B [Trj]
Cybereasonmalicious.33b6bd
PandaGeneric Malware

How to remove ML/PE-A + Mal/Bladabi-O?

ML/PE-A + Mal/Bladabi-O removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment