Home Malware Programs Backdoors Backdoor.Bladabindi.B

Backdoor.Bladabindi.B

Posted: May 1, 2013

Threat Metric

Ranking: 2,816
Threat Level: 6/10
Infected PCs: 246,321
First Seen: May 1, 2013
Last Seen: October 17, 2023
OS(es) Affected: Windows

Aliases

not-a-virus:RiskTool.Win32.BitCoinMiner [Ikarus]Bitcoin Miner [Sophos]not-a-virus:RiskTool.Win32.BitCoinMiner.cns [Kaspersky]Generic32.CKXR [AVG]Troj/Agent-ABNT [Sophos]Trojan.Win32.Redyms.pix [Kaspersky]Win32:Rootkit-gen [Rtk] [Avast]Trj/Genetic.gen [Panda]Crypt_s.AVA [AVG]Trojan.Crypt_s [Ikarus]Dropper/Win32.Clons [AhnLab-V3]TR/Crypt.TPM.Gen [AntiVir]Backdoor.Win32.Agent.SPA [Comodo]Trojan-Dropper.Win32.Clons.zzx [Kaspersky]W32/Boaxxe.F2.gen!Eldorado [F-Prot]
More aliases (50)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\c5dbc4b5114eccb1261dfdb2194089a8.exe File name: c5dbc4b5114eccb1261dfdb2194089a8.exe
Size: 115.71 KB (115712 bytes)
MD5: 52e8d405637fbd963055823c15f0f9a1
Detection count: 337
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\c5dbc4b5114eccb1261dfdb2194089a8.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5f805e177fa7c673482c92c255460b67.exe File name: 5f805e177fa7c673482c92c255460b67.exe
Size: 200.7 KB (200704 bytes)
MD5: d313b3409a30ce1040ce3d010f4e4b99
Detection count: 84
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5f805e177fa7c673482c92c255460b67.exe
Group: Malware file
Last Updated: September 11, 2023
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e7519346edbd1261bb7e4084fb50cd6b.exe File name: e7519346edbd1261bb7e4084fb50cd6b.exe
Size: 16.89 KB (16896 bytes)
MD5: e4396258e2a50828a318f2d35785d93d
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\e7519346edbd1261bb7e4084fb50cd6b.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3008b25cd890618ead84115e2b073a47.exe File name: 3008b25cd890618ead84115e2b073a47.exe
Size: 202.24 KB (202240 bytes)
MD5: fd21ff54f5a33b5b37260814d0731c2a
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3008b25cd890618ead84115e2b073a47.exe
Group: Malware file
Last Updated: June 26, 2020
c:\Users\<username>\downloads\troj_generic_ebc5a6b5083f5b9a0d2e2aadfd2daa3d3697a23461c0cc40ff347672c75767d0.exe File name: troj_generic_ebc5a6b5083f5b9a0d2e2aadfd2daa3d3697a23461c0cc40ff347672c75767d0.exe
Size: 46.08 KB (46080 bytes)
MD5: d682acc4b6eae500dc3c908dbaedf519
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: c:\Users\<username>\downloads
Group: Malware file
Last Updated: April 19, 2019
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a0bd4888d482d751fa2518c73e7d2a9f.exe File name: a0bd4888d482d751fa2518c73e7d2a9f.exe
Size: 1.22 MB (1225160 bytes)
MD5: 5a33c50a8117f87ae4ef0da3bacfb12d
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a0bd4888d482d751fa2518c73e7d2a9f.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\62b4a7f32364bd20762dd3b30db01d93.exe File name: 62b4a7f32364bd20762dd3b30db01d93.exe
Size: 300.54 KB (300544 bytes)
MD5: 09d66712ca96bd1a7d627e66c60b2b9c
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\62b4a7f32364bd20762dd3b30db01d93.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cc6885fb771802b45c9dcc628f9ad989.exe File name: cc6885fb771802b45c9dcc628f9ad989.exe
Size: 709.63 KB (709632 bytes)
MD5: de479c9e92ecc1ac8447901cdce64bce
Detection count: 19
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\cc6885fb771802b45c9dcc628f9ad989.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5db5c656e6f615eba326e0e421c56c58.exe File name: 5db5c656e6f615eba326e0e421c56c58.exe
Size: 411.13 KB (411136 bytes)
MD5: 270c797a677b22b3f768350412969936
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\5db5c656e6f615eba326e0e421c56c58.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\79c3667e6e3ee30e7cbb11fd90ef9fe4.exe File name: 79c3667e6e3ee30e7cbb11fd90ef9fe4.exe
Size: 139.26 KB (139264 bytes)
MD5: fa3c14ca50dbc11e58800f1bdf462f5f
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\79c3667e6e3ee30e7cbb11fd90ef9fe4.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\69b5b7ca364f50a6f2ca0f32b9e3c064.exe File name: 69b5b7ca364f50a6f2ca0f32b9e3c064.exe
Size: 44.03 KB (44032 bytes)
MD5: 4c721d10ff63f1ec9bb0415a4a7a5c0e
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\69b5b7ca364f50a6f2ca0f32b9e3c064.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a5ab2dbc68c601545cd9a9946ac0b01c.exe File name: a5ab2dbc68c601545cd9a9946ac0b01c.exe
Size: 651.77 KB (651776 bytes)
MD5: 3715f2a674f9b3996b0309724188aa73
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\a5ab2dbc68c601545cd9a9946ac0b01c.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\9f192a1f8ea7e654ab7f4f6227bc120c.exe File name: 9f192a1f8ea7e654ab7f4f6227bc120c.exe
Size: 80.89 KB (80896 bytes)
MD5: 3770847fb83d43a0fa2c2a9cff45202f
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\9f192a1f8ea7e654ab7f4f6227bc120c.exe
Group: Malware file
Last Updated: November 8, 2021
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f683abc40afcb2fb0f4a33d15709c9b7.exe File name: f683abc40afcb2fb0f4a33d15709c9b7.exe
Size: 1.81 MB (1813504 bytes)
MD5: 09604a0cc24b679da7cf9b2c0d576410
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\f683abc40afcb2fb0f4a33d15709c9b7.exe
Group: Malware file
Last Updated: January 12, 2022
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7d4366b7a274f87b26c436a0e40a9090.exe File name: 7d4366b7a274f87b26c436a0e40a9090.exe
Size: 24.06 KB (24064 bytes)
MD5: d62a817ace66b957d2602656b78d142f
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\7d4366b7a274f87b26c436a0e40a9090.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\db87ad7e45211040c408f1ad355e0739.exe File name: db87ad7e45211040c408f1ad355e0739.exe
Size: 220.16 KB (220160 bytes)
MD5: 9c809e09d971aab8c42f77f4fb5effd4
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\db87ad7e45211040c408f1ad355e0739.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\adf954c8b8af53ba18232ab9e7f642d4.exe File name: adf954c8b8af53ba18232ab9e7f642d4.exe
Size: 66.56 KB (66560 bytes)
MD5: c797a3bf5ed730a47d8324aed964bcc4
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\adf954c8b8af53ba18232ab9e7f642d4.exe
Group: Malware file
Last Updated: June 26, 2020
file.exe File name: file.exe
Size: 185.34 KB (185344 bytes)
MD5: 5ee9c9da29774358656354302309b2a9
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 22, 2019
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3409dfc64132b6ba26c828455e34860f.exe File name: 3409dfc64132b6ba26c828455e34860f.exe
Size: 740.86 KB (740864 bytes)
MD5: d9d919762f8c1e45978a72b5a3992863
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3409dfc64132b6ba26c828455e34860f.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\50a6ceecce3b6e575a63bbcea6a2bd9e.exe File name: 50a6ceecce3b6e575a63bbcea6a2bd9e.exe
Size: 326.29 KB (326296 bytes)
MD5: bdfe70f9e4ab1b1437f130ebc2afd08c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\50a6ceecce3b6e575a63bbcea6a2bd9e.exe
Group: Malware file
Last Updated: June 26, 2020
%SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3098dbecbe29b36c4c0e9641f6559743.exe File name: 3098dbecbe29b36c4c0e9641f6559743.exe
Size: 151.04 KB (151040 bytes)
MD5: 038b69aee6c4f0d6585e11cb3db633d6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3098dbecbe29b36c4c0e9641f6559743.exe
Group: Malware file
Last Updated: June 26, 2020

More files

Registry Modifications

The following newly produced Registry Values are:

Regexp file mask%ALLUSERSPROFILE%\images[RANDOM CHARACTERS].exe%ALLUSERSPROFILE%\smss.exe%ALLUSERSPROFILE%\System.exe%ALLUSERSPROFILE%\system32.exe%APPDATA%\ Explorer.exe%APPDATA%\.pif%APPDATA%\Documento Pdf.exe%APPDATA%\GoogleCrashHandler.exe%APPDATA%\Java\JavaUpdtr.exe%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Server.exe%APPDATA%\Microsoft\Windows\Start Menu\Startup\DetaUp.exe%APPDATA%\trof.exe%APPDATA%\WindowsServices.exe%APPDATA%\wored.exe%HOMEDRIVE%\Java update.exe%HOMEDRIVE%\svchost.exe%TEMP%\ Explorer.exe%TEMP%\audiodef.exe%TEMP%\sam.exe%USERPROFILE%\google.exe%USERPROFILE%\svchost.exe%USERPROFILE%\system[NUMBERS].exe%WINDIR%\win32.exeHKEY..\..\..\..{RegistryKeys}SOFTWARE\e936a10f968ac948cd351c9629dbd36dSOFTWARE\Microsoft\Tracing\JavaUpdtr_RASMANCSSOFTWARE\Wow6432Node\Microsoft\Tracing\JavaUpdtr_RASMANCS
Loading...