Gridinsoft Logo
File Icon

Audiggle-.exe Backdoor Bladabindi Analysis

Technical Analysis

File Name audiggle-.exe
File Type
PE32 executable (GUI) Intel 80386, for MS Windows
Scanner Version 1.0.151.174
Database Version 2023-12-13 18:01:17 UTC

Backdoor.Win32.Bladabindi.sm!s1

Malware family: Bladabindi

Bladabindi, also known as NjRat, is a Remote Access Trojan providing unauthorized system control. Developed by the M38dHhM group, it has been used in campaigns targeting Middle Eastern regions.
N/A
Detection Rate
1,893,367
File Size (bytes)
2023-12-13
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
03e48a4f45e53886d90a2937f57043c8
SHA1
2faefda885f3e105dc76163d7e4d3000cec3bd74
SHA256
9f0bee1b09eda958e7bb865f54d700c9f33d1d750aa97de8a88583e593e7f4f7
SHA512
b6eb30d744f34e39b9c6354b806120e9d30727f06fcbbd63b6eeeb56f50be6a6b16b4ba72509c51618efaddf14a1b443f4851b5f1d952c54885e8386081d9665
ImpHash
18a8f1cc88bfbadd72d06bfd1a86f94c

PE Analysis

Basic Information

Icon
Hash: d67a7ec1e541b5497a10c4225c394c22
Fuzzy: c5dace78993d50eaedeb05b7c48ce608
dHash: 848c5454baf47474
Image Base 0x00400000
Entry Point 0x00407481
Compilation Time 2005-03-17 10:31:50
Checksum 0x00000000 (Actual: 0x001d14de)
OS Version 4.0
PEiD Signatures PE32 executable (GUI) Intel 80386, for MS Windows
Digital Signature The PE file does not contain a certificate table.
Imports 3 libraries
KERNEL32, USER32, SHELL32
Exports 0 functions
Resources 7 Resources
Sections 4 Sections

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 49,477 bytes 53,248 bytes 6.39 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 416803C8E7A321BD1C7C135529D38DFF
.rdata 0x0000e000 5,552 bytes 8,192 bytes 4.53 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 74792A6EDA080BB87FCB87593DBEF177
.data 0x00010000 27,140 bytes 20,480 bytes 2.12 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE AA0800B2E408F3065D6C8B1F861CB8E9
.rsrc 0x00017000 6,120 bytes 8,192 bytes 2.63 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 4ECB4F2527A84BB97B057776E1AC6382

Resource Analysis

Total Resources: 7 (5,632 bytes)
Resource Type Count Total Size Percentage
RT_BITMAP 1 1,256 bytes
22.3%
RT_ICON 1 3,240 bytes
57.5%
RT_DIALOG 3 1,044 bytes
18.5%
RT_STRING 1 72 bytes
1.3%
RT_GROUP_ICON 1 20 bytes
0.4%

Certificate Chain Analysis

No Digital Signatures

This file is not digitally signed.

Security Implications:
  • Cannot verify the publisher's identity
  • Increased security risk when running this file
  • May trigger security warnings on some systems

⚠ This file either lacks a digital signature or the certificate chain could not be verified
Exercise caution when executing unsigned files from unknown sources

Certificate Verification Status

The PE file does not contain a certificate table.

Recommendation: Verify the file source and ensure it comes from a trusted publisher.

Backdoor.Win32.Bladabindi.sm!s1 Removal

Gridinsoft has the capability to identify and eliminate Backdoor.Win32.Bladabindi.sm!s1 without requiring further user intervention.

Download Anti-Malware

Removal Instructions

Follow these steps to completely remove the threat from your system

  1. Start by downloading Gridinsoft Anti-Malware to your computer.
  2. Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  3. Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  4. Click on the "Standard Scan" button to begin scanning your computer for threats.
  5. After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  6. If prompted, restart your system to complete the removal process and ensure all threats are eliminated.
Important: Before You Start
Disconnect from the internet to prevent the malware from spreading or downloading additional threats. Run the scan in Safe Mode for better detection and removal of persistent threats.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware