Malware

About “Bulz.10532” infection

Malware Removal

The Bulz.10532 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.10532 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Bulz.10532?


File Info:

crc32: 64B0AE55
md5: 6527e1a2e5d4be9672fd737a0c42e80f
name: 6527E1A2E5D4BE9672FD737A0C42E80F.mlw
sha1: 726d88bf4624089a7f2a33a91e1f5fa737d8ab06
sha256: 7c385533aee54b90a7d263a37f68839b127666ccec967dcd2a27b352b1fdc42a
sha512: 5110eb54f1be4e68470ad65baccbac67ff4e2f74770849ea3c83feb648a28668993c88f102cc37102159386b3d0811f98211534b85b6fd1692b51b8eda167ebe
ssdeep: 6144:DgqgePVH0pwpMQEFGQz/eI8+8nDvX72t7:0qgePVH0ppQGGK8n767
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.10532 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0052c8a31 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.10532
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaBackdoor:Win32/Farfli.bef818a9
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.2e5d4b
CyrenW32/Trojan.STNT-7676
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Farfli.PZ
APEXMalicious
AvastWin32:Agent-BBBO [Trj]
ClamAVWin.Dropper.Ramnit-7076131-0
KasperskyBackdoor.Win32.Farfli.bwaa
BitDefenderGen:Variant.Bulz.10532
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Variant.Bulz.10532
Ad-AwareGen:Variant.Bulz.10532
SophosMal/Generic-R + Mal/ResDro-B
BitDefenderThetaGen:NN.ZexaF.34770.pCX@auJBemQ
VIPRETrojan-Dropper.Win32.Resdro.b (v) (not malicious)
TrendMicroTROJ_GEN.R005C0DFP21
McAfee-GW-EditionBehavesLike.Win32.Emotet.dc
FireEyeGeneric.mg.6527e1a2e5d4be96
EmsisoftGen:Variant.Bulz.10532 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor/Farfli.te
AviraHEUR/AGEN.1121023
eGambitUnsafe.AI_Score_57%
MicrosoftTrojan:Win32/Farfli.DSK!MTB
ArcabitTrojan.Bulz.D2924
AegisLabTrojan.Win32.Farfli.m!c
ZoneAlarmBackdoor.Win32.Farfli.bwaa
GDataGen:Variant.Bulz.10532
AhnLab-V3Trojan/Win32.Zegost.R105172
Acronissuspicious
McAfeeBackDoor-EXZ
MAXmalware (ai score=85)
VBA32BScope.Trojan.StartServ
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R005C0DFP21
RisingTrojan.Generic@ML.97 (RDML:ZaTZF4HKwhuxBsc++eRFnQ)
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FV!tr.ransom
AVGWin32:Agent-BBBO [Trj]
Paloaltogeneric.ml

How to remove Bulz.10532?

Bulz.10532 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment