Malware

About “Bulz.130854” infection

Malware Removal

The Bulz.130854 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.130854 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (5 unique times)
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Farsi
  • The binary likely contains encrypted or compressed data.
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
telete.in
apps.identrust.com
cheapdealnow.top

How to determine Bulz.130854?


File Info:

crc32: F20FF708
md5: c38a0bfe426685005caec1f2689eb5bd
name: upload_file
sha1: 6b95f7249d59c00036f16d1d9ceffd523d31e624
sha256: 023476d2fca3e3304355e3c340d34dbb715b6c8d4957e8ffc368e58cef40aec1
sha512: 72a5ead18620c3302a86ca47e2e483c1ea84abeeb4c18f3eda522556ac269ad1616e0216c584dee918b6970f05cb9f2b2292ca63652810ce28acdd2b9cfd615f
ssdeep: 6144:AXilPiczitqTvCV49NM4jE7HEoFA6rlD0NdDevDEbpvnDHFclAop1oymxyxsnEFu:dYGvC0djSHGNdDevIbt5StNYsU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

FileV: 1.0.0.26
Translations: 0x0218 0x07a1

Bulz.130854 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Siggen10.33291
MicroWorld-eScanGen:Variant.Bulz.130854
FireEyeGeneric.mg.c38a0bfe42668500
McAfeeTrojan-FSUC!C38A0BFE4266
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Variant.Bulz.130854
K7GWTrojan ( 005701311 )
K7AntiVirusTrojan ( 005701311 )
BitDefenderThetaGen:NN.ZexaF.34298.MrZ@amD!ZGhG
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Zenpak.gen
Ad-AwareGen:Variant.Bulz.130854
F-SecureTrojan.TR/Crypt.Agent.krqyu
McAfee-GW-EditionBehavesLike.Win32.Generic.tz
EmsisoftGen:Variant.Bulz.130854 (B)
SentinelOneDFI – Malicious PE
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.Agent.krqyu
Antiy-AVLTrojan/Win32.Zenpak
MicrosoftTrojan:Win32/Wacatac.D0!ml
ArcabitTrojan.Bulz.D1FF26
ZoneAlarmHEUR:Trojan.Win32.Zenpak.gen
GDataGen:Variant.Bulz.130854
CynetMalicious (score: 100)
VBA32Backdoor.Mokes
ALYacGen:Variant.Bulz.130854
MAXmalware (ai score=89)
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Kryptik.HGND
RisingTrojan.Generic@ML.100 (RDML:RqgYKht64qpLcCVH5cfdSg)
eGambitUnsafe.AI_Score_70%
FortinetW32/Kryptik.HGNJ!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Bulz.130854?

Bulz.130854 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment