Malware

Should I remove “Bulz.140578”?

Malware Removal

The Bulz.140578 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.140578 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the zgRAT malware family

How to determine Bulz.140578?


File Info:

name: A775AABFD1A41A7DCC13.mlw
path: /opt/CAPEv2/storage/binaries/24cb48ae638677b3763e0987e5d2220a859b2f03472e2cf67f6b6a82a44f0bef
crc32: 231197C0
md5: a775aabfd1a41a7dcc13aade497c8e41
sha1: 6d6840e9d6900d82493f99389a54edc8f09f7f39
sha256: 24cb48ae638677b3763e0987e5d2220a859b2f03472e2cf67f6b6a82a44f0bef
sha512: 17696762408144917d0d89ca095b5e14c4a3fa8963a674d392d822be0b3afb0f133c016242403569938abfeb9cb64792147b207e6d980f5564121e857233bfdd
ssdeep: 49152:cEEVH+i7YN29+XkxxCwhNStxZk0EyFMITsh2FDPuAxpRCBad:cEEh3vOkxxkMVexv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E0268E1237E89A62C1AF1B36E4B2092403F6ED066666F70E2DD9719F1C537578E00B6F
sha3_384: 55fbd00015dd398b172c66d2699e1d1efbc3daffb232e15909f2a31dd0eee88e190cda2717d4debc5014ef5bbe1371c8
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-09-13 07:16:59

Version Info:

Translation: 0x0000 0x04b0
Comments: https://www.facebook.com/8591PostBot
CompanyName:
FileDescription: 8591PostBot
FileVersion: 3.9.6.4
InternalName: 8591PostBot.exe
LegalCopyright: Copyright © 2010-2022 黑豹
LegalTrademarks: Panther
OriginalFilename: 8591PostBot.exe
ProductName: 8591PostBot
ProductVersion: 3.9.6.4
Assembly Version: 21.9.13.15

Bulz.140578 also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
McAfeeArtemis!A775AABFD1A4
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Bulz.140578
ArcabitTrojan.Bulz.D22522
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
AlibabaTrojanPSW:MSIL/Agensla.ba9aeff9
MicroWorld-eScanGen:Variant.Bulz.140578
Ad-AwareGen:Variant.Bulz.140578
EmsisoftGen:Variant.Bulz.140578 (B)
TrendMicroTROJ_GEN.R002C0WIL21
McAfee-GW-EditionArtemis!Trojan
FireEyeGen:Variant.Bulz.140578
MaxSecureTrojan.Malware.300983.susgen
AviraHEUR/AGEN.1134953
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.140578
ALYacGen:Variant.Bulz.140578
VBA32TScope.Trojan.MSIL
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002C0WIL21
SentinelOneStatic AI – Suspicious PE
FortinetW32/Agensla!tr.pws
AVGWin32:Malware-gen
AvastWin32:Malware-gen

How to remove Bulz.140578?

Bulz.140578 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment