Malware

Bulz.154197 information

Malware Removal

The Bulz.154197 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.154197 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The executable is compressed using UPX
  • Attempts to create or modify system certificates

Related domains:

z.whorecord.xyz
a.tomx.xyz
user.xunfss.com

How to determine Bulz.154197?


File Info:

crc32: 48C0FACE
md5: 39bfad4118e1742ceee9e0a5cbfc041b
name: 39BFAD4118E1742CEEE9E0A5CBFC041B.mlw
sha1: f4fc62cbcc7463dd601743d8f901f64d6638bebb
sha256: 0fe286bdee0ef9e3d8313222735ad34a7ac358de8308137220e7a70459d49ed7
sha512: 180afc4919fa405aa23b272e6f2b3016edda6c02bf1e0ab8455f73429ae18c1f13e6445faf60c5d37a8a4162a901c3fb2fb2c52f5cc3914fca0f7f7a5ba066b4
ssdeep: 1536:/bmmEbPMz9Kw1krBCgrByCpCDiT0MvQ/yMFCyG+TWBT1/BgjCZRDw+rB2tNK:+bM0w1krHrUdBMRMnG+C7/2aRDwAwtY
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

Translation: 0x0804 0x04b0
InternalName: x6700x65b0x5730x5740
FileVersion: 1.00
CompanyName: 1024
ProductName: x6700x65b0x5730x5740
ProductVersion: 1.00
OriginalFilename: x6700x65b0x5730x5740.exe

Bulz.154197 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.154197
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderGen:Variant.Bulz.154197
Cybereasonmalicious.118e17
SymantecML.Attribute.HighConfidence
APEXMalicious
MicroWorld-eScanGen:Variant.Bulz.154197
Ad-AwareGen:Variant.Bulz.154197
SophosML/PE-A
FireEyeGeneric.mg.39bfad4118e1742c
EmsisoftGen:Variant.Bulz.154197 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_92%
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataGen:Variant.Bulz.154197
MAXmalware (ai score=84)
MalwarebytesMalware.AI.1442062647
TrendMicro-HouseCallTROJ_GEN.R005H09EA21
RisingMalware.Heuristic!ET#83% (RDMK:cmRtazrXOayEf95GYMX6orPITI4F)
FortinetPossibleThreat.PALLAS.H

How to remove Bulz.154197?

Bulz.154197 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment