Malware

Bulz.172352 information

Malware Removal

The Bulz.172352 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.172352 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.172352?


File Info:

crc32: 0B84FF7D
md5: 2354179bad198cea7b503c7d04cbde86
name: 2354179BAD198CEA7B503C7D04CBDE86.mlw
sha1: 1867bce6c62796dd34acc102351ff1374015f1f3
sha256: 1a2a65b20d2e6a7355030868bbe7387d54e6b755e054ab8448024c7f27f71ce8
sha512: b56ea5106f937787414c787bc22e669f6b8f7c3a5e6fb3c3a98ed0edb8bc69fb41d478068cb3422dfee17c94c901dff626071369dad2321b0dee4b6c79d5c2af
ssdeep: 12288:WSXMipasXMnpa/fQE+03qw9SBG3x7bG/ltR4SUC7pbLz7:WSXMipasXMnpa/fQq6wX3xIkSxtbT
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: botz
FileVersion: 1.01
CompanyName: botz
Comments: Special Thanks to MaskingTape for 99% of the fullscreen code =)
ProductName: botz
ProductVersion: 1.01
OriginalFilename: botz.exe

Bulz.172352 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0053404f1 )
LionicTrojan.Win32.Macrodrop.b!c
DrWebTrojan.Trick.45128
ClamAVWin.Dropper.TrickBot-9864226-0
ALYacGen:Variant.Bulz.172352
CylanceUnsafe
ZillyaTrojan.Injector.Win32.607566
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanDropper:Win32/Macrodrop.727837db
K7GWTrojan ( 0053404f1 )
Cybereasonmalicious.bad198
CyrenW32/S-80c7a63e!Eldorado
SymantecPacked.Generic.558
ESET-NOD32a variant of Win32/Injector.DYPA
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Macrodrop.fo
BitDefenderGen:Variant.Bulz.172352
NANO-AntivirusTrojan.Win32.Trick.fdvshq
MicroWorld-eScanGen:Variant.Bulz.172352
TencentMalware.Win32.Gencirc.10b4dcab
Ad-AwareGen:Variant.Bulz.172352
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZevbaF.34236.Em0@aGmqv0oi
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.gc
FireEyeGeneric.mg.2354179bad198cea
EmsisoftGen:Variant.Bulz.172352 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDropper.Macrodrop.as
AviraHEUR/AGEN.1133606
Antiy-AVLTrojan/Generic.ASMalwS.2690131
MicrosoftTrojan:Win32/Totbrick.H
SUPERAntiSpywareTrojan.Agent/Generic
GDataGen:Variant.Bulz.172352
TACHYONTrojan-Dropper/W32.VB-Macrodrop.495616
AhnLab-V3Trojan/Win32.Injector.R231019
McAfeeGenericRXFS-YP!2354179BAD19
MAXmalware (ai score=100)
VBA32TrojanDropper.Macrodrop
MalwarebytesSpyware.TrickBot
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!DpqhfRLSkUA
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.CCAH!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.172352?

Bulz.172352 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment