Malware

Bulz.204843 (file analysis)

Malware Removal

The Bulz.204843 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.204843 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to identify installed AV products by installation directory

How to determine Bulz.204843?


File Info:

name: D74A9B58114CD4E2FCC9.mlw
path: /opt/CAPEv2/storage/binaries/2e70e1228239794bebfc78daa3db6d31fe9716d4e9644b6bf23be519d9db719b
crc32: 717B67BA
md5: d74a9b58114cd4e2fcc95a3788baaebf
sha1: cb0edf9718cb6991c2865746da8a56bb485779c2
sha256: 2e70e1228239794bebfc78daa3db6d31fe9716d4e9644b6bf23be519d9db719b
sha512: 8ba94b022f96c2596453e04993184f179562649480a26c1beaaf08dccc7b106bc9bee5b32e9c3da35f7720c2eadbde8d4467f53fa8207b8fb1b68e20ff68f9fe
ssdeep: 196608:WbFXA6S/QSIFHvifFQj0m9dHz5g1NKI+8J5dWoTn8sn5011m72buYmbI/9h2KSf1:iNA6zSyHviOldT5g10Ibv5e1vCIFhCD5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18DC62277A210E02EC99D46B1C9B192F4A5772FB1E0264C5B43F83D0DFF759250FAA90A
sha3_384: c4426a03adaeae288c2d2aa77ce5eadbd799ec619ea569ed25a034b777e03cbd6e546334ffc5bcada4b75fe04d42f54f
ep_bytes: 558bec83c4a453565733c08945c48945
timestamp: 2020-05-21 05:56:23

Version Info:

Comments: This installation was built with Inno Setup.
CompanyName: Line Media Technologies Ltd.
FileDescription: S-Mobile Uploader Setup
FileVersion: 1.0.0.2
LegalCopyright:
OriginalFileName:
ProductName: S-Mobile Uploader
ProductVersion: 1.0.0.2
Translation: 0x0000 0x04b0

Bulz.204843 also known as:

LionicTrojan.Win32.Ekstak.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.204843
FireEyeGen:Variant.Bulz.204843
ALYacGen:Variant.Bulz.204843
CylanceUnsafe
SangforTrojan.Win32.Wacatac.C
AlibabaTrojanDropper:Win32/Ekstak.021e0ca1
K7GWTrojan ( 005722f11 )
K7AntiVirusTrojan ( 005722f11 )
CyrenW32/Agent.CDI.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/TrojanDropper.Agent.SLC
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Ekstak.ahgju
BitDefenderGen:Variant.Bulz.204843
NANO-AntivirusTrojan.Win32.Ekstak.ibnenh
AvastWin32:Trojan-gen
TencentWin32.Trojan.Ekstak.Wqms
Ad-AwareGen:Variant.Bulz.204843
EmsisoftGen:Variant.Bulz.204843 (B)
F-SecureHeuristic.HEUR/AGEN.1237233
DrWebTrojan.Zadved.1659
McAfee-GW-EditionBehavesLike.Win32.Dropper.wc
SophosMal/Generic-S
IkarusTrojan.Ekstak
GDataGen:Variant.Bulz.204843
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1237233
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Malware/Win32.RL_Generic.R355971
McAfeeArtemis!D74A9B58114C
MAXmalware (ai score=88)
VBA32Trojan.Zadved
MalwarebytesAdware.DownloadAssistant
MaxSecureTrojan.Malware.109553646.susgen
FortinetW32/Agent.SLC!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.8114cd
PandaTrj/CI.A

How to remove Bulz.204843?

Bulz.204843 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment