Malware

Bulz.206123 information

Malware Removal

The Bulz.206123 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.206123 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Bulz.206123?


File Info:

name: 1A85EC13814A11F0D673.mlw
path: /opt/CAPEv2/storage/binaries/3ff986af0cc357af89251d13a47c8f96a1394bf183d38681a9dfac6fb2fa9728
crc32: 44519EEC
md5: 1a85ec13814a11f0d673e794118fc8f7
sha1: 103d7bbec987559cebcda35e3f4de153246ab649
sha256: 3ff986af0cc357af89251d13a47c8f96a1394bf183d38681a9dfac6fb2fa9728
sha512: b6343cdeb1bcdf7fc831acf5e9d32ed6e1fc32a8a4966ef25fb4ec40a65e748c77dc4f7e1c3a6710bc81f44b9ddd5cbbe97651fa3d7a5d398502821bf8243eea
ssdeep: 49152:zFfAppg1b4KSXYOglbEsfgVDZQYvfPlhPbZ97tdKeUC/OLmoQtVDZQYvfPlhPbZP:xfA0uVSYL3zxOLtQtVSYL3zxOLtQK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T177568D22F241953EC8AB1576463F7524993EAB7127125CCB13E44DECDF366C02E3A68B
sha3_384: b32b63d7f7a8636cc0c58afc295e860b7361f351c83cea47bc3c7990eff256390130abac808bd9862980cd145cfd1882
ep_bytes: 558bec83c4f0b890a15d00e868e2e2ff
timestamp: 2020-07-15 14:12:22

Version Info:

FileDescription: patch
FileVersion: 1.0.0.0
ProgramID: com.embarcadero.patch
ProductName: patch
ProductVersion: 1.0.0.0
Translation: 0x0409 0x04e4

Bulz.206123 also known as:

LionicAdware.Win32.Generic.2!c
DrWebTrojan.PWS.Gamania.34950
MicroWorld-eScanGen:Variant.Bulz.206123
FireEyeGeneric.mg.1a85ec13814a11f0
ALYacGen:Variant.Bulz.206123
CylanceUnsafe
AlibabaTrojan:Win32/Occamy.7c9e5831
Cybereasonmalicious.3814a1
BitDefenderThetaGen:NN.ZedlaF.34606.ry4@aCfAvmf
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
TrendMicro-HouseCallTROJ_GEN.R02CC0DH221
Kasperskynot-a-virus:HEUR:AdWare.Win32.Generic
BitDefenderGen:Variant.Bulz.206123
AvastWin32:Malware-gen
RisingTrojan.Occamy!8.F1CD (CLOUD)
Ad-AwareGen:Variant.Bulz.206123
EmsisoftGen:Variant.Bulz.206123 (B)
F-SecureTrojan.TR/PSW.Gamania.yuejw
ZillyaTrojan.Gamania.Win32.228
TrendMicroTROJ_GEN.R02CC0DH221
McAfee-GW-EditionBehavesLike.Win32.CoinMiner.th
SophosMal/Generic-S
JiangminTrojan.Generic.caijt
AviraTR/PSW.Gamania.yuejw
MicrosoftTrojan:Win32/Occamy.C3F
GDataGen:Variant.Bulz.206123
CynetMalicious (score: 99)
McAfeeArtemis!1A85EC13814A
MAXmalware (ai score=85)
APEXMalicious
MaxSecureTrojan.Malware.300983.susgen
FortinetAdware/Generic
AVGWin32:Malware-gen
PandaTrj/GdSda.A
CrowdStrikewin/grayware_confidence_100% (W)

How to remove Bulz.206123?

Bulz.206123 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment