Malware

What is “Bulz.208358”?

Malware Removal

The Bulz.208358 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.208358 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Bulz.208358?


File Info:

crc32: FFD4228E
md5: 6650d9a3b27793b09c4e3c0068182d5f
name: 6650D9A3B27793B09C4E3C0068182D5F.mlw
sha1: 504703c07963ffbf9570424cb01b9163742a0a72
sha256: f89fc44879011d120ae4db4eb450ff875aadc38b501d9682ff7a03b168d05c47
sha512: a86b4cacf3e6cad13ecf06e7ab538e5142b440c85b9153a58ace7ce4e2918f0c51ab6c3d5a6f4761a1679b5defafeacad0901414545091cffd059975994e4239
ssdeep: 6144:bl1nTqNYzlnYU1JPs5vffaQHZPjWkv9sn+7BzUxW0pA+:b7qNWln3Ds9fCQHZPjWkv9sn/W0L
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 1.0.0.0
InternalName: Crypted.exe
FileVersion: 1.0.0
CompanyName: Ki
Comments: ConfuserEx
ProductName: ConfuserEx
ProductVersion: 1.0.0
FileDescription: ConfuserEx GUI
OriginalFilename: Crypted.exe

Bulz.208358 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Siggen12.9827
MicroWorld-eScanGen:Variant.Bulz.208358
FireEyeGeneric.mg.6650d9a3b27793b0
Qihoo-360Win32/TrojanDropper.Generic.HgIASPoA
ALYacGen:Variant.Bulz.208358
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005500731 )
BitDefenderGen:Variant.Bulz.208358
K7GWTrojan ( 005500731 )
BitDefenderThetaGen:NN.ZemsilF.34590.su0@ae!Ozpj
CyrenW32/Trojan.BVR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Packed.Ursu-7748951-0
KasperskyHEUR:Trojan-Dropper.MSIL.Generic
Ad-AwareGen:Variant.Bulz.208358
EmsisoftGen:Variant.Bulz.208358 (B)
F-SecureHeuristic.HEUR/AGEN.1101679
TrendMicroTrojan.Win32.Boilod.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1101679
MicrosoftTrojan:Win32/Wacatac.DF!ml
GridinsoftRansom.Win32.Somhoveran.vl!i
ArcabitTrojan.Bulz.D32DE6
ZoneAlarmHEUR:Trojan-Dropper.MSIL.Generic
GDataGen:Variant.Bulz.208358
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Bladabindi.C3085728
McAfeeArtemis!6650D9A3B277
MAXmalware (ai score=81)
VBA32CIL.HeapOverride.Heur
MalwarebytesTrojan.PasswordStealer
ESET-NOD32a variant of MSIL/Kryptik.QAT
TrendMicro-HouseCallTrojan.Win32.Boilod.SM.hp
IkarusTrojan.MSIL.Confuser
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Kryptik.QAT!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.208358?

Bulz.208358 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment