Malware

Bulz.221364 removal guide

Malware Removal

The Bulz.221364 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.221364 virus can do?

  • Creates RWX memory
  • Unconventionial binary language: Polish
  • Unconventionial language used in binary resources: Polish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Binary compilation timestomping detected

How to determine Bulz.221364?


File Info:

name: BB92861AFA747E44F485.mlw
path: /opt/CAPEv2/storage/binaries/4a602fcde571e77a8b77077a1107035dec7916f6a807a6ae91de14c6c2791daf
crc32: 1E791596
md5: bb92861afa747e44f48539c758afbbc2
sha1: ba59f969608a7b3874b9cb6dc203ca76ebdb3087
sha256: 4a602fcde571e77a8b77077a1107035dec7916f6a807a6ae91de14c6c2791daf
sha512: c3cab49e16aa48f8abebdab13caaba9fb3167466baceb6a1cb253603733086ac2f22256f12bf9455100b7775ae592f032b4199738e731144ee35b34deb834e7f
ssdeep: 98304:X7x/wHv1oUdhy2x2GJXHSN/mut23rbt5++jchI+GvDXflI1WSDCEL9qe8w99YqGg:XNwHvOrEa9tQ3jGLGrfa1W89/8wfBn
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1926622FD6288375CC42EC4B09437AD44B2B5D52D17DAA5AEB2C77AE03BA6430E603F51
sha3_384: 209928d1517b725b3ea00db9e563677b7f50899aa32b2b3299e2d972066a038c0f0ebd53cef8d41033d8e83f5b7e157b
ep_bytes: 68d408c286e8115b0c0098da0bb19693
timestamp: 2062-07-25 12:18:00

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Samorozpakowujący się plik typu .cab Win32
FileVersion: 11.00.19038.1 (WinBuild.160101.0800)
InternalName: Wextract
LegalCopyright: © Microsoft Corporation. Wszelkie prawa zastrzeżone.
OriginalFilename: WEXTRACT.EXE .MUI
ProductName: Internet Explorer
ProductVersion: 11.00.19038.1
Translation: 0x0415 0x04b0

Bulz.221364 also known as:

LionicRiskware.Win32.Generic.1!c
Elasticmalicious (high confidence)
DrWebTrojan.Siggen15.50366
MicroWorld-eScanGen:Variant.Bulz.221364
FireEyeGeneric.mg.bb92861afa747e44
ALYacGen:Variant.Bulz.221364
K7AntiVirusTrojan ( 0054d6c01 )
AlibabaTrojanPSW:Win32/Disco.4265b52d
K7GWTrojan ( 0054d6c01 )
Cybereasonmalicious.afa747
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win64/Packed.VMProtect.FZ
TrendMicro-HouseCallTROJ_GEN.R002H06KM21
Paloaltogeneric.ml
KasperskyTrojan-PSW.Win32.Disco.hjb
BitDefenderGen:Variant.Bulz.221364
AvastWin64:Trojan-gen
Ad-AwareGen:Variant.Bulz.221364
EmsisoftGen:Variant.Bulz.221364 (B)
McAfee-GW-EditionBehavesLike.Win64.Generic.vc
SophosMal/Generic-S
IkarusTrojan.Win64.Vmprotect
JiangminRiskTool.Generic.ubr
GridinsoftRansom.Win64.Sabsik.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Bulz.221364
CynetMalicious (score: 100)
McAfeeBackDoor-FDOH!BB92861AFA74
MAXmalware (ai score=83)
VBA32Trojan.Sabsik.FL
APEXMalicious
TencentWin32.Trojan-qqpass.Qqrob.Phzu
eGambitUnsafe.AI_Score_94%
FortinetW64/BDoor.FDOH!tr
AVGWin64:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_80% (W)

How to remove Bulz.221364?

Bulz.221364 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment