Malware

Bulz.230326 malicious file

Malware Removal

The Bulz.230326 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.230326 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Binary compilation timestomping detected

How to determine Bulz.230326?


File Info:

name: 4C129F8016ACCE4E843C.mlw
path: /opt/CAPEv2/storage/binaries/bfe6c282f9ed7254ccdd1e2c0cb60264337a91e4c0a7625098b481de0063ee14
crc32: 7D8F7839
md5: 4c129f8016acce4e843c00651790465d
sha1: b5b824d48929e40ee944a35f24c1223c1a75a6e5
sha256: bfe6c282f9ed7254ccdd1e2c0cb60264337a91e4c0a7625098b481de0063ee14
sha512: d25e4a2ebc6214311fb8b03ce5b0e09ea6768e97cc146547fe71d2a0bd3830725b5b43383f1cd334c71ce6c4c409e2b6852dd8aa03148e9657bed35153f24523
ssdeep: 6144:tyd/86M7AaTSHqxwH9L3UM0smsn79asxLjipR5yP+ITAQXjyJic+oIl1OzTyb8:tQ/nM7AaHuH9L3b07Qiph+AQcsoIl38
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10F258806DAC6CBD8EB47347AD5983269FB96E0C47DE7671118E062F070149AF1F2E4E2
sha3_384: 0c4206106f1750f69b44d1f299d4930d96c24f5d7432af430f1099d9d0ad73cdbf604ead30c49826bdb579fd16962e86
ep_bytes: ff250020400000000000000000000000
timestamp: 2047-07-29 18:28:10

Version Info:

Translation: 0x0000 0x04b0
Comments: Installer on my app
CompanyName: aucunes idee
FileDescription: HelloWorld
FileVersion: 3.1.3.2
InternalName: SystemNetwork.exe
LegalCopyright: Copyright © Ansrama 2020
LegalTrademarks:
OriginalFilename: SystemNetwork.exe
ProductName: Installer on my app
ProductVersion: 3.1.3.2
Assembly Version: 3.1.3.2

Bulz.230326 also known as:

LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PackedNET.27
MicroWorld-eScanGen:Variant.Bulz.230326
FireEyeGeneric.mg.4c129f8016acce4e
McAfeeArtemis!4C129F8016AC
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2662062
SangforTrojan.Win32.Wacatac.C
K7AntiVirusTrojan ( 004c77211 )
AlibabaTrojan:MSIL/Kryptik.0f4b4d35
K7GWTrojan ( 004c77211 )
Cybereasonmalicious.016acc
BitDefenderThetaGen:NN.ZemsilF.34212.7m0@aSL8YLd
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Kryptik.CQR
TrendMicro-HouseCallTROJ_GEN.R067C0WAC22
Paloaltogeneric.ml
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGen:Variant.Bulz.230326
AvastWin32:Trojan-gen
TencentMsil.Trojan.Dropper.Pcso
Ad-AwareGen:Variant.Bulz.230326
EmsisoftGen:Variant.Bulz.230326 (B)
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_GEN.R067C0WAC22
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Bulz.230326
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Ymacco.AABF
CynetMalicious (score: 99)
AhnLab-V3Win-Trojan/MSILKrypt15.Exp
ALYacGen:Variant.Bulz.230326
APEXMalicious
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:r+NKPBlV8aYjwh/j4GbGAA)
IkarusTrojan.MSIL.Crypt
eGambitUnsafe.AI_Score_84%
FortinetMSIL/Kryptik.CQR!tr
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.230326?

Bulz.230326 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment