Categories: Malware

Bulz.2321 (file analysis)

The Bulz.2321 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.2321 virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Bulz.2321?


File Info:

crc32: 5FE504C7md5: 1528ce6a3f3fa724b1571828308b1b42name: 1528CE6A3F3FA724B1571828308B1B42.mlwsha1: 1a0045443ade63610b2a15949d328f4cbbbaef80sha256: 425683479d9f3bf85f4746fa709b0f9b23efc1b013907528ed5c5c20882ef3d4sha512: e7692bf835a8a376e8516c24200fbf60a7d5641f23aa38817c2483f4edce2ebc7a7d227d92ef23fd040284ed806b64a3f384ff1a7ef17fd247e94cf4afc197dessdeep: 12288:TEuOSwfOiRNwFD7LERnoSUEA2yfz44b0F4CvCsAaYAjXY9aD5wyN:TzOSeOiKERoSUEx4bC6crh5wyNtype: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0LegalCopyright: Copyright xa9 2017Assembly Version: 1.0.0.0InternalName: WindowsFormsApplication4.exeFileVersion: 1.0.0.0CompanyName: LegalTrademarks: Comments: ProductName: WindowsFormsApplication4ProductVersion: 1.0.0.0FileDescription: WindowsFormsApplication4OriginalFilename: WindowsFormsApplication4.exe

Bulz.2321 also known as:

Lionic Trojan.Win32.Generic.4!c
Elastic malicious (high confidence)
Cynet Malicious (score: 99)
ALYac Gen:Variant.Bulz.2321
Cylance Unsafe
Zillya Backdoor.Bladabindi.Win32.21184
Sangfor Trojan.Win32.QQHelper.1
CrowdStrike win/malicious_confidence_100% (W)
Alibaba Backdoor:MSIL/Bladabindi.b8c090b6
Cybereason malicious.a3f3fa
Cyren W32/MSIL_Bladabindi.GV.gen!Eldorado
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of MSIL/Packed.PvLogNetProtector.E suspicious
APEX Malicious
Avast Win32:Malware-gen
ClamAV Win.Packed.Razy-9858748-0
Kaspersky HEUR:Backdoor.MSIL.Bladabindi.gen
BitDefender Gen:Variant.Bulz.2321
NANO-Antivirus Trojan.Win32.PvLogNetProtector.elpbba
MicroWorld-eScan Gen:Variant.Bulz.2321
Tencent Msil.Backdoor.Bladabindi.Dvpw
Ad-Aware Gen:Variant.Bulz.2321
Sophos Mal/Generic-S
Comodo Malware@#1vkaewtm2jfp1
BitDefenderTheta Gen:NN.ZemsilF.34266.Ku0@aS2wo8e
VIPRE Trojan.Win32.Generic!BT
McAfee-GW-Edition GenericRXEY-OW!1528CE6A3F3F
FireEye Generic.mg.1528ce6a3f3fa724
Emsisoft Gen:Variant.Bulz.2321 (B)
SentinelOne Static AI – Malicious PE
Webroot W32.Trojan.Gen
Avira HEUR/AGEN.1122329
Kingsoft Win32.Troj.Generic_a.a.(kcloud)
Microsoft Backdoor:MSIL/Bladabindi!rfn
GData Gen:Variant.Bulz.2321
AhnLab-V3 Malware/Win32.Generic.C1785210
McAfee GenericRXEY-OW!1528CE6A3F3F
MAX malware (ai score=81)
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.Perseus
Panda Trj/GdSda.A
Yandex Trojan.GenAsa!zsAvxQWEPXk
Fortinet MSIL/Generic.AP.C2704A!tr
AVG Win32:Malware-gen
Paloalto generic.ml

How to remove Bulz.2321?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

BScope.Trojan.VBCR.1912 removal tips

The BScope.Trojan.VBCR.1912 is considered dangerous by lots of security experts. When this infection is active,…

37 seconds ago

Zusy.542015 (B) removal guide

The Zusy.542015 (B) is considered dangerous by lots of security experts. When this infection is…

11 mins ago

Malware.AI.3876614151 (file analysis)

The Malware.AI.3876614151 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Should I remove “Generic.Dacic.94CCEEA9.A.01DEBE39”?

The Generic.Dacic.94CCEEA9.A.01DEBE39 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

How to remove “Malware.AI.2670838656”?

The Malware.AI.2670838656 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Malware.AI.3626015347 removal

The Malware.AI.3626015347 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago