Malware

About “Bulz.238074” infection

Malware Removal

The Bulz.238074 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.238074 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Bulz.238074?


File Info:

name: 16AB404561CB28549094.mlw
path: /opt/CAPEv2/storage/binaries/d0c63be6797e7f245fb3a3c340365c12f1f51f8b40e70619267049db539bf5d6
crc32: FE927BA5
md5: 16ab404561cb28549094bb64f21cfb6c
sha1: 6fcda5f5d2eb6135c1867ccb3861398af5d87e87
sha256: d0c63be6797e7f245fb3a3c340365c12f1f51f8b40e70619267049db539bf5d6
sha512: 8b030bb8191a213e0d51917cd1f10883ec30b34258eba5f4ab3369839332a79d494ca2d61829639fba1f3a10cf0f9f270b597858bd653398a40a55068d4ba045
ssdeep: 49152:rOlEeyAxiMHweK8MTuYlnDV7D2voyDHdOJESZw6Gxz5GJghogWwE/K/wow1Gjg+c:rIWAxv8d2vFD9OJESlzbwL++A33
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T191166B50F9DB60F5F6074A3045A7A37F6330A6099738CBD7CA909FA6FC17AE10932256
sha3_384: b765524c7da8eafe782ead04ffa2e0e5a5b43f0e6007e69d7b25a7255e00ceb7b14b1090a17cf844b6981e4f12bf567a
ep_bytes: e90bdbffffcccccccccccccccccccccc
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Bulz.238074 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.238074
FireEyeGen:Variant.Bulz.238074
McAfeeArtemis!16AB404561CB
CylanceUnsafe
ZillyaTrojan.Udochka.Win32.49
SangforRansom.Win32.Filecoder.NZJ
K7AntiVirusTrojan ( 00570c7f1 )
AlibabaTrojan:Win32/Udochka.5487e379
K7GWTrojan ( 00570c7f1 )
Cybereasonmalicious.561cb2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.NZJ
APEXMalicious
Paloaltogeneric.ml
KasperskyTrojan.Win32.Udochka.gs
BitDefenderGen:Variant.Bulz.238074
NANO-AntivirusTrojan.Win32.Udochka.ignqpa
AvastWin32:Trojan-gen
EmsisoftGen:Variant.Bulz.238074 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.rh
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraTR/FileCoder.biwgy
Antiy-AVLTrojan/Generic.ASMalwS.310A6DC
MicrosoftTrojan:Win32/Glupteba!ml
GDataGen:Variant.Bulz.238074
CynetMalicious (score: 99)
AhnLab-V3Malware/Gen.Reputation.C4212635
BitDefenderThetaAI:Packer.88AEF6DE21
ALYacGen:Variant.Bulz.238074
MAXmalware (ai score=81)
RisingTrojan.Filecoder!8.68 (CLOUD)
YandexTrojan.Udochka!6YEJijDMsV8
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.109859067.susgen
FortinetW32/Encoder.261C!tr.ransom
AVGWin32:Trojan-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.238074?

Bulz.238074 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment