Malware

Bulz.24507 information

Malware Removal

The Bulz.24507 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.24507 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Behavioural detection: Injection (inter-process)
  • Attempts to disable Windows Auto Updates
  • Anomalous binary characteristics
  • Attempts to modify Explorer settings to prevent hidden files from being displayed

How to determine Bulz.24507?


File Info:

name: CF8A840B5421C521124C.mlw
path: /opt/CAPEv2/storage/binaries/60d6bddd22e5e656d51f4d73c85d1912c002c88c8185e07be15b6892943eeae4
crc32: 0FA1F212
md5: cf8a840b5421c521124cea640518dd95
sha1: af3496ebef83ccda9401ad7a19e5574620221e88
sha256: 60d6bddd22e5e656d51f4d73c85d1912c002c88c8185e07be15b6892943eeae4
sha512: 6fd1624595595f8082826dc7608d5fc6a03283e7de17ad211db317ca4e3b94a1e3182bf091ff34100c0b6c1586a120b8e070bc9e75ad76e8021a5577ef99b622
ssdeep: 3072:L1CxYpWufuhuQSamFi5eLb532qRgzqRe/aT4E1KZnBmaOtDvJRZ8Ng0ykdSXsj42:L1CxAb532qRmqRe/aT4EYDmaOtNRKNZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T152641A1673A0FA2AD5218BF02AAA43B4517EEC3115D1A907F7803F1E77B2E975236713
sha3_384: 0a040375b8ba285e6ddf2479bc7ee741293b40b8b9b5bbd6c0d8d0b842173677fde39e04ab734a018692cc9fd0aaa7cb
ep_bytes: 6864434000e8eeffffff000068000000
timestamp: 2012-10-04 19:27:38

Version Info:

Translation: 0x0409 0x04b0
ProductName: ricksha
FileVersion: 8.42
ProductVersion: 8.42
InternalName: incettero
OriginalFilename: incettero.exe

Bulz.24507 also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Variant.Bulz.24507
CAT-QuickHealTrojan.Beebone.D
SkyhighBehavesLike.Win32.VBObfus.fm
McAfeeGenDownloader.rv
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Bulz.24507
SangforTrojan.Win32.Save.a
K7AntiVirusEmailWorm ( 0054d10f1 )
K7GWEmailWorm ( 0054d10f1 )
Cybereasonmalicious.b5421c
BaiduWin32.Worm.Pronny.d
VirITTrojan.Win32.SHeur4.AQUQ
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/Pronny.FA
APEXMalicious
TrendMicro-HouseCallWORM_VOBFUS.SMAS
ClamAVWin.Trojan.Changeup-6169544-0
KasperskyWorm.Win32.Vobfus.scu
BitDefenderGen:Variant.Bulz.24507
NANO-AntivirusTrojan.Win32.WBNA.csfhhl
AvastWin32:VB-AEQD [Trj]
TencentWorm.Win32.Vobfus.kaz
TACHYONWorm/W32.Vobfus.323638
SophosMal/SillyFDC-W
GoogleDetected
F-SecureTrojan.TR/Symmi.2336989
DrWebWin32.HLLW.Autoruner1.27186
TrendMicroWORM_VOBFUS.SMAS
FireEyeGeneric.mg.cf8a840b5421c521
EmsisoftGen:Variant.Bulz.24507 (B)
IkarusWorm.Win32.Vobfus
JiangminWorm/WBNA.diik
VaristW32/VB.HE.gen!Eldorado
AviraTR/Symmi.2336989
Antiy-AVLWorm/Win32.WBNA.gen
Kingsoftmalware.kb.a.1000
MicrosoftWorm:Win32/Vobfus.IY
XcitiumWorm.Win32.VB.PJT@4r48sc
ArcabitTrojan.Bulz.D5FBB
ViRobotWorm.Win32.A.Vobfus.305927
ZoneAlarmWorm.Win32.Vobfus.scu
GDataGen:Variant.Bulz.24507
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Vobfus.R38791
BitDefenderThetaGen:NN.ZevbaF.36802.tm1@aaVjgygi
ALYacGen:Variant.Bulz.24507
MAXmalware (ai score=87)
VBA32Malware-Cryptor.VB.gen
Cylanceunsafe
PandaTrj/Genetic.gen
RisingMalware.FakeFolder/ICON!1.6AC4 (CLASSIC)
YandexTrojan.GenAsa!h1mNOJ3gpiw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4636701.susgen
FortinetW32/VBKrypt.CA!tr
AVGWin32:VB-AEQD [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudWorm:Win/Vobfus.16fb5ccc

How to remove Bulz.24507?

Bulz.24507 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment