Malware

Bulz.263867 removal

Malware Removal

The Bulz.263867 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.263867 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Checks for the presence of known windows from debuggers and forensic tools
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

dist.divx.com
vertxvid.com
track.cmllk1.info

How to determine Bulz.263867?


File Info:

crc32: FBC54847
md5: 4cd283db7b9d7167e2ebdbe4b10a814b
name: 4CD283DB7B9D7167E2EBDBE4B10A814B.mlw
sha1: 1be52d25aa406a7599f336b9657676beef729662
sha256: 5a86a67c587b474becc9ffe60ea17e24a30281a7de5e217c5852b244be8bfffa
sha512: 4904a964302a8fe40d40781064d99250e85f7dcc593462727239b1de54c61e05f964610b4cdf845def39579cfd570b0042375590690795212ab6bc5976f7c435
ssdeep: 24576:IGhN5k2XJLekOrV1v/VKbWSudONgA7XUrQ:5N5k2VzOrV13bBMBTIQ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: 2014 DivX, LLC.
InternalName: Turbo
FileVersion: 2.6.3.52
CompanyName: DivX, LLC
ProductName: DivX Setup
ProductVersion: 2.6.3.52
FileDescription: DivX Setup
OriginalFilename: DivXSetup.exe
Translation: 0x0409 0x04b0

Bulz.263867 also known as:

Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Sodinokibi-9887839-0
ALYacGen:Variant.Bulz.263867
ZillyaDropper.NSIS.Win32.2347
BitDefenderGen:Variant.Bulz.263867
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
APEXMalicious
CynetMalicious (score: 99)
KasperskyTrojan-Dropper.Win32.NSIS.auik
MicroWorld-eScanGen:Variant.Bulz.263867
Ad-AwareGen:Variant.Bulz.263867
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1122485
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
FireEyeGeneric.mg.4cd283db7b9d7167
EmsisoftGen:Variant.Bulz.263867 (B)
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1122485
ArcabitTrojan.Bulz.D406BB
ZoneAlarmTrojan-Dropper.Win32.NSIS.auik
GDataGen:Variant.Bulz.263867
McAfeeGenericR-MBM!4CD283DB7B9D
MAXmalware (ai score=84)
IkarusTrojan.SuspectCRC

How to remove Bulz.263867?

Bulz.263867 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment