Malware

What is “Bulz.264016”?

Malware Removal

The Bulz.264016 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.264016 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

How to determine Bulz.264016?


File Info:

crc32: 63340C89
md5: 2512bc611f3477627381e7b69fd3dfc0
name: 2512BC611F3477627381E7B69FD3DFC0.mlw
sha1: 4de71f730b57d672c3ccc9a655fd9e347b5462f9
sha256: d1d3cf433e871d3aa6836ddb87578cbf494603f6f4a8918f36aea5816c6ce5e0
sha512: ec71f2e14f38fd1aa8956ff38417cefbbebf35d2b79f70ac242f946cc7870a99c06329ee142a7fdc6c47e7ba27461065db38747eacf309b265d495c8e9b032f7
ssdeep: 3072:wh8W5EOvE8utrloMC0kfF1IZEZZ4QQ4h5UNrd:BWWOUtrlTSe+ZR8
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.264016 also known as:

Elasticmalicious (high confidence)
DrWebBackDoor.PlugX.89
ALYacGen:Variant.Bulz.264016
ZillyaTrojan.Korplug.Win32.1381
K7GWTrojan ( 005746d31 )
K7AntiVirusTrojan ( 005746d31 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Korplug.QV
APEXMalicious
AvastWin32:Korplug-M [Trj]
CynetMalicious (score: 99)
KasperskyUDS:Trojan.Win32.Agentb.a
BitDefenderGen:Variant.Bulz.264016
NANO-AntivirusTrojan.Win32.Korplug.iddzkw
MicroWorld-eScanGen:Variant.Bulz.264016
Ad-AwareGen:Variant.Bulz.264016
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZedlaF.34058.iu4@aeCAC8gi
McAfee-GW-EditionRDN/Generic BackDoor
FireEyeGeneric.mg.2512bc611f347762
EmsisoftGen:Variant.Bulz.264016 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Agentb.hkk
AviraTR/AD.Korplug.illau
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Bulz.D40750
GDataGen:Variant.Bulz.264016
AhnLab-V3Malware/Win32.Generic.C4364795
McAfeeRDN/Generic BackDoor
MAXmalware (ai score=81)
VBA32Backdoor.Korplug
MalwarebytesBackdoor.Agent
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R06EH0CH721
RisingTrojan.Generic@ML.91 (RDML:h1R+U+81s4c4J7IZ6SfQ3A)
YandexTrojan.Korplug!7W/4QjaCEAM
IkarusTrojan.Win32.Korplug
FortinetW32/Korplug.QV!tr
AVGWin32:Korplug-M [Trj]
Qihoo-360Win32/Backdoor.PlugX.HgkASZ0A

How to remove Bulz.264016?

Bulz.264016 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment