Malware

What is “Bulz.274126”?

Malware Removal

The Bulz.274126 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.274126 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Steals private information from local Internet browsers
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

www.cncode.pw
iplogger.org
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Bulz.274126?


File Info:

crc32: 73AA3C07
md5: 700d9f6d8a9ac0bfc5f556dfaf149660
name: 700D9F6D8A9AC0BFC5F556DFAF149660.mlw
sha1: 163852e998ff25bfcbde01b60f97b41dd59c54ca
sha256: 50d5492bbb1dbe3ea1673fa55f1504890aabdeb1588a244992deb92c35276952
sha512: 41f72bfeece65532d4238804626edd300c9e3f388616ed120702e31ebdc63348005aa76d3f63ed4826838becb0b552ba2f877d273b11badeb36c85a344bffb9a
ssdeep: 12288:UboD5u+frlTC4YvvSEKGnWJxy5ElqTp3ghybz08Y1Mn2ohu:UboDPf1aUGqtATpwhuvn2Wu
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifes.acs
FileVers: 26.26.361
ProductVersion: 1.0.22
Copyright: Copyrighz (C) 2020, fadkafug
TranslationUsa: 0x0272 0x04d4

Bulz.274126 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.274126
FireEyeGeneric.mg.700d9f6d8a9ac0bf
CAT-QuickHealTrojan.Zenpak
ALYacGen:Variant.Bulz.274126
CylanceUnsafe
AegisLabTrojan.Win32.Zenpak.4!c
SangforMalware
K7AntiVirusTrojan ( 00574dcf1 )
BitDefenderGen:Variant.Bulz.274126
K7GWTrojan ( 00574dcf1 )
Cybereasonmalicious.998ff2
BitDefenderThetaGen:NN.ZexaF.34700.HmKfaeiWGfoG
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIIF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Tofsee-9812536-0
KasperskyTrojan.Win32.Zenpak.bawq
AlibabaBackdoor:Win32/KZip.3d97e4ca
RisingTrojan.Kryptik!8.8 (TFE:5:4GYgIj05huN)
Ad-AwareGen:Variant.Bulz.274126
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Socelars.xzjyl
McAfee-GW-EditionBehavesLike.Win32.Trojan.hc
EmsisoftGen:Variant.Bulz.274126 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_91%
AviraTR/AD.Socelars.xzjyl
MAXmalware (ai score=89)
MicrosoftTrojan:Win32/Azorult.FW!MTB
ArcabitTrojan.Bulz.D42ECE
ZoneAlarmTrojan.Win32.Zenpak.bawq
GDataGen:Variant.Bulz.274126
CynetMalicious (score: 100)
Acronissuspicious
McAfeeRDN/Generic.grp
VBA32BScope.Trojan.Glupteba
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CLJ20
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.HIFA!tr
WebrootW32.Malware.Gen
AVGFileRepMalware
AvastWin32:MalwareX-gen [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.9f4

How to remove Bulz.274126?

Bulz.274126 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment