Malware

Should I remove “Bulz.280947”?

Malware Removal

The Bulz.280947 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.280947 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Slovenian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • CAPE detected the Raccoon malware family

How to determine Bulz.280947?


File Info:

name: BB92A16DD8E1EB7B693C.mlw
path: /opt/CAPEv2/storage/binaries/ce53b7725f248e4882debb611c670641d3af9a1b15fbe8b00d49169b08976fe3
crc32: CE5EF7E8
md5: bb92a16dd8e1eb7b693c341236164127
sha1: f73f491a88e5ee840b8f02711b23382b46b3b25a
sha256: ce53b7725f248e4882debb611c670641d3af9a1b15fbe8b00d49169b08976fe3
sha512: a0783c77d754f383de5b50b6eee8d2e947f95964ee3260b80a15a0d3749efb0724f69d517219a88838a6fdad4c3cc57f64744b8adc55a29416fdd9dcd9e0d00e
ssdeep: 12288:JZg1dIOuLgjJ60GtSiO0NebJwZSgRwwW3gDz6Q62WKy+6lpekN:E1+O6gjJRGtSiO0dD6wuxM+c
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E9C42362C80408FDCCAB1E34E728A6D4190A55522BFFFD31FFEA8C6436B9947E616D14
sha3_384: 5fb3c0c9d12216583bc609fd7963e0f1f67ec67e33817443f86dce8a46e2d51894fdd3a998cf00fbb216ca0b0ab3bcb0
ep_bytes: 60be00f011058dbe00202efb57eb0b90
timestamp: 2020-06-27 01:15:01

Version Info:

FileVersions: 1.0.5.4
InternalSurname: reboud.exe
LegalCo: Copyri (C) 2019, patrition
Product: 1.7.6
Translation: 0x0439 0x00fa

Bulz.280947 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.60926
MicroWorld-eScanGen:Variant.Bulz.280947
FireEyeGeneric.mg.bb92a16dd8e1eb7b
ALYacGen:Variant.Bulz.280947
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.2776824
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00575f941 )
AlibabaTrojan:Win32/SpyEyes.5d4c94d2
K7GWTrojan ( 00575f941 )
Cybereasonmalicious.dd8e1e
BitDefenderThetaGen:NN.ZexaF.34084.JmGfaiLPtfcc
CyrenW32/S-3ce371b4!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HIKI
Paloaltogeneric.ml
KasperskyHEUR:Exploit.Win32.ShellCode.vho
BitDefenderGen:Variant.Bulz.280947
NANO-AntivirusExploit.Win32.Shellcode.ikluhb
TencentWin32.Exploit.Shellcode.Phzu
Ad-AwareGen:Variant.Bulz.280947
EmsisoftGen:Variant.Bulz.280947 (B)
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SophosMal/Generic-S
IkarusTrojan.Win32.Ranumbot
GDataGen:Variant.Bulz.280947
JiangminExploit.ShellCode.bbu
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1140469
Antiy-AVLTrojan/Generic.ASMalwS.31098A2
ArcabitTrojan.Bulz.D44973
MicrosoftTrojan:Win32/Azorult.FW!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R360167
McAfeeGenericRXAA-AA!BB92A16DD8E1
MAXmalware (ai score=88)
VBA32BScope.Backdoor.Agent
MalwarebytesTrojan.Glupteba
PandaTrj/GdSda.A
APEXMalicious
RisingMalware.Obscure/Heur!1.A89F (CLASSIC)
YandexExploit.Shellcode!u95YE/4lBmc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.111475148.susgen
FortinetW32/CoinMiner.HGHW!tr
AVGWin32:BotX-gen [Trj]
AvastWin32:BotX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Bulz.280947?

Bulz.280947 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment