Malware

About “Bulz.284902” infection

Malware Removal

The Bulz.284902 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.284902 virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Sniffs keystrokes
  • Interacts with known DarkComet registry keys
  • Creates known Fynloski/DarkComet mutexes

Related domains:

0.tcp.ngrok.io

How to determine Bulz.284902?


File Info:

crc32: E08C3C50
md5: a7c4b880ca2a4e975890199e06b439cc
name: A7C4B880CA2A4E975890199E06B439CC.mlw
sha1: 12f7d72ba4fa4e1f496856441b53ede33f1e3809
sha256: 5cd8924328a7410215c895cd0de484846df13d583e15650ded75ba62b88c17d0
sha512: d1be9c477973172c64d7d7238e95c3d3a86e5aa354262207d40114419620df4bcc34c62e70a9da90d547a93f4e9ce1978a269af887dbf64685b76459d17b571f
ssdeep: 12288:wRZ+IoG/n9IQxW3OBseWJcZiabpbQfFgVmf+7WDU07/wbWtA2LB5YnWp/A:q2G/nvxW3WwWi81QtgVmSL08WrP0WK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.284902 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.284902
FireEyeGeneric.mg.a7c4b880ca2a4e97
CAT-QuickHealTrojan.Wacatac
ALYacGen:Variant.Bulz.284902
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderGen:Variant.Bulz.284902
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
CyrenW32/Darkkomet.A.gen!Eldorado
SymantecBackdoor.Graybird
APEXMalicious
AvastWin32:Agent-AWZS [Trj]
KasperskyBackdoor.Win32.DarkKomet.aagt
AlibabaBackdoor:Win32/DarkKomet.37dbb780
NANO-AntivirusTrojan.Win32.DarkKomet.ecawjb
Ad-AwareGen:Variant.Bulz.284902
EmsisoftGen:Variant.Bulz.284902 (B)
ComodoTrojWare.Win32.Fynloski.B@57zt85
F-SecureHeuristic.HEUR/AGEN.1136694
DrWebBackDoor.Tordev.976
TrendMicroTROJ_GEN.R002C0DBS21
McAfee-GW-EditionBehavesLike.Win32.Dropper.jh
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
AviraHEUR/AGEN.1136694
Antiy-AVLTrojan[Backdoor]/Win32.DarkKomet.xyk
KingsoftWin32.Hack.Undef.(kcloud)
MicrosoftBackdoor:Win32/Fynloski
ArcabitTrojan.Bulz.D458E6
ZoneAlarmBackdoor.Win32.DarkKomet.aagt
GDataGen:Variant.Bulz.284902
CynetMalicious (score: 100)
McAfeeArtemis!A7C4B880CA2A
MAXmalware (ai score=85)
VBA32Backdoor.Tordev
MalwarebytesGeneric.Worm.Autorun.DDS
PandaTrj/CI.A
ZonerTrojan.Win32.29392
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0DBS21
TencentWin32.Backdoor.Darkkomet.Lork
IkarusBackdoor.Win32.DarkKomet
FortinetW32/multiple_detections
BitDefenderThetaGen:NN.ZexaF.34590.PyZ@aai7@FdO
AVGWin32:Agent-AWZS [Trj]
Cybereasonmalicious.0ca2a4
Paloaltogeneric.ml
Qihoo-360Win32/Backdoor.DarkKomet.HgIASPkA

How to remove Bulz.284902?

Bulz.284902 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment