Malware

Bulz.298262 malicious file

Malware Removal

The Bulz.298262 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.298262 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Sniffs keystrokes
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
dl.dropboxusercontent.com
ocsp.digicert.com
crl4.digicert.com
crl3.digicert.com

How to determine Bulz.298262?


File Info:

crc32: EAC524BD
md5: 0cc254bd1b9bcebbe96217668280d82c
name: 0CC254BD1B9BCEBBE96217668280D82C.mlw
sha1: eb7dc734279c2c1cf803db6e282172897a712e5f
sha256: c2c7e2208e818b40078b64af3aba934a77e4211672aa35a035d8181b8ed9aee6
sha512: cc91905c611a508ea3c9cd74a0af7d1b55312e92246a6c3cdcc07e0050742f935f4a03f160e1cccce9e7295e47f26444814f5ece2bb0ae010ad34e7f9172b97d
ssdeep: 96:AB1yd/+a6mkqgd+q/djrresw+yIgU71aST6dGAHP1O0l9pECG0+NHJ8vqozYpM6:ABzF9yshyIxaG2l3Wx0+NHKdaE
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: bogos.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: bogos.exe

Bulz.298262 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.298262
FireEyeGeneric.mg.0cc254bd1b9bcebb
CAT-QuickHealBackdoor.MSIL
McAfeeRDN/Generic Downloader.x
CylanceUnsafe
AegisLabTrojan.MSIL.Bladabindi.m!c
SangforMalware
K7AntiVirusTrojan-Downloader ( 00575ae51 )
BitDefenderGen:Variant.Bulz.298262
K7GWTrojan-Downloader ( 00575ae51 )
Cybereasonmalicious.4279c2
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
AlibabaBackdoor:MSIL/Bladabindi.7e90b5da
Ad-AwareGen:Variant.Bulz.298262
SophosMal/Generic-S
F-SecureTrojan.TR/Dldr.Small.yzetl
TrendMicroTROJ_GEN.R002C0PAV21
McAfee-GW-EditionRDN/Generic Downloader.x
EmsisoftGen:Variant.Bulz.298262 (B)
IkarusTrojan-Downloader.MSIL.Small
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Dldr.Small.yzetl
MAXmalware (ai score=84)
MicrosoftTrojan:Win32/Wacatac.B!ml
ArcabitTrojan.Bulz.D48D16
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
GDataGen:Variant.Bulz.298262
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.C4308492
BitDefenderThetaGen:NN.ZemsilF.34804.am0@aqKipNm
ALYacGen:Variant.Bulz.298262
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/TrojanDownloader.Small.CIJ
TrendMicro-HouseCallTROJ_GEN.R002C0PAV21
TencentMsil.Backdoor.Bladabindi.Jck
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetMSIL/Small.CIJ!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Win32/Backdoor.NjRAT.HgIASOIA

How to remove Bulz.298262?

Bulz.298262 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment