Malware

Bulz.35204 malicious file

Malware Removal

The Bulz.35204 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.35204 virus can do?

  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Creates known Njrat/Bladabindi RAT registry keys

How to determine Bulz.35204?


File Info:

name: 906E87BC7DB32D542B5F.mlw
path: /opt/CAPEv2/storage/binaries/2ef371e66abfd85c33902f3a34c0046e6d2a7ee1a88ef2d15840784baba94d91
crc32: 03FB8CF9
md5: 906e87bc7db32d542b5f912f53cb551e
sha1: dd6a73da7fec26e5f803f95bc42d7965ef81750c
sha256: 2ef371e66abfd85c33902f3a34c0046e6d2a7ee1a88ef2d15840784baba94d91
sha512: f129bd3557f8144b11f4693b6fb3749620d190411a05cac7767dccd0449ae9eb65aaea1141dc31219de40b4b6c034ccf1bf2d06e0f110cb78df3412a64ad79de
ssdeep: 12288:VgYYXxOEsJZFLFznz5tIVvjn84TkbTJ2TQGT8bT+JTe4BT1/QT1Unk+BmIM02EmM:zmxOE+FLFznz5tIVvjn84TkbTJ2TQGTZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137A4984A704D5A81D7780F73A1F7606563E0529F7672EF2B0FCCE6780C903CA695A4AE
sha3_384: 1599f871305dcaf9f495ab2031c65f54c5cbed2ee031122151f1a627ae58cdac917f57e5f11e4cf36c97d5b421a3dcdd
ep_bytes: ff250020400000000000000000000000
timestamp: 2023-05-20 02:03:25

Version Info:

Translation: 0x0000 0x04b0
FileDescription: Clean
FileVersion: 1.0.0.0
InternalName: Clean.exe
LegalCopyright: Copyright © 2023
OriginalFilename: Clean.exe
ProductName: Clean
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.35204 also known as:

tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Bulz.35204
FireEyeGeneric.mg.906e87bc7db32d54
ALYacGen:Variant.Bulz.35204
Cylanceunsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004b8b661 )
K7GWTrojan ( 004b8b661 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.MSIL_Heur.B
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Kryptik.GBD
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Bulz.35204
AvastWin32:RATX-gen [Trj]
EmsisoftGen:Variant.Bulz.35204 (B)
F-SecureHeuristic.HEUR/AGEN.1353893
VIPREGen:Variant.Bulz.35204
TrendMicroTROJ_GEN.R014C0WEM23
McAfee-GW-EditionArtemis
Trapminemalicious.high.ml.score
GDataGen:Variant.Bulz.35204
AviraHEUR/AGEN.1353893
ArcabitTrojan.Bulz.D8984
ZoneAlarmHEUR:Backdoor.MSIL.Bladabindi.gen
MicrosoftTrojan:Win32/Wacatac.B!ml
AhnLab-V3Trojan/Win.Generic.C5119165
Acronissuspicious
McAfeeArtemis!906E87BC7DB3
MAXmalware (ai score=87)
TrendMicro-HouseCallTROJ_GEN.R014C0WEM23
RisingMalware.Obfus/MSIL@AI.98 (RDM.MSIL2:c6ELZTJ2bFmSzrGruoCx0Q)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.DN.13FBAB!tr
BitDefenderThetaGen:NN.ZemsilF.36196.Cm0@a8qi5N
AVGWin32:RATX-gen [Trj]
Cybereasonmalicious.c7db32
DeepInstinctMALICIOUS

How to remove Bulz.35204?

Bulz.35204 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment