Malware

Bulz.399886 information

Malware Removal

The Bulz.399886 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.399886 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates known Njrat/Bladabindi RAT registry keys
  • Anomalous binary characteristics

How to determine Bulz.399886?


File Info:

name: 6F23FA1B035BCD302892.mlw
path: /opt/CAPEv2/storage/binaries/8eefc038e9cb1aeb95b233ff27190ea1ba657f4ad9bd2a102ba5bedc3a2190cf
crc32: 7F3BC3D0
md5: 6f23fa1b035bcd30289261b955f04b4b
sha1: 76286a573fb8c5163e50bfbd0ffccecf6c547c85
sha256: 8eefc038e9cb1aeb95b233ff27190ea1ba657f4ad9bd2a102ba5bedc3a2190cf
sha512: c284f4ffa8b031fae9f046b3d5215b8be92b760b310ee1824342a83d60888bc5591599e82e4e0aaca511b7a0896e5658e8caff8a1f28b78f53a1c210dd5da8ba
ssdeep: 384:CEq7I8Lf9iGjYD5gUin6z2CjM1wLn1lZyAMw80gcK6T/kAZKuTNGyp5CqfT8jpL:Vgf5ai6z2CjM1QJyvw87wk4KGA8oP
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T10CF2D1E2E3B46C27F86C87346DE3D361F5AA39149A43B35E168441AF2D537189610F29
sha3_384: 6c8295c90de12b2ca5f5b032512bce159b537dd3c5cefdec3a2ee5af61a6539e24f31134b464937f39d237c7af8633ed
ep_bytes: 4d5a90000300000004000000ffff0000
timestamp: 2021-12-05 03:33:58

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: hkjghjk.exe
LegalCopyright:
OriginalFilename: hkjghjk.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Bulz.399886 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.399886
FireEyeGeneric.mg.6f23fa1b035bcd30
ALYacGen:Variant.Bulz.399886
BitDefenderGen:Variant.Bulz.399886
Cybereasonmalicious.b035bc
ArcabitTrojan.Bulz.D61A0E
CyrenW64/S-566e2c4d!Eldorado
ESET-NOD32a variant of MSIL/Kryptik.HXG
Paloaltogeneric.ml
ClamAVWin.Trojan.Generic-6335829-0
KasperskyHEUR:Trojan.MSIL.Generic
NANO-AntivirusTrojan.Win64.Bladabindi.ecsqgp
Ad-AwareGen:Variant.Bulz.399886
EmsisoftGen:Variant.Bulz.399886 (B)
F-SecureHeuristic.HEUR/AGEN.1101670
DrWebBackDoor.Bladabindi.12919
McAfee-GW-EditionBehavesLike.Win64.Generic.nh
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/Mdrop-JDM
APEXMalicious
AviraHEUR/AGEN.1101670
MAXmalware (ai score=86)
GDataMSIL.Trojan.Kryptik.KS
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Korat.Gen
McAfeePacked-LB!6F23FA1B035B
IkarusTrojan.MSIL.Crypt
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Kryptik.HXG!tr
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.399886?

Bulz.399886 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment