Malware

Bulz.419309 removal

Malware Removal

The Bulz.419309 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.419309 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.419309?


File Info:

name: 280A25253CD8DFE893D3.mlw
path: /opt/CAPEv2/storage/binaries/5d6b528bc40d8305acc05c216de73e21942fbd405567142fad2d82adcee12211
crc32: 139519BE
md5: 280a25253cd8dfe893d327ce48698ca7
sha1: c6c33ac7084ab3800075d3401d84363152566cf7
sha256: 5d6b528bc40d8305acc05c216de73e21942fbd405567142fad2d82adcee12211
sha512: e6a89fb79e7eef270d9620d1c2af8b64015d4e461d69f45f1e72f3f99b5d6bb6c37cdeab4d0e970bad4ea3c462a0e024cb9e5d6e3e2e16866edb53ae6d46a365
ssdeep: 24576:uroNK/w0YIes+kJMJ0Je+/8L3vt6s48wGg5kjBX27n53caIprjWAn4p:uUN25esRJMJt08zv44g5kVXgn5sHnc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D355234247484890C4421B3CB0DEFB577E7CB3E1BFA0D18769565EC6A7E22C27E99227
sha3_384: 9613dadb005e0acc14f83c209a6a5e3ab0362b963ae50002452d3ebbd488d320c65dc1794ff7c193817b10e9fe679412
ep_bytes: e846140000f6d0b0108d6424349cff34
timestamp: 2006-08-16 00:33:39

Version Info:

FileVersion: 24, 0, 0, 28
ProductVersion: 1.00
CompanyName: Beijing Rising Information Technology Co., Ltd.
InternalName: Beijing Rising Information Technology Co., Ltd.
LegalCopyright: Copyright(C) 2012-2013 Beijing Rising Information Technology Co., Ltd. All Rights Reserved.
OriginalFilename: RsdSfx.exe
ProductName: Rising Software Distribute System
SpecialBuild: 20130922173022218
FileDescription: pmake.dat
Translation: 0x0000 0x04b0

Bulz.419309 also known as:

LionicTrojan.Win32.Strictor.4!c
MicroWorld-eScanGen:Variant.Bulz.419309
FireEyeGeneric.mg.280a25253cd8dfe8
McAfeeArtemis!280A25253CD8
CylanceUnsafe
ZillyaTrojan.Agent.Win32.1616154
SangforTrojan.Win32.Wacatac.B
K7AntiVirusSpyware ( 0055134d1 )
K7GWSpyware ( 0055134d1 )
Cybereasonmalicious.53cd8d
BitDefenderThetaGen:NN.ZexaF.34182.rD2@ayuml3kj
SymantecML.Attribute.HighConfidence
Paloaltogeneric.ml
BitDefenderGen:Variant.Bulz.419309
AvastWin32:Trojan-gen
RisingSpyware.Agent!8.C6 (RDMK:cmRtazowUyhoVVsWiddNqDwYi2KZ)
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Bulz.419309 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Spy.Agent.dentf
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.3260E89
MicrosoftTrojan:Win32/Ymacco.AA5D
GDataGen:Variant.Bulz.419309
CynetMalicious (score: 99)
ALYacGen:Variant.Bulz.419309
APEXMalicious
YandexTrojanSpy.Agent!IErz3L+PrEA
IkarusTrojan.Spy.Agent
AVGWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Bulz.419309?

Bulz.419309 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment