Malware

Bulz.457452 malicious file

Malware Removal

The Bulz.457452 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.457452 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Collects and encrypts information about the computer likely to send to C2 server
  • Uses csc.exe C# compiler to build and execute code
  • Uses suspicious command line tools or Windows utilities

How to determine Bulz.457452?


File Info:

name: 592F7EA177612EC32E77.mlw
path: /opt/CAPEv2/storage/binaries/4c4cc3473e050b83943e58548a71c72603a934b2daba6d57fd75908323d32776
crc32: A8F4C496
md5: 592f7ea177612ec32e77732feb46a7c7
sha1: f215c11d04be4a8bef4bc4323983a669a5939197
sha256: 4c4cc3473e050b83943e58548a71c72603a934b2daba6d57fd75908323d32776
sha512: 8020ed0a52b523a5e99657839410e94ff61475df10af710d2dc325444871ede5530b0805d664f3ba82c4f943c29e0c117d67466b665ff8df8b52abff04e9fab4
ssdeep: 768:Bwu7aglVRU+TCsOtYKFXgqJF0S/q7rpTfKfobKXroJHEeLgHDkC:tpU+TNOxuqJFVqRLjbKboG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14D233A09B7D8DF29C66F4E7468F105680238F21B1466EB0F8CCB51DA9DA37D49A01EF2
sha3_384: 696692fa501d2b63f9b6898cd580967ec6f33dc0c17f186f783498db22b5d64b0d993155a600f8d1cc4aae53b3b35da0
ep_bytes: ff250020400000000000000000000000
timestamp: 2018-12-27 13:28:54

Version Info:

Translation: 0x0000 0x04b0
Comments: vmware_authd
CompanyName: vmware
FileDescription: vmware_authd
FileVersion: 28.97.0.14
InternalName: vmware_authd.exe
LegalCopyright: Copyright © 2014
LegalTrademarks:
OriginalFilename: vmware_authd.exe
ProductName: vmware
ProductVersion: 28.97.0.14
Assembly Version: 13.1.8.10

Bulz.457452 also known as:

LionicTrojan.MSIL.Agent.4!c
ClamAVWin.Trojan.MSILPerseus-6847168-0
McAfeeTrojan-FRGM!592F7EA17761
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00556cbe1 )
AlibabaBackdoor:MSIL/Bladabindi.983683e5
K7GWTrojan ( 00556cbe1 )
Cybereasonmalicious.177612
ESET-NOD32a variant of MSIL/TrojanDropper.Agent.EJC
APEXMalicious
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Variant.Bulz.457452
MicroWorld-eScanGen:Variant.Bulz.457452
TencentMsil.Trojan.Agent.Suxz
Ad-AwareGen:Variant.Bulz.457452
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZemsilF.34742.cm0@aC@yvmc
McAfee-GW-EditionTrojan-FRGM!592F7EA17761
FireEyeGeneric.mg.592f7ea177612ec3
EmsisoftGen:Variant.Bulz.457452 (B)
IkarusBackdoor.MSIL.Bladabindi
GDataGen:Variant.Bulz.457452
JiangminTrojan.MSIL.mfpa
ArcabitTrojan.Bulz.D6FAEC
ZoneAlarmHEUR:Trojan.MSIL.Agent.gen
MicrosoftBackdoor:MSIL/Bladabindi
AhnLab-V3Unwanted/Win32.Agent.C2913168
ALYacTrojan.MSIL.Bladabindi
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.8703358.susgen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.457452?

Bulz.457452 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment