Malware

Bulz.502059 (file analysis)

Malware Removal

The Bulz.502059 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.502059 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Bulz.502059?


File Info:

name: F67113C3C8B71EE4EA8F.mlw
path: /opt/CAPEv2/storage/binaries/1b2ace5895b75576321783ae7801c0b47a6b3623bf9a1a468d3cb4f20a747209
crc32: 8D44EB2D
md5: f67113c3c8b71ee4ea8f72c78019013e
sha1: 00926a52bcf23185594ef4b9484633c13c939352
sha256: 1b2ace5895b75576321783ae7801c0b47a6b3623bf9a1a468d3cb4f20a747209
sha512: 3d7b3b98a463ae9de91dbd45080f45562788e025fbf623782814c50049be37264a665ad88d2a2ef096dd177f8fcba156e10e698f11fb23ead9b2965ab8ecb449
ssdeep: 3072:Y32GhNvo5FpFdfYhAG+rKfW/mmuq+PGGPWvnPnXf/xvmvGijeWnidaPmGSpPnPed:O2GhNw59xYhf
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T195F4D93C285E167EC7DBCBB117E2605B7B6987E54B018EED05A213770B1290B37489EE
sha3_384: a162d2038d3ece58eecb2141b059271f422bbddb148e3dd5a4c4822b89a51a8772e30629b45c4fc7018276d92e65f2b2
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-05-29 04:04:26

Version Info:

Translation: 0x0000 0x04b0
CompanyName: qlubicwin7
FileDescription: 2000
FileVersion: 1.0.0.0
InternalName: 2000.exe
LegalCopyright: Copyright © qlubicwin7 2021
OriginalFilename: 2000.exe
ProductName: 2000
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.502059 also known as:

LionicTrojan.MSIL.Bladabindi.m!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.20044
MicroWorld-eScanGen:Variant.Bulz.502059
ALYacGen:Variant.Bulz.502059
CylanceUnsafe
ZillyaTrojan.Injector.Win32.987725
SangforBackdoor.MSIL.Bladabindi.gen
K7AntiVirusTrojan ( 0056befe1 )
AlibabaBackdoor:MSIL/Bladabindi.b5fcb75f
K7GWTrojan ( 0056befe1 )
Cybereasonmalicious.2bcf23
BitDefenderThetaGen:NN.ZemsilF.34084.Vq0@aix2WGh
CyrenW32/MSIL_Kryptik.DCG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Injector.TTT
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Bladabindi.gen
BitDefenderGen:Variant.Bulz.502059
NANO-AntivirusTrojan.Win32.Bladabindi.iwddqv
AvastWin32:RATX-gen [Trj]
TencentMsil.Backdoor.Bladabindi.Eddh
Ad-AwareGen:Variant.Bulz.502059
SophosMal/Generic-S
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.f67113c3c8b71ee4
EmsisoftGen:Variant.Bulz.502059 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.MSIL.Gen
Antiy-AVLTrojan/Generic.ASMalwS.335E16E
MicrosoftTrojan:Win32/Tiggre!rfn
ArcabitTrojan.Bulz.D7A92B
GDataMSIL.Trojan.Agent.AUM
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.Generic.C4530606
McAfeeArtemis!F67113C3C8B7
MAXmalware (ai score=81)
VBA32TScope.Trojan.MSIL
MalwarebytesBackdoor.Bladabindi
YandexTrojan.Injector!6QLlFelHKUg
IkarusTrojan.MSIL.Injector
FortinetMSIL/Injector.SHW!tr
AVGWin32:RATX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Bulz.502059?

Bulz.502059 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment