Malware

How to remove “Bulz.515437”?

Malware Removal

The Bulz.515437 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.515437 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Azeri (Cyrillic)
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Checks for the presence of known windows from debuggers and forensic tools
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

bandakere.tumblr.com
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com

How to determine Bulz.515437?


File Info:

crc32: FF49C06F
md5: 7283347ba70004a56396caa0a2de7bb0
name: 7283347BA70004A56396CAA0A2DE7BB0.mlw
sha1: 4200e6d839329ce2935aa53071021157ea0a07ca
sha256: d9d7be1231912d7967848f8b286332be9972712bbf745d9cd725123f3ca6cf57
sha512: 1444d092dd7122753efc451d1780aa911f8bbb9ebe7003fe5e619616123aa22012c19d62578c65f55f348eb8a18f735136afd69f6967b300d3437918a0081854
ssdeep: 49152:0pA6l5jszHjVcp5jKVK1CP9wnYEwMgb6eghQD5jKVKFOrnrgIYeghQ:kv5ozDVcp9KIQ4Ydb6DM9KIorsIYD
type: MS-DOS executable, MZ for MS-DOS

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: labsofte polish 2021 @gov.pl
Assembly Version: 32.8.1.4
InternalName: x6cex6210x987ex695pTx6d5x6868x629.exe
FileVersion: 32.8.1.4
CompanyName: labsofte polish
LegalTrademarks:
Comments: Installer for Europe
ProductName: gnu all langwidge
ProductVersion: 32.8.1.4
FileDescription: GitLOto
OriginalFilename: x6cex6210x987ex695pTx6d5x6868x629.exe

Bulz.515437 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
ALYacGen:Variant.Bulz.515437
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PSW.Agent.OGR
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.Win32.Chapak.ezqv
BitDefenderGen:Variant.Bulz.515437
MicroWorld-eScanGen:Variant.Bulz.515437
Ad-AwareGen:Variant.Bulz.515437
SophosGeneric ML PUA (PUA)
BitDefenderThetaGen:NN.ZexaF.34738.2wuaa0JE2nmG
FireEyeGeneric.mg.7283347ba70004a5
EmsisoftGen:Variant.Bulz.515437 (B)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_89%
MicrosoftTrojan:Win32/Hynamer.A!ml
GridinsoftTrojan.Heur!.03014681
GDataGen:Variant.Bulz.515437
AhnLab-V3Trojan/Win.Generic.C4527066
MAXmalware (ai score=80)
VBA32BScope.TrojanPSW.Coins
MalwarebytesTrojan.Downloader
RisingMalware.Heuristic!ET#94% (RDMK:cmRtazrjxRvKqjrH5E2bVJzQWERL)
AVGWin32:Malware-gen

How to remove Bulz.515437?

Bulz.515437 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment