Malware

Bulz.51555 information

Malware Removal

The Bulz.51555 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.51555 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to mimic the file extension of a Word 97-2003 document by having ‘doc’ in the file name.
  • The binary likely contains encrypted or compressed data.
  • Executed a process and injected code into it, probably while unpacking
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Anomalous binary characteristics

How to determine Bulz.51555?


File Info:

crc32: 5ACD7710
md5: 9937565f0c0b6658fee521ef9828baba
name: INVOICE & AWB_doc.exe
sha1: 02b698bb7187990d1cb99cb4a9424d706ac0520a
sha256: 463bb6840c11c5fe503539176cb0eb53623b6096ab4608619c7244b832ebbcad
sha512: 6d357a55de29263b727fede44beec0dad0e345d53a5167be09cf482869d629214837b214e6bc3e1315eefbf2b2e07ed1ff8ed1322d5d7b101203a1e31b54c898
ssdeep: 12288:LgftlTxIDJRRtYRNeuawx2+8zVQLlcqPTxUHYY3UmNUSKhZjaa87HLxG/9Z9pIxg:Lg1JxIwP5YxaZ0dD6SQeaOrxGlZ9Wxg
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.51555 also known as:

BkavW32.AIDetectVM.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.51555
FireEyeGeneric.mg.9937565f0c0b6658
K7AntiVirusTrojan ( 0056c99c1 )
K7GWTrojan ( 0056c99c1 )
Cybereasonmalicious.b71879
Invinceaheuristic
SymantecInfostealer.Lokibot!43
APEXMalicious
GDataGen:Variant.Bulz.51555
KasperskyHEUR:Trojan.Win32.Kryptik.gen
BitDefenderGen:Variant.Bulz.51555
Paloaltogeneric.ml
Ad-AwareGen:Variant.Bulz.51555
F-SecureHeuristic.HEUR/AGEN.1121831
DrWebTrojan.PWS.Stealer.29093
CyrenW32/Injector.ORWQ-3620
AviraHEUR/AGEN.1121831
ZoneAlarmHEUR:Trojan.Win32.Kryptik.gen
MicrosoftTrojan:Win32/Wacatac.C!ml
CynetMalicious (score: 100)
AhnLab-V3Suspicious/Win.Delphiless.X2091
McAfeeFareit-FPQ!9937565F0C0B
MAXmalware (ai score=85)
MalwarebytesTrojan.MalPack
ESET-NOD32a variant of Win32/Injector.ENAI
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusTrojan.Inject
FortinetW32/Injector.EMZL!tr
BitDefenderThetaGen:NN.ZelphiF.34152.0GW@ai2PgOpi
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Bulz.51555?

Bulz.51555 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment