Malware

Should I remove “Bulz.539058”?

Malware Removal

The Bulz.539058 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.539058 virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Attempts to modify proxy settings
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Bulz.539058?


File Info:

name: 87E09599FF68D0138095.mlw
path: /opt/CAPEv2/storage/binaries/9b0cc9219b854fb5dbb13eb5daafe18e12ce7387de55c8cf83cef20487b6d38c
crc32: 6B11AD03
md5: 87e09599ff68d0138095504f6fd814e6
sha1: 640f587dded6aa0871561031012cd4fd06a6d642
sha256: 9b0cc9219b854fb5dbb13eb5daafe18e12ce7387de55c8cf83cef20487b6d38c
sha512: 65719a6acc5e46d47ca12f5c02ddcc85e28e1ae19e195fa55b40732b3951b467a07a3970777a5e977eb2a545d6c2a6dd0916823c4a9ed166f26ca403b4d39a2c
ssdeep: 49152:tuEDLB2F3fWPO7jZrrgqBo90HOg+k53icr7aeLav4WbD72Hv1wOhLnis2b+ltAsN:tLef7RAB3zD7Kjjq0usjmqMh56rl
type: PE32+ executable (console) x86-64, for MS Windows
tlsh: T1A9666B39ABB4C1E5F9ABD83CA9778671FA727A510833530B89E1C21E6F336524D19331
sha3_384: af803971c55cc7347306791f1d7894c7fd62b95002bc6894575fbed25d652e5a7480288bffbc2db4ba455cd2df118e8a
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2020-02-12 20:23:46

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Office Click-to-Run Integrator
FileVersion: 16.0.12430.20286
InternalName: C2R Integrator
LegalTrademarks1: Microsoft® is a registered trademark of Microsoft Corporation.
LegalTrademarks2: Windows® is a registered trademark of Microsoft Corporation.
OriginalFilename: Integrator.exe
ProductName: Microsoft Office
ProductVersion: 16.0.12430.20286
Translation: 0x0000 0x04e4

Bulz.539058 also known as:

LionicTrojan.Win32.Crypmodng.tsaK
MicroWorld-eScanGen:Variant.Bulz.539058
ClamAVWin.Ransomware.Lazy-9977608-0
FireEyeGen:Variant.Bulz.539058
McAfeeArtemis!87E09599FF68
CylanceUnsafe
SangforTrojan.Win64.Filecoder.Vuj6
K7AntiVirusTrojan ( 0059aa0b1 )
AlibabaTrojan:Win64/Filecoder.88e1d7b9
K7GWTrojan ( 0059aa0b1 )
CrowdStrikewin/malicious_confidence_60% (D)
CyrenW64/Ipamor.A
SymantecDownloader
ESET-NOD32Win64/Filecoder.GG
KasperskyTrojan-Ransom.Win32.Blocker.zduf
BitDefenderGen:Variant.Bulz.539058
AvastWin64:Trojan-gen
TencentWin32.Trojan.Blocker.Qnkl
Ad-AwareGen:Variant.Bulz.539058
EmsisoftGen:Variant.Bulz.539058 (B)
DrWebWin32.HLLP.Azov.2
VIPREGen:Variant.Bulz.539058
McAfee-GW-EditionBehavesLike.Win64.Expiro.vh
SophosMal/Generic-R + Troj/Azov-A
GDataGen:Variant.Bulz.539058
JiangminTrojan.Blocker.urx
Antiy-AVLGrayWare/Win32.Filecoder.gg
ArcabitTrojan.Bulz.D839B2
MicrosoftTrojan:Win32/Wacatac.B!ml
GoogleDetected
AhnLab-V3Trojan/Win.Generic.R534176
ALYacGen:Variant.Bulz.539058
MAXmalware (ai score=83)
TrendMicro-HouseCallTROJ_GEN.R002H0CKE22
RisingRansom.Agent!8.6B7 (TFE:2:U9tOTBNOHOO)
IkarusTrojan-Ransom.FileCrypter
FortinetW64/Filecoder.GG!tr
AVGWin64:Trojan-gen

How to remove Bulz.539058?

Bulz.539058 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment