Malware

Bulz.5876 (file analysis)

Malware Removal

The Bulz.5876 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.5876 virus can do?

  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Telugu
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Bulz.5876?


File Info:

name: 940357FA35820028829D.mlw
path: /opt/CAPEv2/storage/binaries/9cb6783eeda4b9b7200c9c16ba3ebf1f3795015091863a9799ff69ee3734db26
crc32: F98D5619
md5: 940357fa35820028829dfe38da91bc6d
sha1: ad3b3798290c4992560969010af84ef94f0b3213
sha256: 9cb6783eeda4b9b7200c9c16ba3ebf1f3795015091863a9799ff69ee3734db26
sha512: 68ff694d5f9538b6dece73ea06e566d641d4518ad4e966f63c0631729fe4cc09f5feda0e99f3602e9a7b92ab5cb76991c2fe2e2a9287a73dc90711d2b4aafaf1
ssdeep: 6144:0SDaWXpl5alOHD1O2XfgAOF+dXIf7c/ywZr4BntNM90wKRB:DDaW5HalOHD1OMfo+dXIeywZr4ZM90r
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B84102C76D285EAEC0FE072CD6136B46A930F0F96506D4B5F8A79CABB6A4151D34CCC
sha3_384: 6939ca77eb16488976ead67de65498b01a971dd93ddaf04a0e3d0225f3e9a307b3b48378b865c9e2277d5990211832e3
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-12-08 18:50:23

Version Info:

CompanyName: Adobe Inc.
FileDescription: Adobe Installer
FileVersion: 5.3.1.470
InternalName: Adobe Installer
LegalCopyright: © 2020 Adobe. All rights reserved.
OriginalFilename: Adobe Installer
ProductName: Adobe Installer
ProductVersion: 5.3.1.470
Translation: 0x0409 0x04b0

Bulz.5876 also known as:

LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Inject4.21705
MicroWorld-eScanGen:Variant.Bulz.5876
ALYacGen:Variant.Bulz.5876
MalwarebytesTrojan.Injector
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:MSIL/Injector.21aece96
K7GWTrojan ( 005819cf1 )
K7AntiVirusTrojan ( 005819cf1 )
BitDefenderThetaGen:NN.ZemsilF.34084.ym0@aG1u4QiG
ESET-NOD32a variant of MSIL/Injector.VRI
TrendMicro-HouseCallTROJ_GEN.R002C0WL921
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.5876
AvastWin32:InjectorX-gen [Trj]
TencentWin32.Trojan.Generic.Hqbb
Ad-AwareGen:Variant.Bulz.5876
EmsisoftGen:Variant.Bulz.5876 (B)
TrendMicroTROJ_GEN.R002C0WL921
FireEyeGeneric.mg.940357fa35820028
IkarusTrojan.MSIL.Injector
GDataMSIL.Backdoor.ASyncRAT.BDX0TI
AviraTR/Injector.haqlu
Antiy-AVLTrojan/Generic.ASMalwS.34E78A6
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Bulz.D16F4
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win.NK.C4827035
McAfeeRDN/Generic.hbg
MAXmalware (ai score=82)
VBA32TScope.Trojan.MSIL
CylanceUnsafe
APEXMalicious
YandexTrojan.Agent!UVWGtG8ySrY
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_88%
FortinetMSIL/Injector.VRI!tr
AVGWin32:InjectorX-gen [Trj]
Cybereasonmalicious.a35820
PandaTrj/GdSda.A

How to remove Bulz.5876?

Bulz.5876 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment