Malware

Bulz.593226 (file analysis)

Malware Removal

The Bulz.593226 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.593226 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself

Related domains:

smtp.gmail.com

How to determine Bulz.593226?


File Info:

crc32: 41D0D90A
md5: af0beadb84d518a471483b70b788cebf
name: AF0BEADB84D518A471483B70B788CEBF.mlw
sha1: 5267e2a949972ed6ff9999edb32d1d31a5c023c2
sha256: d78b24d0fb7c29712417e1934d4c2523bd0cb3f4f9bb412b47371e62b28ee572
sha512: 16811c09cdb45b56cc057f11857da632b29d6e681541bc2e06091e2f2bc7618b6921d30dbade97fb9866387fc4ea8e4623cf88b1daa301e31a769322b0c988d1
ssdeep: 196608:AqmITDpKQeUpg176z1p/k/zJwtPc0N5qo:eIgVMg1Oz1VQzYP75
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Bulz.593226 also known as:

Elasticmalicious (high confidence)
CAT-QuickHealTrojan.Sabsik
ALYacGen:Variant.Bulz.593226
SangforTrojan.Win32.Sabsik.FL
AlibabaTrojan:Win32/Reconyc.92e6f22b
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Reconyc.oite
BitDefenderGen:Variant.Bulz.593226
ViRobotTrojan.Win32.Z.Bulz.6383583
MicroWorld-eScanGen:Variant.Bulz.593226
TencentWin32.Trojan.Reconyc.Lneh
Ad-AwareGen:Variant.Bulz.593226
SophosMal/Generic-R
FireEyeGeneric.mg.af0beadb84d518a4
EmsisoftGen:Variant.Bulz.593226 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Reconyc.yhien
ArcabitTrojan.Bulz.D90D4A
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
McAfeeArtemis!AF0BEADB84D5
MAXmalware (ai score=89)
VBA32BScope.TrojanPSW.Python
MalwarebytesMalware.Heuristic.1003
PandaTrj/Genetic.gen
FortinetW32/PossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.593226?

Bulz.593226 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment