Malware

Bulz.627592 information

Malware Removal

The Bulz.627592 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.627592 virus can do?

  • Sample contains Overlay data
  • Presents an Authenticode digital signature
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Bulz.627592?


File Info:

name: 2F544BC98BE91A5522BD.mlw
path: /opt/CAPEv2/storage/binaries/2d578996ba37cae2592e618e5696a983ac73422347c114afcaadada2360de358
crc32: ECA2D0ED
md5: 2f544bc98be91a5522bd1560a7a4d11a
sha1: 7584056702dc79ebfc26ad727cda12dd09c778ff
sha256: 2d578996ba37cae2592e618e5696a983ac73422347c114afcaadada2360de358
sha512: 060f64fe67638a4caaac53bebb67ed671ee6c4cc6dc981f24d05a8fc44bc6646c29eca86d49083abeb9313eebdc68a7b86b33b9f97a122950bb4c6276f7a170f
ssdeep: 49152:SpGsoE+rtjdbhXyw2e1Z75BSivbk5hG1Itkm7o1VoR8SSM+QHw3Xokdg0h0r:zlR7hXt2e7GOk5701Kr8XtgHr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T199E533C62F8A68ACE9273272F105FF2DC064D228FC713596F26E507689BB2E4545712F
sha3_384: 90a740a33424d6f3031248643a95353ae010050a0b32010aaf34897eb6ff12ffa0b923b1b02353484af245d6d97ca8f0
ep_bytes: 60be00805d008dbe0090e2ff66818720
timestamp: 2021-08-16 16:37:32

Version Info:

0: [No Data]

Bulz.627592 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Farfli.m!c
DrWebTrojan.MulDrop24.22581
MicroWorld-eScanGen:Variant.Bulz.627592
FireEyeGen:Variant.Bulz.627592
SkyhighArtemis!Trojan
ALYacGen:Variant.Bulz.627592
CrowdStrikewin/grayware_confidence_60% (D)
ArcabitTrojan.Bulz.D99388
BitDefenderThetaGen:NN.ZexaF.36792.epIfaixUaAej
ESET-NOD32Win32/Farfli.CTT
CynetMalicious (score: 99)
KasperskyBackdoor.Win32.Farfli.cobf
BitDefenderGen:Variant.Bulz.627592
AvastWin32:Trojan-gen
EmsisoftGen:Variant.Bulz.627592 (B)
F-SecureTrojan.TR/Farfli.jxctj
VIPREGen:Variant.Bulz.627592
TrendMicroTROJ_GEN.R011C0XKQ23
Trapminemalicious.high.ml.score
JiangminBackdoor.Farfli.fez
AviraTR/Farfli.jxctj
MAXmalware (ai score=84)
Antiy-AVLTrojan/Win32.Farfli
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmBackdoor.Win32.Farfli.cobf
GDataWin32.Trojan.Agent.4KEPS3
McAfeeArtemis!2F544BC98BE9
VBA32Backdoor.Farfli
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R011C0XKQ23
RisingBackdoor.Farfli!8.B4 (CLOUD)
IkarusTrojan.Win32.Farfli
AVGWin32:Trojan-gen
Cybereasonmalicious.702dc7

How to remove Bulz.627592?

Bulz.627592 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment