Malware

Bulz.628365 information

Malware Removal

The Bulz.628365 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.628365 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Bulz.628365?


File Info:

name: 06DC07AEED1AE3155264.mlw
path: /opt/CAPEv2/storage/binaries/71a6d7874b86f32f63e1dd5ffb24f1b09f6c66795ab06a2ad65e84c427d5e884
crc32: 5DB3620B
md5: 06dc07aeed1ae3155264d8ce0b008d9e
sha1: 222c9b54b51c7805dfcc4927190fbd555197ad4f
sha256: 71a6d7874b86f32f63e1dd5ffb24f1b09f6c66795ab06a2ad65e84c427d5e884
sha512: ae37c5b79702c690bcdae58de9a32a9ffb2459749caa1c41a297dd73d9753a5427afbaf8482005df65e9d875edbe245a0aba2ad9abca48341de936d4110c552f
ssdeep: 192:hoLPSvCTVsnlYJLLLTXbenRIWWKIvQvcJ:hoLiCTbPLTXboIXKIrJ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18522E705F7E543F2CB66173768639B421B6AEC006D23A71FB4D4B66F9DB320C4162A72
sha3_384: 534b8116b797c31e75267539d09dd833b315788a6df9e4dff101194dc7a8774bfbde910eab19476ff3de59cc616e97c1
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-02-07 20:46:16

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: Windows Media Player.exe
LegalCopyright:
OriginalFilename: Windows Media Player.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Bulz.628365 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.628365
FireEyeGeneric.mg.06dc07aeed1ae315
ALYacGen:Variant.Bulz.628365
CylanceUnsafe
ZillyaTrojan.Hesv.Win32.1683
SangforTrojan.Win32.Save.a
AlibabaTrojan:MSIL/Generic.0f69895b
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZemsilF.34212.am0@airj55n
CyrenW32/Razy.CL.gen!Eldorado
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PB922
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.Hesv.gen
BitDefenderGen:Variant.Bulz.628365
SUPERAntiSpywareAdware.DotDo/Variant
AvastWin32:Malware-gen
TencentMsil.Trojan.Hesv.Hfo
Ad-AwareGen:Variant.Bulz.628365
EmsisoftGen:Variant.Bulz.628365 (B)
TrendMicroTROJ_GEN.R002C0PB922
McAfee-GW-EditionBehavesLike.Win32.Generic.lt
SophosMal/Generic-S
IkarusTrojan.Hesv
GDataGen:Variant.Bulz.628365
AviraHEUR/AGEN.1221800
MAXmalware (ai score=87)
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Bulz.D9968D
ZoneAlarmHEUR:Trojan.MSIL.Hesv.gen
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 99)
AhnLab-V3Malware/RL.Generic.R242845
McAfeeGenericRXGT-XU!06DC07AEED1A
TACHYONTrojan/W32.DN-Hesv.10752
VBA32TScope.Trojan.MSIL
APEXMalicious
RisingTrojan.Generic/MSIL@AI.100 (RDM.MSIL:Zikc6lLLyIP65d/0w6YraA)
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Hesv.XU!tr
AVGWin32:Malware-gen
Cybereasonmalicious.eed1ae
PandaTrj/CI.A

How to remove Bulz.628365?

Bulz.628365 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment