Malware

Bulz.629685 (B) (file analysis)

Malware Removal

The Bulz.629685 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.629685 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Harvests cookies for information gathering

How to determine Bulz.629685 (B)?


File Info:

name: 70B80E57D89C0EE6E227.mlw
path: /opt/CAPEv2/storage/binaries/f818c65786ef0792e50c6a10b7d495a7ba94de3bee9120bd55bf1929092a322a
crc32: 0D016BF6
md5: 70b80e57d89c0ee6e227cafd0740b087
sha1: a72146f3f3d0307bd40ca6b2eb686e664a2be75a
sha256: f818c65786ef0792e50c6a10b7d495a7ba94de3bee9120bd55bf1929092a322a
sha512: ac29a38dbb103ffb856304122f006951f7a03faa01cae1e7fcab0c4f423742ee409172f9b4f287d7a788097ec5a5a9242b6488533d3b7be5389d97576f2c5cbf
ssdeep: 12288:IzxzTDWikLSb4NS7t2X+t40XosFUM/NysMkIesvy4JCZHPNjN/DSdS+LFZ:+DWHSb4Nc0ANSesvy9ZH3/DgFn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12B05F102BAC191B1E6711D321979AB20593BBD201B34CE9FA3DC591D9B770C1AB31BB7
sha3_384: 719223b4a4be59942666c488ae4aac6feaddd698f1033b8053b9b9a2b45d775d7b144e7abdfb7c242532459f543ee652
ep_bytes: e864040000e988feffff3b0d68e64300
timestamp: 2021-06-11 09:16:47

Version Info:

0: [No Data]

Bulz.629685 (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.629685
FireEyeGeneric.mg.70b80e57d89c0ee6
ALYacGen:Variant.Bulz.629685
Cybereasonmalicious.3f3d03
ArcabitTrojan.Bulz.D99BB5
BitDefenderGen:Variant.Bulz.629685
Ad-AwareGen:Variant.Bulz.629685
EmsisoftGen:Variant.Bulz.629685 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
SophosGeneric ML PUA (PUA)
JiangminRiskTool.BitCoinMiner.asbj
MAXmalware (ai score=87)
GDataGen:Variant.Bulz.629685
APEXMalicious
SentinelOneStatic AI – Malicious PE

How to remove Bulz.629685 (B)?

Bulz.629685 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment