Malware

Should I remove “Bulz.668824”?

Malware Removal

The Bulz.668824 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.668824 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • NtSetInformationThread: attempt to hide thread from debugger
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is likely packed with VMProtect
  • Authenticode signature is invalid
  • Tries to suspend Cuckoo threads to prevent logging of malicious activity
  • Attempts to modify proxy settings

How to determine Bulz.668824?


File Info:

name: 56157CF67859BCEB12A5.mlw
path: /opt/CAPEv2/storage/binaries/fe293e079c6b04a9320a04b7c17bdaf57897a0d6d4e73c72aa97deaae5615c61
crc32: 70B5FF58
md5: 56157cf67859bceb12a582c7452678b7
sha1: b59bd5ecda5f472477faafd793d6087bdc172d63
sha256: fe293e079c6b04a9320a04b7c17bdaf57897a0d6d4e73c72aa97deaae5615c61
sha512: 7fba367e2e6dbc5c528ca99289ef9ee13bfd94303d455db203849381bccd9f73d75833649b67125d82f50b935e7748a1782047ea19c9ebaad3b2ac05ea004870
ssdeep: 393216:CqELopaSFyTdtvNAgucCgCNxc/GHTCjPw3U:CqEUpuTnNTCgCNxteN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1E633749C6A27A2F80C6CB4628CF5B5384F5D2E6D628BC73ACC9EBF986DC41114F614
sha3_384: 666d855075753cc5dc27a24676bc2afcdd9720871628ccdb70e5a037892d4ec4c5df7d03ce12995702215623703c2eaf
ep_bytes: e8eca3d700e8a3a1d7008d053ab0bf01
timestamp: 2022-04-01 02:52:24

Version Info:

FileVersion: 4.7.0.0
FileDescription: 路胜视频批量
ProductName: 路胜视频批量
ProductVersion: 4.7.0.0
CompanyName: 在路上
LegalCopyright: 在路上 版权所有
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Bulz.668824 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.668824
FireEyeGeneric.mg.56157cf67859bceb
ALYacGen:Variant.Bulz.668824
CylanceUnsafe
K7AntiVirusAdware ( 005693e61 )
BitDefenderGen:Variant.Bulz.668824
K7GWAdware ( 005693e61 )
Cybereasonmalicious.cda5f4
BaiduWin32.Packed.VMProtect.a
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/FlyStudio.Packed.AN potentially unwanted
APEXMalicious
RisingTrojan.Generic@AI.85 (RDMK:cmRtazqrrBj79UOcydJZbumwzBno)
Ad-AwareGen:Variant.Bulz.668824
EmsisoftGen:Variant.Bulz.668824 (B)
ComodoTrojWare.Win32.Agent.ISVQ@5mbonp
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
SophosMal/VMProtBad-A
GDataWin32.Application.PUPStudio.A
AviraTR/Black.Gen2
ArcabitTrojan.Bulz.DA3498
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 99)
MAXmalware (ai score=84)
SentinelOneStatic AI – Suspicious PE
MaxSecureDropper.Dinwod.frindll
BitDefenderThetaGen:NN.ZexaF.34638.@F0@a4WEB0ib
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Bulz.668824?

Bulz.668824 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment