Malware

Bulz.687816 (file analysis)

Malware Removal

The Bulz.687816 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.687816 virus can do?

  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine Bulz.687816?


File Info:

name: FBAAC2CBB7319AC4F294.mlw
path: /opt/CAPEv2/storage/binaries/627a03c0dcae3ab276c4ad48ee8333b4eb164c7265387024773ac2dd4208bf6f
crc32: 70F3B89E
md5: fbaac2cbb7319ac4f294506e0ecb1fb2
sha1: 848ceb4a8f9bbc9c4475f6dbb6bb6b52d3b77b09
sha256: 627a03c0dcae3ab276c4ad48ee8333b4eb164c7265387024773ac2dd4208bf6f
sha512: 5bb7cbb0aa963ac76c41280d75744bf3ea8214ab3ebc22eca5d3a94fb6d1c9526b6e85e3f9b2bae619d53f76ddb3073de6669fbe528fc39fc5be3738590fbbf1
ssdeep: 1536:lvXRncGIJ1+RoWwT829iqn/GzbaaoUwZEDFxtwE5qfZVZYCyiyO53rgq6i/1lmLs:lvhctJQRe8SnIfLD3twzbaNleIbe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E6B39F709097B552F10AC5F067E8BFA3027239F3EACF1A39522A57378BEDA413A4454D
sha3_384: 9c117429af9b99186aae8952f2015c94f47f786615c02fd36528e4a6f49beb76c253c3b6696f5560760ce60e56880876
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-09-02 18:19:24

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: runPPe
FileVersion: 1.0.0.0
InternalName: runPPe.exe
LegalCopyright: Copyright © Microsoft 2021
OriginalFilename: runPPe.exe
ProductName: runPPe
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.687816 also known as:

BkavW32.AIDetectMalware.CS
Elasticmalicious (moderate confidence)
MicroWorld-eScanGen:Variant.Bulz.687816
FireEyeGeneric.mg.fbaac2cbb7319ac4
SkyhighArtemis!Trojan
McAfeeArtemis!FBAAC2CBB731
MalwarebytesTrojan.Downloader
ZillyaTrojan.GenKryptik.Win32.105816
SangforTrojan.Win32.Kryptik.V3sz
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/GenKryptik.401f238e
K7GWTrojan ( 0059ed541 )
K7AntiVirusTrojan ( 0059ed541 )
ArcabitTrojan.Bulz.DA7EC8
VirITTrojan.Win32.MSIL_Heur.A
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/GenKryptik.FJZI
APEXMalicious
TrendMicro-HouseCallTROJ_GEN.R002C0WA924
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.687816
NANO-AntivirusTrojan.Win32.Kryptik.juvisg
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.13bff2b0
EmsisoftGen:Variant.Bulz.687816 (B)
VIPREGen:Variant.Bulz.687816
TrendMicroTROJ_GEN.R002C0WA924
SophosMal/Generic-S
IkarusTrojan-Downloader.MSIL.Tiny
GoogleDetected
VaristW32/ABRisk.JMTE-2773
Antiy-AVLTrojan/MSIL.GenKryptik
KingsoftWin32.Trojan.Generic.a
MicrosoftTrojan:Win32/Fareit!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Bulz.687816
AhnLab-V3Trojan/Win.Generic.C4643184
ALYacGen:Variant.Bulz.687816
MAXmalware (ai score=80)
Cylanceunsafe
PandaTrj/GdSda.A
RisingMalware.Obfus/MSIL@AI.87 (RDM.MSIL2:JZke5+WMOwl9ICAJnDdZig)
YandexTrojan.Agent!UmG8Rf9M3ZE
MaxSecureTrojan.Malware.7164915.susgen
FortinetMSIL/Agent.PHB!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS

How to remove Bulz.687816?

Bulz.687816 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment