Malware

About “Bulz.72403” infection

Malware Removal

The Bulz.72403 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.72403 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • Queries information on disks, possibly for anti-virtualization
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
akconsult.linkpc.net

How to determine Bulz.72403?


File Info:

crc32: B86BAFD5
md5: bc89e655d02d832bb691e80bf9998a40
name: BC89E655D02D832BB691E80BF9998A40.mlw
sha1: 488bfc15dae66912334d36667fdc6d9a01c773ad
sha256: 288c2b8a892fccff6fb94aeb90ae791322892d5ac1949f19f71b1664edc19c28
sha512: b2521d7422184187d556b6a837228c7e87978aa3fc3afe42b301a7c81791dcc7ec8478251ffac1b0530ae756d5d5d24d8ae451e75316a95e42ea781d33fef4f7
ssdeep: 12288:2XdaJcOSQ75uR0LCr9zzY6EO7YDzAMe6ABsOXJ:2XzJQIgUx95
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Bulz.72403 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 7000000f1 )
LionicTrojan.Win32.Foreign.j!c
Elasticmalicious (high confidence)
DrWebBackDoor.Wirenet.144
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.72403
CylanceUnsafe
ZillyaTrojan.Foreign.Win32.59536
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Foreign.a46087a3
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.5d02d8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Injector.CZWP
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Foreign.nupz
BitDefenderGen:Variant.Bulz.72403
NANO-AntivirusTrojan.Win32.Wirenet.evrmgx
MicroWorld-eScanGen:Variant.Bulz.72403
TencentWin32.Trojan.Foreign.Piab
Ad-AwareGen:Variant.Bulz.72403
SophosMal/Generic-S
ComodoMalware@#11hm7nbbqqtu
BitDefenderThetaAI:Packer.744ADE8318
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Infected.dt
FireEyeGeneric.mg.bc89e655d02d832b
EmsisoftGen:Variant.Bulz.72403 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Foreign.dxj
AviraDR/Delphi.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2396CE7
MicrosoftBackdoor:Win32/NetWiredRC.C
ArcabitTrojan.Bulz.D11AD3
ZoneAlarmTrojan-Ransom.Win32.Foreign.nupz
GDataGen:Variant.Bulz.72403
McAfeeArtemis!BC89E655D02D
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Foreign
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_Foreign.R002C0GIG21
RisingTrojan.Generic@ML.86 (RDML:1rGjWWCkRTKoBsBN+EwE7g)
YandexTrojan.GenAsa!Ow14qLhBCVU
IkarusTrojan.Win32.Injector
FortinetW32/Generic.AC.27844c!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Bulz.72403?

Bulz.72403 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment