Malware

Bulz.764598 malicious file

Malware Removal

The Bulz.764598 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.764598 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Bulz.764598?


File Info:

name: 168C4230F86E1CBADC20.mlw
path: /opt/CAPEv2/storage/binaries/12bc5dfd1b4c1ad27be66dd1a0a870099d9493a808b3d498871bd31a71d41190
crc32: 67F4B03D
md5: 168c4230f86e1cbadc20b2fa511f5f69
sha1: db0e039546496f3d1c0edc6361688474fb0ef704
sha256: 12bc5dfd1b4c1ad27be66dd1a0a870099d9493a808b3d498871bd31a71d41190
sha512: 244faa3dbb62a257b8b7326e657f2a461b4e9170e8fd5925900c2a500cd0ce73491aca2563952cbdb752ab426bf88a2eeb6b1c54d767624a649ab2d883e7bbfb
ssdeep: 49152:eUI08BbD1VqjsrGKTxelGhFNRE+CwmYCk3CZC8Z6uIy:eTJVqwZThjRE+CwmRkSZC8ZZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EFF5BF43F7A39C61DEB211F001FB9639C6619F049B22EAC7A7743A89D9F12E05E352C5
sha3_384: 729d2a68d3ab26fd615e81abac21b0eb67a43493a26ad0f1aa955a680d586f7d161b737ff4324238fed13227c682254b
ep_bytes: c3000000000000000000000000000000
timestamp: 2018-12-10 16:39:12

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName:
FileDescription:
FileVersion: 1.0.0.0
InternalName: Loader.exe
LegalCopyright: Copyright © 2019 By @3eni Private Programs
LegalTrademarks:
OriginalFilename: Loader.exe
ProductName:
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Bulz.764598 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.764598
ClamAVWin.Malware.Fuerboos-7700490-0
FireEyeGeneric.mg.168c4230f86e1cba
McAfeeArtemis!168C4230F86E
SangforTrojan.Win32.Save.a
AlibabaPacked:Win32/BoxedApp.218823b4
Cybereasonmalicious.0f86e1
BitDefenderThetaGen:NN.ZexaF.36348.Cx0@amxKN6nc
CyrenW32/BoxedApp.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.BoxedApp.A
APEXMalicious
CynetMalicious (score: 100)
BitDefenderGen:Variant.Bulz.764598
AvastFileRepMalware [Trj]
SophosMal/Generic-S
VIPREGen:Variant.Bulz.764598
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
EmsisoftGen:Variant.Bulz.764598 (B)
SentinelOneStatic AI – Suspicious PE
ArcabitTrojan.Bulz.DBAAB6
GDataGen:Variant.Bulz.764598
GoogleDetected
ALYacGen:Variant.Bulz.764598
MAXmalware (ai score=77)
VBA32Trojan.Inject
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:h4zLsmmu1fFDP4B/wchffg)
IkarusTrojan.Win32.Boxedapp
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AC.43D44A!tr
AVGFileRepMalware [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.764598?

Bulz.764598 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment