Malware

About “Bulz.801907” infection

Malware Removal

The Bulz.801907 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.801907 virus can do?

  • Presents an Authenticode digital signature
  • Authenticode signature is invalid
  • The executable used a known stolen/malicious Authenticode signature
  • Anomalous binary characteristics

How to determine Bulz.801907?


File Info:

name: 12CDB727A7D5B075AA1E.mlw
path: /opt/CAPEv2/storage/binaries/402e4f4d05ee1205ac892a9f21bcfbedde0d25d85d545ff25fdaaead9abcf59f
crc32: 71C5601B
md5: 12cdb727a7d5b075aa1e4111bf205066
sha1: 035a69b40e6adb9e06d3c3c53d580de2ebf5ef4c
sha256: 402e4f4d05ee1205ac892a9f21bcfbedde0d25d85d545ff25fdaaead9abcf59f
sha512: dd8f0e8e370baf9264cdbc9d046bcf29f6e197e10cd3ca0076699ba1574e09375bbc162dac6ed182ab7b4aaa1f5288e66d0d149397f352bca27e6960c49982d2
ssdeep: 6144:LoISwMd7wvcULnZ2wo2sj0tTcZcpuSGcJQdbyw:LVSwM+Vd2wMj0bidn
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T13E544946A3AC7CEDE06A813449B19491AB35FC321360D28F66B5774A1E333D3BD29736
sha3_384: d49719589cab56a66518866379c18f45cc3f26f65941da5e375ad1bd444708b53ad88c4b4317235f900a2ef21873c714
ep_bytes: 4883ec28e8670800004883c428e9f6fd
timestamp: 2021-02-19 13:48:51

Version Info:

CompanyName: Python Software Foundation
FileDescription: Python
FileVersion: 3.9.2
InternalName: Python Application
LegalCopyright: Copyright © 2001-2021 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.
OriginalFilename: pythonw.exe
ProductName: Python
ProductVersion: 3.9.2
Translation: 0x0000 0x04b0

Bulz.801907 also known as:

Elasticmalicious (high confidence)
DrWebWin32.HLLW.Autoruner.547
MicroWorld-eScanGen:Variant.Bulz.801907
FireEyeGen:Variant.Bulz.801907
McAfeeArtemis!12CDB727A7D5
CylanceUnsafe
CyrenW64/Agent.DLO.gen!Eldorado
ClamAVWin.Malware.Genpack-9877676-0
BitDefenderGen:Variant.Bulz.801907
AvastWin32:VB-FBX
Ad-AwareGen:Variant.Bulz.801907
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win64.Virus.dh
EmsisoftGen:Variant.Bulz.801907 (B)
GDataGen:Variant.Bulz.801907
ArcabitTrojan.Bulz.DC3C73
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32Worm.AutoRun
ALYacGen:Variant.Bulz.801907
MAXmalware (ai score=80)
MalwarebytesMalware.AI.3696146603
TrendMicro-HouseCallTROJ_GEN.R03BH0CL421
YandexTrojan.GenAsa!g8z8LT30jj4
IkarusTrojan.Dropper
FortinetW64/Autorun.BJD!tr
AVGWin32:VB-FBX
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Bulz.801907?

Bulz.801907 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment