Malware

What is “Bulz.8554”?

Malware Removal

The Bulz.8554 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.8554 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Network activity contains more than one unique useragent.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
a.clickdata.37wan.com
gameapp.37.com
img1.37wanimg.com
img2.37wanimg.com
ptres.37.com
d.wanyouxi7.com

How to determine Bulz.8554?


File Info:

crc32: 93315D9C
md5: be8cfc2526efcc21da279e97faac0ccd
name: ddqjh_wqeq.exe
sha1: cde7dc54797056c2afcb852fa178db49fa529657
sha256: 5557bc2b4439f7e348cc30dfab22714f051296d8906691256d1280715cb40825
sha512: 5951360882c7790700d6907dc9915f181f9446538cb44c03a59f0cf45b53d85a1ad05293b4b4c24c59771fe73fb6f1e0134968c640db8db3f610da3fe1f00bed
ssdeep: 49152:RMumM6xRN9GfpB9EbWMVjHg9/chd/ww1vQr/wi6LfUwRD:qZRSfprEW/0zisLtRD
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

LegalCopyright: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
FileVersion: 3.0.0.0
CompanyName: x4e0ax6d77x4e09x4e03x73a9x7f51x7edcx79d1x6280x6709x9650x516cx53f8
ProductName: x83bdx8352x7eaa2
ProductVersion: 3.0.0.0
FileDescription: x83bdx8352x7eaa2 install
Translation: 0x0804 0x03a8

Bulz.8554 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.8554
FireEyeGeneric.mg.be8cfc2526efcc21
CAT-QuickHealApplication.Agent.ZZ5
McAfeeArtemis!BE8CFC2526EF
CylanceUnsafe
K7AntiVirusAdware ( 004fef751 )
BitDefenderGen:Variant.Bulz.8554
K7GWAdware ( 004fef751 )
CrowdStrikewin/malicious_confidence_60% (D)
SymantecSMG.Heur!gen
Kasperskynot-a-virus:AdWare.Win32.Wews87.eln
AlibabaAdWare:Win32/Wews87.5d020e7e
RisingMalware.Heuristic!ET#83% (RDMK:cmRtazrc1H3/9F/b+bSElhfA6Ug+)
ComodoApplication.Win32.Wews87.E@7mby71
F-SecureAdware.ADWARE/Wews87.otgyv
DrWebProgram.Unwanted.3980
Invinceaheuristic
SophosGeneric PUA MN (PUA)
APEXMalicious
AviraADWARE/Wews87.xtyzk
MAXmalware (ai score=87)
ArcabitTrojan.Bulz.D216A
ZoneAlarmnot-a-virus:AdWare.Win32.Wews87.eln
MicrosoftPUA:Win32/Caypnamer.A!ml
VBA32BScope.Adware.Wews
MalwarebytesAdware.ChinAd
ESET-NOD32a variant of Win32/Wews87.B potentially unwanted
FortinetRiskware/Wews87
IkarusAdWare.Wews87
eGambitUnsafe.AI_Score_99%
GDataGen:Variant.Bulz.8554
AVGFileRepMetagen [Adw]
Qihoo-360Generic/Trojan.233

How to remove Bulz.8554?

Bulz.8554 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment