Malware

Bulz.858230 malicious file

Malware Removal

The Bulz.858230 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.858230 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • .NET file is packed/obfuscated with Confuser
  • Authenticode signature is invalid
  • Anomalous .NET characteristics

How to determine Bulz.858230?


File Info:

name: EF958837619BA6DEEDD0.mlw
path: /opt/CAPEv2/storage/binaries/51a38fd45a8be20d8b9fea813ea6f4fdb9d8823fd1a0605a50772f13583bc98f
crc32: 48D8EFA2
md5: ef958837619ba6deedd08ce3bf287136
sha1: a92cfe6de95ed44815d97954a221e53e28b6cfbf
sha256: 51a38fd45a8be20d8b9fea813ea6f4fdb9d8823fd1a0605a50772f13583bc98f
sha512: 595ae9b5e4be1d3211fafcd1a7ab36ae1577d0f49a8497a641c7090c334a69bd3733a2505d7e8591397c6bee5be3d36aca480eeecd9637f29cc29e6d003b8806
ssdeep: 3072:Tw7KQALDKY4ZY/KPPSvSkXpmLZSOzDl6BcrKMqMkhLK/VOZcnnnnnI:KKPKpu4SQ/rXqS7nnnnn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T126E34CEEFAFD9E81DB1D0B37C153602C8167E4674215F3DA95C84E32AEA06E5C58B8D0
sha3_384: ed0382c1ca6558f18572d896f7fc0e2444b46b6a6e9805e6476ee1b134e1f2955a8d7ba64ad1c8ca6c866f35258d9d6d
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-10-11 17:40:11

Version Info:

0: [No Data]

Bulz.858230 also known as:

BkavW32.AIDetectNet.01
MicroWorld-eScanGen:Variant.Bulz.858230
FireEyeGeneric.mg.ef958837619ba6de
CAT-QuickHealBackdoor.Bladabindi
ALYacGen:Variant.Bulz.858230
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
K7GWTrojan ( 700000121 )
Cybereasonmalicious.7619ba
BaiduMSIL.Backdoor.Bladabindi.a
CyrenW32/MSIL_Bladabindi.C.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Bladabindi.DW
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Bulz.858230
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Bulz.858230
EmsisoftGen:Variant.Bulz.858230 (B)
VIPREGen:Variant.Bulz.858230
TrendMicroTROJ_GEN.R014C0DJB22
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cm
Trapminemalicious.high.ml.score
SophosML/PE-A
IkarusBackdoor.MSIL.Bladabindi
JiangminBackdoor.MSIL.bgwv
AviraTR/Dropper.MSIL.Gen2
MicrosoftBackdoor:MSIL/Bladabindi.AN
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Bulz.858230
GoogleDetected
Acronissuspicious
McAfeeArtemis!EF958837619B
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
TrendMicro-HouseCallTROJ_GEN.R014C0DJB22
RisingTrojan.Generic/MSIL@AI.98 (RDM.MSIL:Hat0SKUUBwdUwVgFEsU3vA)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Generic.DN.116D22!tr
BitDefenderThetaGen:NN.ZemsilF.34726.imW@aui09Ei
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Bulz.858230?

Bulz.858230 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment