Malware

Bulz.860044 (file analysis)

Malware Removal

The Bulz.860044 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.860044 virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Bulz.860044?


File Info:

name: 8E572CAD92465FC67EB0.mlw
path: /opt/CAPEv2/storage/binaries/b99755c00967410e5eb023380a7b5c4da9bb75135bc6979258b76f93ebf82f89
crc32: 563C9AD7
md5: 8e572cad92465fc67eb06295197458e6
sha1: 13a1d55f8aceabdcbc6728276539fcdd2e21f750
sha256: b99755c00967410e5eb023380a7b5c4da9bb75135bc6979258b76f93ebf82f89
sha512: 61519e207fb95772fe0197d14309b8ebad85e4c4993e83f80c064a47ba7bb210533ca8e00e2a2d13d559035082bcbd0f9a7da357c37afc49b8a328c3d80948cf
ssdeep: 12288:TtZgkzBoN4gl7vgCsVmHGbnIiFs8xB2J2ooSprQgVpD1YkVQ2/AfxrNdjqF0weRK:TtZgqBo2K+2J27YT1YuQ2/Af5NweU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EB15AE12FA82C272E4A212718AFA97671A39ED71475492DBA3E0347D4D353E13E3B31D
sha3_384: 09625d16080ffb94714b8da8423607a1ab621e3ffdb06d77a2fc72175a6fda7ad36d74f618e343688cec761a81a69ef5
ep_bytes: e822930000e989feffff8bff558bec5d
timestamp: 2012-10-06 06:17:55

Version Info:

CompanyName: 午夜星云
FileDescription: 与文件路径有关
FileVersion: 0.0.1.1
InternalName: 梦三国秒货工具
LegalCopyright: Copyright (C) 午夜星云 2012
OriginalFilename: 梦三国.exe
ProductName: 梦三国秒货工具
ProductVersion: 0.0.1.1
Translation: 0x0009 0x04b0

Bulz.860044 also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
ClamAVWin.Trojan.Swisyn-5681
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Bulz.860044
CrowdStrikewin/grayware_confidence_60% (D)
BitDefenderGen:Variant.Bulz.860044
K7GWTrojan ( 005072391 )
K7AntiVirusTrojan ( 005072391 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.AAuto.A suspicious
APEXMalicious
CynetMalicious (score: 100)
NANO-AntivirusTrojan.Win32.Swisyn.bbykri
MicroWorld-eScanGen:Variant.Bulz.860044
RisingTrojan.Generic@AI.100 (RDML:HFnWyWOgb1k/ODG7xwg2fQ)
SophosGeneric ML PUA (PUA)
ZillyaDropper.Agent.Win32.425834
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.8e572cad92465fc6
EmsisoftGen:Variant.Bulz.860044 (B)
SentinelOneStatic AI – Malicious PE
GoogleDetected
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ArcabitTrojan.Bulz.DD1F8C
GDataWin32.Trojan.PSE.1FKB2Z4
VBA32Trojan.Swisyn
ALYacGen:Variant.Bulz.860044
DeepInstinctMALICIOUS
Cylanceunsafe
YandexTrojan.GenAsa!oMV1A/fW7dE
Cybereasonmalicious.f8acea

How to remove Bulz.860044?

Bulz.860044 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment