Malware

How to remove “Bulz.863398”?

Malware Removal

The Bulz.863398 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.863398 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.863398?


File Info:

name: B1B1979169D2BD58A760.mlw
path: /opt/CAPEv2/storage/binaries/423fb5954dda7cf36e88671bcf1f64ead48029b27afcb36d7607de0711af2090
crc32: D271FD98
md5: b1b1979169d2bd58a7602d518ebb98cf
sha1: 3ad78a27670c98f8c6b7caa31da1c1fae760025c
sha256: 423fb5954dda7cf36e88671bcf1f64ead48029b27afcb36d7607de0711af2090
sha512: 47faf6a5dab64f55ab985c443d435ec33c87e6e2f8e1de77f5211dba1cb0a7b2ec4771f56e5f4c5269c7404345546447cb3dfb27e922a9f72ab47e88c53ec66e
ssdeep: 24576:p7AHF8z3j5D7JaT+KVvrSrtUxZA7wnNTB:psHF+3j5D78OBUEwnNTB
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T1FA555A10B3F541A5F1B39A3999B6A726EA71BC115F30C6CF1250A65E4E33AC09E35B33
sha3_384: a91a1a64b1de3678f9e0ff50e6a259fc439420caeb2703d6da1ecfdddae5459e60f66a6dd2b7f363d59cf12008c6ec58
ep_bytes: 4883ec28e85b0200004883c428e97afe
timestamp: 2021-08-11 22:26:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge
FileVersion: 92.0.902.73
InternalName: cookie_exporter_exe
LegalCopyright: Copyright Microsoft Corporation. All rights reserved.
OriginalFilename: cookie_exporter.exe
ProductName: Microsoft Edge
ProductVersion: 92.0.902.73
CompanyShortName: Microsoft
ProductShortName: Microsoft Edge
LastChange: cad199e39220991414cd71868a619fff614880c7
Official Build: 1
Translation: 0x0409 0x04b0

Bulz.863398 also known as:

LionicTrojan.Win32.Bulz.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.863398
FireEyeGen:Variant.Bulz.863398
McAfeeArtemis!B1B1979169D2
CrowdStrikewin/malicious_confidence_60% (W)
CyrenW64/Bulz.BT.gen!Eldorado
TrendMicro-HouseCallTROJ_GEN.R03BH09L321
ClamAVWin.Malware.Generic-9884574-0
BitDefenderGen:Variant.Bulz.863398
Ad-AwareGen:Variant.Bulz.863398
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win64.Generic.th
EmsisoftGen:Variant.Bulz.863398 (B)
IkarusTrojan.Win32.Skeeyah
GDataGen:Variant.Bulz.863398
JiangminPacked.Krap.gvxb
Antiy-AVLTrojan/Generic.ASMalwS.349521C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
ALYacGen:Variant.Bulz.863398
MAXmalware (ai score=86)
SentinelOneStatic AI – Suspicious PE
FortinetW32/PossibleThreat

How to remove Bulz.863398?

Bulz.863398 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment