Malware

Bulz.868738 (B) malicious file

Malware Removal

The Bulz.868738 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Bulz.868738 (B) virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Dynamic (imported) function loading detected
  • Presents an Authenticode digital signature
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Bulz.868738 (B)?


File Info:

name: A947C6268961D325F3B4.mlw
path: /opt/CAPEv2/storage/binaries/6d5e62f008bc4a986e4d7c3f1265d7d8d2e1c0866a309a37ca430e3931c44973
crc32: A3FCAE36
md5: a947c6268961d325f3b4e789e2c9bbe5
sha1: c3d1c12160a9ecd15c23fdab099dbf0191650aae
sha256: 6d5e62f008bc4a986e4d7c3f1265d7d8d2e1c0866a309a37ca430e3931c44973
sha512: 8fa6c201376af787d7b6c6f0578a4ffb5182a1d7b87a7ddd8e727cb9b8ee3a02597f521f601286897f7bc883f9cb9c7ea45a5d6da521c9f7347a34a1702d76c9
ssdeep: 49152:p5SSCwnNTBKoJdXN0BMOwLloBrugbakOElMaFLkZ2RAR5FeA6w:p5ZHJdXN0B7+sNak7q
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T183E56C1DFEA18C75E1B342308965A33DA675BD300931D61F6280FA4DDE71FA29D26B23
sha3_384: 1b7bf59329b6415f72af94d3eba6b59532f6536569775e96997dee5b8e7d979b15b06877f96e9400462de633dbf502a0
ep_bytes: 4883ec28e85b0200004883c428e97afe
timestamp: 2021-08-11 22:26:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge
FileVersion: 92.0.902.73
InternalName: cookie_exporter_exe
LegalCopyright: Copyright Microsoft Corporation. All rights reserved.
OriginalFilename: cookie_exporter.exe
ProductName: Microsoft Edge
ProductVersion: 92.0.902.73
CompanyShortName: Microsoft
ProductShortName: Microsoft Edge
LastChange: cad199e39220991414cd71868a619fff614880c7
Official Build: 1
Translation: 0x0409 0x04b0

Bulz.868738 (B) also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Bulz.868738
ALYacGen:Variant.Bulz.868738
SangforTrojan.Win32.Save.a
CyrenW64/Bulz.BT.gen!Eldorado
ClamAVWin.Trojan.Blackie-9838328-0
BitDefenderGen:Variant.Bulz.868738
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win64.BadFile.wh
FireEyeGen:Variant.Bulz.868738
EmsisoftGen:Variant.Bulz.868738 (B)
SentinelOneStatic AI – Malicious PE
Antiy-AVLTrojan/Generic.ASMalwS.349521C
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Variant.Bulz.868738
McAfeeArtemis!A947C6268961
MAXmalware (ai score=82)
TrendMicro-HouseCallTROJ_GEN.R03BH09L721
IkarusTrojan.Autorun
FortinetW64/Bulz.BT!tr
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Bulz.868738 (B)?

Bulz.868738 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment