SecuriteInfo.com.Variant.Bulz.386265.27040.5090
Classification: Malicious
SecuriteInfo.com.Variant.Bulz.386265.27040.5090 is a malicious file sample. Linked to Servhelper malware. Reported by 1 threat source, last seen 2021-03-18.
Detection summary
- 74 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: SERVHELPER (S0382)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| ServHelper | Abuse.ch | 2021-03-18 12:56:30 | 2021-03-18 12:56:30 | malicious-activity | S0382 ServHelper |
Sample information
- Filenames
- SecuriteInfo.com.Variant.Bulz.386265.27040.5090
- File type
- application/x-dosexec
- MD5
f111dbe60c4dbff789a64d3a1145edd7- SHA-1
1d8809af5064e34d19a266c2b4b30d279a78976a- SHA-256
b591e73c3ebfe7ba44eb161c3cc1ee7b9a794d4e9b9b9aa4e3936f518e814ceb- First indexed
- 2021-03-18 14:15:11
- Last updated
- 2026-05-05 07:44:59
Antivirus detections
| Engine | Detection |
|---|---|
| MicroWorld-eScan | Gen:Variant.Bulz.386265 |
| FireEye | Gen:Variant.Bulz.386265 |
| McAfee | Artemis!F111DBE60C4D |
| CrowdStrike | win/malicious_confidence_60% (D) |
| Cyren | W64/GoClr.A.gen!Eldorado |
| ESET-NOD32 | a variant of WinGo/GoCLR.A |
| APEX | Malicious |
| Kaspersky | UDS:DangerousObject.Multi.Generic |
| BitDefender | Gen:Variant.Bulz.386265 |
| Ad-Aware | Gen:Variant.Bulz.386265 |
| Emsisoft | Gen:Variant.Bulz.386265 (B) |
| McAfee-GW-Edition | BehavesLike.Win64.Generic.vh |
| Sophos | ML/PE-A |
| GData | Gen:Variant.Bulz.386265 |
| Jiangmin | Trojan.Cobalt.ic |
| Arcabit | Trojan.Bulz.D5E4D9 |
| AhnLab-V3 | Trojan/Win64.Generic.R372645 |
| Microsoft | Trojan:Win32/Wacatac.B!ml |
| Cynet | Malicious (score: 100) |
| MAX | malware (ai score=80) |
| Malwarebytes | Malware.AI.4281202999 |
| Fortinet | W64/GoCLR.A!tr |
| ALYac | Backdoor.Agent.ServHelper |
| AVG | Win64:Trojan-gen |
| Alibaba | TrojanDropper:Win64/Donipye.f062b17b |
| Antiy-AVL | Trojan[Dropper]/MSIL.Agent |
| Arcabit | Trojan.Injector.155 |
| Avast | Win64:Trojan-gen |
| Avira | HEUR/AGEN.1318170 |
| BitDefender | Gen:Variant.Injector.155 |
| Bkav | W64.AIDetectMalware |
| CAT-QuickHeal | Trojan.Ghanarava.162896936645edd7 |
| CTX | exe.trojan.goclr |
| ClamAV | Win.Malware.Bulz-9847817-0 |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.MulDrop16.31716 |
| Elastic | malicious (high confidence) |
| Emsisoft | Gen:Variant.Injector.155 (B) |
| F-Secure | Heuristic.HEUR/AGEN.1318170 |
| FireEye | Gen:Variant.Injector.155 |
| GData | Gen:Variant.Injector.155 |
| Detected | |
| Gridinsoft | Trojan.Win64.Agent.oa!s1 |
| Ikarus | Trojan.WinGo.Rozena |
| K7AntiVirus | Trojan ( 0057c5571 ) |
| K7GW | Trojan ( 0057c5571 ) |
| Kaspersky | Trojan-Dropper.MSIL.Agent.seskgy |
| Lionic | Trojan.MSIL.Agent.b!c |
| Malwarebytes | Generic.Malware.AI.DDS |
| MaxSecure | Trojan.Malware.1728101.susgen |
| McAfee | GenericRXAA-AA!F111DBE60C4D |
| McAfeeD | ti!B591E73C3EBF |
| MicroWorld-eScan | Gen:Variant.Injector.155 |
| Microsoft | Trojan:Win64/Donipye.STH |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | HackTool.GoCLR!1.D71D (CLASSIC) |
| Sangfor | Trojan.Win32.Save.a |
| SentinelOne | Static AI - Malicious PE |
| Skyhigh | BehavesLike.Win64.Kryptik.vh |
| Sophos | Mal/Generic-S |
| Symantec | ML.Attribute.HighConfidence |
| Tencent | Msil.Trojan-Dropper.Agent.Dplw |
| TrendMicro-HouseCall | Trojan.Win32.VSX.PE04C9V |
| VBA32 | TrojanDropper.MSIL.Agent |
| VIPRE | Gen:Variant.Injector.155 |
| Varist | W64/GoClr.A.gen!Eldorado |
| Webroot | W32.Trojan.Gen |
| Xcitium | Malware@#uofyrct8ax0a |
| Zillya | Trojan.GoCLR.Win32.29 |
| alibabacloud | Trojan[dropper]:Multi/GoCLR.A |
| huorong | TrojanDownloader/W64.Agent.c |