Threat Database Trojans Trojan.Bulz.B

Trojan.Bulz.B

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 85
First Seen: December 10, 2021
Last Seen: August 30, 2025
OS(es) Affected: Windows

The detection of Trojan.Bulz.B on your system indicates a potential security threat that requires immediate attention. Trojans are a type of malicious software that can cause significant harm to your computer and compromise your personal data. In this report, we will provide you with an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system.

What Is Trojan.Bulz.B?

Trojan.Bulz.B is a detected threat that falls under the category of Trojan-type malware. Trojans are malicious programs that disguise themselves as legitimate software, allowing them to bypass security measures and gain unauthorized access to a system. The name "Trojan.Bulz.B" suggests that it is a specific variant of Trojan malware, but without more information, it is difficult to determine its exact characteristics or behaviors.

How Trojan.Bulz.B Operates

Trojan malware, including Trojan.Bulz.B, typically operates by exploiting vulnerabilities in a system or application, allowing it to gain access and establish a foothold. Once inside, the malware can perform a variety of malicious activities, such as stealing sensitive data, installing additional malware, or providing unauthorized access to the system. Trojans can also be used to create backdoors, allowing attackers to remotely control the infected system. The exact operating methods of Trojan.Bulz.B are unknown, but it is likely to follow similar patterns as other Trojan-type malware.

Symptoms of Infection

Systems infected with Trojan.Bulz.B may exhibit a range of symptoms, including unusual system behavior, slow performance, and unexplained changes to system settings. You may also notice suspicious network activity, such as unusual outgoing connections or data transfers. In some cases, the malware may attempt to disguise itself as a legitimate program, making it difficult to detect without proper security tools. If you suspect that your system is infected with Trojan.Bulz.B, it is essential to take immediate action to remove the threat.

How to Remove Trojan.Bulz.B

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or settings.
  5. Reboot your system and perform another full scan to ensure that the malware has been completely removed.

It is crucial to follow these steps carefully and thoroughly to ensure that the malware is removed from your system. If you are unsure about any part of the process, consider seeking assistance from a qualified IT professional or security expert.

Conclusion

The detection of Trojan.Bulz.B on your system is a serious security concern that requires prompt attention. By understanding the nature of the threat, its operating methods, and symptoms of infection, you can take effective steps to remove the malware and protect your system from future attacks. Remember to always use reputable security tools, keep your software up to date, and practice safe computing habits to minimize the risk of infection. If you have any further questions or concerns, do not hesitate to seek guidance from a trusted security expert.

Analysis Report

General information

Family Name: Trojan.Bulz.B
Signature status: Hash Mismatch

Known Samples

MD5: 8d94182db123b793cb42387c4d2fbae5
SHA1: 68b2278442a074ad9177a166f82c9633a726ac07
SHA256: 7DB94198F5CA0C09ADD0E209F5A1D9B249E2E529E569B931DEE28B95294372E6
File Size: 5.93 MB, 5928824 bytes
MD5: 8da348a83f4a089b87f9ec898640f27c
SHA1: 3704f711fd8a68b742b115aefbf7402bf270574e
SHA256: B4F0AE90269AE9B19F7328BA774DD10BDF3107BB6B947990C24DD3B946EAF067
File Size: 8.68 MB, 8684008 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have relocations information
  • File has exports table
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments
  • https://www.facebook.com/SaldeNov.OFFICIAL
  • Modified by an unpaid evaluation copy of Resource Tuner 2. http://www.heaventools.com
Company Name
  • Ates Yazilim, Bilgisayar ve Internet Teknolojileri Tic. Ltd. St.
  • Mobilecomp.net
File Description
  • HandyCafe Client
  • Novz Client Timer
File Version
  • Hokage Lvl 99
  • 4.1.1.6
Internal Name
  • HandyCafe Client
  • Novz
Legal Copyright
  • Ates Yazilim, Bilgisayar ve Internet Teknolojileri Tic. Ltd. St.
  • Salde Nov Editor-NOVS1
Legal Trademarks
  • @SaldeNov.OFFICIAL
  • Ates Yazilim, Bilgisayar ve Internet Teknolojileri Tic. Ltd. St.
Original Filename
  • hndclient.exe
Product Name
  • HandyCafe Client
  • Novz Client
Product Version
  • Hokage Lvl 99
  • 4.1.16

Digital Signatures

Signer Root Status
Ates Yazilim, Bilgisayar & Internet Teknolojileri Tic Ltd Sti Symantec Class 3 SHA256 Code Signing CA Hash Mismatch

File Traits

  • 2+ executable sections
  • HighEntropy
  • x86

Block Information

Total Blocks: 15,190
Potentially Malicious Blocks: 840
Whitelisted Blocks: 14,350
Unknown Blocks: 0

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Bulz.B
  • Diztakun.K
  • Installmonstr.EC

Files Modified

File Attributes
c:\programdata\handycafe\client\data\data.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\handycafe\client\data\sets.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\handycafe\client\dump.log Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\programdata\handycafe\client\dump.log Generic Write,Read Attributes
c:\programdata\handycafe\client\fiqugllkib_list.dat Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\downloads\language\lng.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\system.ini Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\windows\system32\drivers\etc\hosts Synchronize,Write Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer\advanced::hidden  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalldisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center::uacdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusoverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::antivirusdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::firewalldisablenotify  RegNtPreCreateKey
Show More
HKLM\software\wow6432node\microsoft\security center\svc::firewalloverride  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::updatesdisablenotify  RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\security center\svc::uacdisablenotify  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings::globaluseroffline RegNtPreCreateKey
HKLM\software\microsoft\windows\currentversion\policies\system::enablelua RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::enablefirewall RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::donotallowexceptions RegNtPreCreateKey
HKLM\system\controlset001\services\sharedaccess\parameters\firewallpolicy\standardprofile::disablenotifications  RegNtPreCreateKey
HKCU\software\apcr\1214104697::1919251317 š RegNtPreCreateKey
HKCU\software\apcr\1214104697::-456464662 RegNtPreCreateKey
HKCU\software\apcr\1214104697::1462786655 RegNtPreCreateKey
HKCU\software\apcr\1214104697::-912929324 # RegNtPreCreateKey
HKCU\software\apcr\1214104697::1006321993 Ź RegNtPreCreateKey
HKCU\software\apcr\1214104697::-1369393986 http://arqdesigngv.com.br/logo/logo.gifhttp://asch-bourj.org/ RegNtPreCreateKey
HKCU\software\apcr\1214104697::549857331 �"%�+�)���l!� ��D��>�R8�`�B�6OR:l�}Z�?{�]����&VZ(�GH� RegNtPreCreateKey
HKCU\software\apcr::u1_0 Yr�� RegNtPreCreateKey
HKCU\software\apcr::u2_0 RegNtPreCreateKey
HKCU\software\apcr::u3_0 権ă RegNtPreCreateKey
HKCU\software\apcr::u4_0 RegNtPreCreateKey
HKCU\software\handycafe\client::path c:\users\user\downloads\3704f711fd8a68b742b115aefbf7402bf270574e_0008684008 RegNtPreCreateKey
HKCU\software\handycafe\client::version 4.1.16 RegNtPreCreateKey
HKLM\software\wow6432node\handycafe\client::path c:\users\user\downloads\3704f711fd8a68b742b115aefbf7402bf270574e_0008684008 RegNtPreCreateKey
HKLM\software\wow6432node\handycafe\client::version 4.1.16 RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\run::hndclient c:\users\user\downloads\3704f711fd8a68b742b115aefbf7402bf270574e_0008684008 RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\tabbedbrowsing::warnonclose RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\tabbedbrowsing::warnoncloseadvanced RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\tabbedbrowsing::newtabpageshow  RegNtPreCreateKey
HKCU\software\microsoft\internet explorer\tabbedbrowsing::openallhomepages RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\policies\system::disabletaskmgr  RegNtPreCreateKey
HKCU\software\handycafe\client\settings::_clnorm RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserName
  • GetUserObjectInformation
Process Manipulation Evasion
  • ReadProcessMemory
Other Suspicious
  • AdjustTokenPrivileges
  • SetWindowsHookEx
Network Winsock2
  • WSAStartup
Anti Debug
  • NtQuerySystemInformation
Network Winsock
  • bind
  • gethostbyname
  • gethostname
  • inet_addr
  • setsockopt
  • socket
Network Info Queried
  • GetAdaptersInfo

Trending

Most Viewed

Loading...