Is Bulbulo.zip safe?
Runtime analysis recorded injection, LSASS-targeting activity, destructive techniques, and defense impairment, outweighing the limited static detections from 3 of 75 engines.
A completed sandbox observation produced a malware finding and mapped activity to process injection, PowerShell execution, destructive behavior, and defense impairment. Only 3 of 75 engines detected the archive and no tier-1 engine flagged it, but the runtime evidence—especially LSASS targeting—carries substantially more weight.
20b18d855ec16960f0…064a95b84e051dRecommended next actions
Before opening or extracting
Do not open or extract it. Delete this archive from the device, then empty the Recycle Bin or Trash.
If you already opened or extracted it
Close it. If it opened links, requested credentials, or triggered unexpected behavior, disconnect from the internet and run a full device scan.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
A completed sandbox observation produced a malware finding and mapped activity to process injection, PowerShell execution, destructive behavior, and defense impairment. Only 3 of 75 engines detected the archive and no tier-1 engine flagged it, but the runtime evidence—especially LSASS targeting—carries substantially more weight.
Only 3 of 75 engines flagged the archive, with Zillya providing the strongest static label, Trojan.Inject.Win32.354102. No tier-1 engine detected it, so engine consensus alone would not support a strong conclusion. However, the completed runtime observation produced a malware finding and recorded five offensive MITRE mappings, including T1055, T1485, T1486, and T1562.001. The LSASS-targeting evidence and process-injection mapping reinforce that result and are not typical installer behavior. The contacted-host check covered only three of seven distinct observed domains and IPs, so network reputation is incomplete. Conflicting sandbox labels and unknown child-file outcomes reduce confidence somewhat, but do not outweigh the observed offensive behavior.
What We Detected
Three of 75 engines flagged the archive. Zillya identified Trojan.Inject.Win32.354102, while Jiangmin and Bkav supplied additional spy or generic-malware labels; no tier-1 engine reported a detection.
Threat Behavior
One completed sandbox observation produced a malware finding and mapped five offensive techniques: T1055 process injection, T1059.001 PowerShell, T1485 data destruction, T1486 impact through encryption, and T1562.001 impairment of defenses. Additional evidence indicates activity targeting lsass.exe, a sensitive credential-store process. The sample also launched an embedded executable, used PowerShell to unpack Java components, and elevated a JAR with RunAs. Host-reputation coverage was incomplete because only three of seven distinct observed domains and IPs were inspected.
What To Do Now
Do not open or extract the archive on a production system. Keep endpoint protection enabled, quarantine the file, and investigate any machine where it ran for credential access, injected processes, PowerShell activity, and possible data impact.
Where this verdict could be wrong4 caveats
- tier1Malicious=0, and 11 tier-1 engines reported no detection; several other tier-1 engines timed out.
- The sandbox verdict records conflict, containing both a malicious and a clean result within the single saved runtime analysis.
- droppedChildren.hasMaliciousChild=false, although all 10 inspected child verdicts are unknown rather than established benign.
- contactedHosts lists no malicious or suspicious hosts among three inspected entries, but it did not cover all observed domains and IPs.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- No tier-1 engine reported a detection
- Only 3/75 engines flagged the archive
- No confirmed malicious dropped child was found
- No inspected contacted host was cached as malicious or suspicious
- behaviour.hasMaliciousSandboxVerdict=true
- Five offensive MITRE mappings, including T1055, T1485, T1486, and T1562.001
- MalwareTips.Synth.CredentialDumper recorded LSASS-targeting activity
- PowerShell unpacking followed by elevated JAR execution with RunAs
- The archive is rare and was first observed three days ago
- Contacted-host reputation coverage was incomplete
Quarantine the archive and avoid executing or extracting it. If it already ran, keep security protection enabled and perform an incident-response scan focused on LSASS access, PowerShell execution, process injection, and data modification.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete3 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial3 of 7 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete2 signature or behavior rules matched.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 23MITRE ATT&CK techniques
- 14spawned processes
- 7network contacts
- 19filesystem & mutex artifacts
What this file does
Observed actions and their security significance
High concern: Injected code into another process, a technique that can conceal execution.
High concern: Encrypted files or data, behaviour commonly associated with ransomware.
High concern: Attempted to impair or bypass security controls.
High concern: Manipulated how the operating system loads code, which can redirect execution.
Moderate concern: Contained obfuscated or packed code that makes inspection harder.
Moderate concern: Runs hidden system commands (script or shell).
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
Threat context
How trojans work
A trojan disguises itself as something useful or harmless to trick you into running it. Once open, it does its real job in the background — anything from stealing data to opening a back door or downloading more malware.
Bottom line:The disguise is the whole trick, so a trustworthy-looking name or icon means nothing.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Bulbulo.zip
20b18d855ec16960f0fa7144de894bc6bb9edaef53cad9c5a9064a95b84e051d
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Users\<USER>\AppData\Local\Temp\Bulbulo.exe"
02Isolated runtime analysis - ProcessObserved
Observed process
powershell.exe -NoProfile -NonInteractive -Command " Add-Type -AssemblyName System.IO.Compression.FileSystem; [System.IO.Compression.ZipFile]::ExtractToDirectory( 'C:\Users\<USER>\AppData\Local\Temp\amazon-corretto-8.zip', 'C:\Users\<USER>\AppData\Local\Temp\java-8-corretto' ) "
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
amazon-corretto-8.zip
C:\Users\<USER>\AppData\Local\Temp\amazon-corretto-8.zip
04Isolated runtime analysis - Written fileObserved
javaw-pack.jar
C:\Users\<USER>\AppData\Local\Temp\java-8-corretto\javaw-pack.jar
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
corretto.aws
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostDerived
discord.com
Saved reputation verdict: safe.
07Contacted-host cross-check - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox; 1 returned "malicious".
Adversary techniques mapped to the MITRE ATT&CK framework.
- corretto.aws
- discord.com
- gateway.discord.gg
- 18.160.71.42
- 162.159.136.232
- 162.159.133.234
- 162.159.36.2
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\JumplistData\{1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\WindowsPowerShell\v1.0\powershell.exe
- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:000000000004011E\VirtualDesktop
- C:\Users\<USER>\AppData\Local\Temp\amazon-corretto-8.zip
- C:\Users\<USER>\AppData\Local\Temp\java-8-corretto\javaw-pack.jar
- C:\Users\<USER>\Desktop\%AppData%\Microsoft\Windows\Start Menu\Programs\Windows PowerShell\Windows PowerShell.lnk
- C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K77BZ721W7TXCUDOVH6M.temp
- C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms
- C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF12248.TMP
- C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
- C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
- C:\Users\<USER>\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF175d7.TMP
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- e8945b3c839ff2a896b9…a0c1b0Never scannednever seen before
- f5ce5433f87ca5040031…ee5e2cNever scannednever seen before
- 4e9c3c15eba82cddd7e2…15e665Never scannednever seen before
- 96ad1146eb96877eab59…87dcf7Never scannednever seen before
- 0c8724dc3acd85f75c11…1c02a7Never scannednever seen before
- 3a2d037b2f517408eb5d…9fd92bNever scannednever seen before
- 137bc9109284ffe5352a…f48a0dNever scannednever seen before
- 69989b97666a480f2dcd…d5922cNever scannednever seen before
- e858373ced25a8c12afb…9d4aa1Never scannednever seen before
- 629f2985b137fd1563b1…c5ce4bNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 3 / 75engines flagged
- 2sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 isolated runtime environment classified the observed behavior as malicious.
Verdict inputView chapterProvenanceObservedSourceIsolated runtime analysisObserved at - 02
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 03
3 of 75 antivirus engines flagged the file, including Bkav and Jiangmin.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 04
Scanned file: Bulbulo.zip — 20b18d855ec16960f0fa7144de894bc6bb9edaef53cad9c5a9064a95b84e051d
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — "C:\Users\<USER>\AppData\Local\Temp\Bulbulo.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — powershell.exe -NoProfile -NonInteractive -Command " Add-Type -AssemblyName System.IO.Compression.FileSystem; [System.IO.Compression.ZipFile]::ExtractToDirectory( 'C:\Users\<USER>\AppData\Local\Temp\amazon-corretto-8.zip', 'C:\Users\<USER>\AppData\Local\Temp\java-8-corretto' ) "
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: amazon-corretto-8.zip — C:\Users\<USER>\AppData\Local\Temp\amazon-corretto-8.zip
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: javaw-pack.jar — C:\Users\<USER>\AppData\Local\Temp\java-8-corretto\javaw-pack.jar
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: corretto.aws — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: discord.com — Saved reputation verdict: safe.
ProvenanceDerivedSourceContacted-host cross-checkObserved at
Detection sources at a glance
Category: generic-trojan
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\Explorer.EXESandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
3 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. 3 antivirus detections make that low prevalence materially relevant, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- Bulbulo.zip
- Format
- ZIP
- Code signing
- Not applicable to this file type
- Size
- 32.2 MB
- Last analyzed
- Oct 1, 2026, 1:24 AM UTC
20b18d855ec16960f0fa7144de894bc6bb9edaef53cad9c5a9064a95b84e051dSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file is dangerous. Treat it as harmful and remove it.
- Recovery step 01
Don't open or extract this archive. Delete this archive from the device, then empty the Recycle Bin or Trash.
- Recovery step 02
If you already opened or extracted it, disconnect from the internet and start with a full antivirus scan or Microsoft Defender Offline scan. If compromise is suspected or the problem persists, use a reputable second-opinion scanner and follow incident-recovery or clean-reinstall guidance.
- Recovery step 03
If any of your files were locked or renamed, do NOT pay the ransom — payment rarely restores files. Recover them from a backup instead.
- Recovery step 04
Get a fresh copy from the original trusted source and verify its exact hash when possible.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is Bulbulo.zip a virus?
What is Bulbulo.zip?
How many antivirus engines detected Bulbulo.zip?
What should I do if I already opened or extracted Bulbulo.zip?
How do I remove Bulbulo.zip?
What kind of malware is Bulbulo.zip?
What is the SHA-256 hash of Bulbulo.zip?
How up to date is this analysis of Bulbulo.zip?
Community
Member reviews and reports for this exact file hash.