Threat Database Trojans Trojan.Farfli.FP

Trojan.Farfli.FP

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 3,022
Threat Level: 80 % (High)
Infected Computers: 349
First Seen: January 1, 2025
Last Seen: July 20, 2026
OS(es) Affected: Windows

The detection of Trojan.Farfli.FP on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system. It is essential to address this issue promptly to prevent potential damage to your computer and protect your personal data.

What Is Trojan.Farfli.FP?

Trojan.Farfli.FP is identified as a Trojan-type threat, which is a broad category of malware designed to deceive users by appearing as legitimate software. The name itself does not directly indicate a specific malware family, but its classification as a Trojan suggests it is designed to gain unauthorized access to a computer system. Trojans can be used for various malicious purposes, including data theft, spyware, ransomware, or as a backdoor for other malware.

How Trojan.Farfli.FP Operates

Like other Trojans, Trojan.Farfli.FP likely operates by disguising itself as a harmless or useful application. Once installed on a system, it can execute a range of malicious activities. Trojans often rely on social engineering tactics to trick users into installing them. This can be through email attachments, downloads from untrusted websites, or infected software downloads. After installation, the Trojan can communicate with its command and control servers to receive instructions, which might include stealing sensitive information, downloading additional malware, or using the infected computer for malicious activities such as DDoS attacks.

Symptoms of Infection

Symptoms of a Trojan infection can vary widely depending on the specific goals of the malware. Common signs include unusual system behavior, such as slow performance, unexpected pop-ups, or changes to browser settings. Some Trojans are designed to operate stealthily, making them difficult to detect without specific security software. If your system has been flagged for Trojan.Farfli.FP, it's crucial to take the warning seriously, even if you don't notice any immediate symptoms, as the malware could be running in the background.

How to Remove Trojan.Farfli.FP

  1. Enter Safe Mode with Networking to prevent the malware from interfering with the removal process. This mode allows you to use the internet to download removal tools while limiting the malware's ability to run.
  2. Perform a full scan of your system using a reputable anti-malware tool such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the Trojan.
  3. Uninstall suspicious programs that you do not recognize or that were installed around the time the Trojan was detected. Be cautious and only remove programs you are sure are not essential to your system's operation.
  4. Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
  5. Reboot your system and then perform another full scan to ensure the Trojan and any associated malware have been completely removed.

Conclusion

Removing Trojan.Farfli.FP from your system requires careful steps to ensure complete eradication. It's also a good opportunity to review your security practices, such as ensuring your operating system and software are up to date, using strong, unique passwords, and being cautious with emails and downloads from unknown sources. Regularly scanning your system with anti-malware tools and maintaining a robust security suite can help protect against future threats. Remember, prevention is key, but swift action upon detection can significantly mitigate the risks associated with malware infections.

Analysis Report

General information

Family Name: Trojan.Farfli.FP
Signature status: No Signature

Known Samples

MD5: c997486974eeb266a3ab66f1d1d53f29
SHA1: 13815a78218c2403e3063eabca94ef56046b9cf5
SHA256: FA419E4C3E1E13FACCA4F5ABE1499400C962A9CB667A218D8DAA4FA0614CEE61
File Size: 2.00 MB, 2002944 bytes
MD5: 2672ae0a91f2a2365269094d835d0ea8
SHA1: 3ca4bf1e4831d9656ca6c051c8be8864699d4625
SHA256: 627EB85BEA403E967AD280CFC68916B80B450C2B004B7C9E0EA13232B5360498
File Size: 2.76 MB, 2764860 bytes
MD5: ca651ab5316fdb9d158fcff96b8388d9
SHA1: 8c04d05e303184b10f4c26ea61b9a20046abc885
SHA256: 77F8EF2E80553962AC8066B35C8CE895791BE8BABFD5119A3A7EFDE002BF0357
File Size: 45.06 KB, 45056 bytes
MD5: 3f860d177522945848b03e06c9a4a701
SHA1: 5ca099b1aeac2082346ad7ebcc3bd8f72ccf84a5
SHA256: 5567C3BED9EDF2927EAFFF84F4A88FC9C663E6C18C5121F9B8B988CB344DDB08
File Size: 2.04 MB, 2039808 bytes
MD5: 30058b79cd933ae85f81c051573d8206
SHA1: 99f34709fac2f949f97626656c80a00690c9de69
SHA256: E944817D438EC152C82AB9D17B43BB2EC8B02EE1DBBE713D79ACC9A9E729EC4B
File Size: 1.19 MB, 1191936 bytes
Show More
MD5: 829474dbd67a7160ae392b171f9252a3
SHA1: 56d0414ccd37d3f133f2720a99c759047aee8035
SHA256: 7ECD511EB33B1B7FA8512B0C676F454562F17B2FFB2072E78D9C6607AAE81811
File Size: 2.06 MB, 2060288 bytes
MD5: cbba5df81a8c8b50b000a1aec58222b6
SHA1: 59a5247fec86b1fea799228a29bae60aec4f4e7d
SHA256: 2A81749E3FA96BBB6434A1EDB6509DFFC9C95A7DC7B80CB6B511686A9F5D82C3
File Size: 438.27 KB, 438272 bytes
MD5: 8d84d9a404e3f4e6438a6fa56f07f6b4
SHA1: 18de5c0c3d52cd643f13b2927e5615bed31b25e8
SHA256: 302243BF9BF8BC9DAC3556B2932979BA2431D12741A34FBF68CA96CAD9966E58
File Size: 2.11 MB, 2113536 bytes
MD5: 5df8f122bafa344ab681d40a7c901206
SHA1: ee97f34e4f61747e8941d6fe056adf1821160bc1
SHA256: 96485133E150D9617A2632D8C6DFBE54E179011394124100936A1769E86EF4A9
File Size: 450.56 KB, 450560 bytes
MD5: 79388626525f487cec5c4a128f7fd183
SHA1: 156e8283abe1519e5ec2fc687b5500a702a9cd6c
SHA256: 26560A32C80CC0043BC306D56A0FE7299202F24646AA59A776289B923ABAF1D6
File Size: 331.78 KB, 331776 bytes
MD5: 9bf903c93108822f4192d677d3e92f1c
SHA1: 81fe7107d480ed4ba3ad4429b9a68499457569be
SHA256: 3669551B0A5B32C73956B447EE3B6A5102F13CBBBC3B8C7DAEAFCFC90C6CE817
File Size: 172.03 KB, 172032 bytes
MD5: a051a0f0a46e530b5823bd1e88952141
SHA1: 18e5abcb520df3661a00cdc96a85cc9625cc9e73
SHA256: 2A73AAC441375C4DF315B2B4EFCF3605B6121751FF49D7C393C88701DE9FE041
File Size: 380.93 KB, 380928 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have resources
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name Actions Semiconductor Co., LTD
File Description
  • MediaManagerCore2 DLL
  • ProBatch DLL
  • SqliteFunc DLL
File Version
  • 5, 43, 12032, 21701
  • 5, 37, 1, 923
  • 1, 0, 0, 1
Internal Name
  • MediaManagerCore2
  • ProBatch
  • SqliteFunc
Legal Copyright
  • CopyRight (c) 2012, Actions reserved
  • 版权所有 (C) 2005
  • 版权所有 (C) 2007
  • 版权所有 (C) 2012
Original Filename
  • MediaManagerCore2.DLL
  • ProBatch.DLL
  • SqliteFunc.DLL
Private Build 5.43.03
Product Name
  • MediaManagerCore2 Dynamic Link Library
  • ProBatch Dynamic Link Library
  • SqliteFunc Dynamic Link Library
Product Version
  • 5, 43, 12032, 21701
  • 5, 38, 1, 924
  • 5, 37, 1, 923
  • 2, 0, 0, 12
  • 1, 0, 0, 1
Special Build 5.43.03

File Traits

  • dll
  • HighEntropy
  • x86

Block Information

Total Blocks: 486
Potentially Malicious Blocks: 8
Whitelisted Blocks: 200
Unknown Blocks: 278

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? 0 0 0 0 ? 0 0 0 0 ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 ? ? 0 0 0 0 0 0 0 0 x 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 ? ? 0 ? ? 0 0 ? 0 0 0 0 ? 0 0 ? ? 0 0 0 ? ? ? 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 1 0 0 0 ? 0 ? 0 0 ? ? ? ? ? 0 0 ? ? ? ? ? 0 0 0 ? ? 0 ? ? ? ? ? 0 ? 0 ? ? ? 0 0 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? 0 ? ? 0 ? ? ? 0 0 ? ? ? ? 0 0 0 0 ? 0 0 ? ? ? 0 0 ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? 0 ? ? ? ? 0 ? 0 ? 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? ? ? 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x x 0 ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 ? ? ? ? ? ? ? 0 ? ? ? ? ? 0 ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 1 0 0 0 1
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtProtectVirtualMemory
Show More
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
  • ntdll.dll!NtWriteVirtualMemory
  • win32u.dll!NtUserGetKeyboardLayout
  • win32u.dll!NtUserGetThreadState
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation
Process Manipulation Evasion
  • NtUnmapViewOfSection

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\13815a78218c2403e3063eabca94ef56046b9cf5_0002002944.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3ca4bf1e4831d9656ca6c051c8be8864699d4625_0002764860.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8c04d05e303184b10f4c26ea61b9a20046abc885_0000045056.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5ca099b1aeac2082346ad7ebcc3bd8f72ccf84a5_0002039808.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\99f34709fac2f949f97626656c80a00690c9de69_0001191936.,LiQMAxHB
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\56d0414ccd37d3f133f2720a99c759047aee8035_0002060288.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\59a5247fec86b1fea799228a29bae60aec4f4e7d_0000438272.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\18de5c0c3d52cd643f13b2927e5615bed31b25e8_0002113536.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ee97f34e4f61747e8941d6fe056adf1821160bc1_0000450560.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\156e8283abe1519e5ec2fc687b5500a702a9cd6c_0000331776.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\81fe7107d480ed4ba3ad4429b9a68499457569be_0000172032.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\18e5abcb520df3661a00cdc96a85cc9625cc9e73_0000380928.,LiQMAxHB

Trending

Most Viewed

Loading...