Trojan.Farfli.FP
Threat Scorecard
EnigmaSoft Threat Scorecard
EnigmaSoft Threat Scorecards are assessment reports for different malware threats which have been collected and analyzed by our research team. EnigmaSoft Threat Scorecards evaluate and rank threats using several metrics including real-world and potential risk factors, trends, frequency, prevalence, and persistence. EnigmaSoft Threat Scorecards are updated regularly based on our research data and metrics and are useful for a wide range of computer users, from end users seeking solutions to remove malware from their systems to security experts analyzing threats.
EnigmaSoft Threat Scorecards display a variety of useful information, including:
Popularity Rank: The ranking of a particular threat in EnigmaSoft’s Threat Database.
Severity Level: The determined severity level of an object, represented numerically, based on our risk modeling process and research, as explained in our Threat Assessment Criteria.
Infected Computers: The number of confirmed and suspected cases of a particular threat detected on infected computers as reported by SpyHunter.
See also Threat Assessment Criteria.
| Popularity Rank: | 3,022 |
| Threat Level: | 80 % (High) |
| Infected Computers: | 349 |
| First Seen: | January 1, 2025 |
| Last Seen: | July 20, 2026 |
| OS(es) Affected: | Windows |
The detection of Trojan.Farfli.FP on your system indicates a potential security threat that requires immediate attention. This report provides an overview of the threat, its operating methods, symptoms of infection, and steps to remove it from your system. It is essential to address this issue promptly to prevent potential damage to your computer and protect your personal data.
Table of Contents
What Is Trojan.Farfli.FP?
Trojan.Farfli.FP is identified as a Trojan-type threat, which is a broad category of malware designed to deceive users by appearing as legitimate software. The name itself does not directly indicate a specific malware family, but its classification as a Trojan suggests it is designed to gain unauthorized access to a computer system. Trojans can be used for various malicious purposes, including data theft, spyware, ransomware, or as a backdoor for other malware.
How Trojan.Farfli.FP Operates
Like other Trojans, Trojan.Farfli.FP likely operates by disguising itself as a harmless or useful application. Once installed on a system, it can execute a range of malicious activities. Trojans often rely on social engineering tactics to trick users into installing them. This can be through email attachments, downloads from untrusted websites, or infected software downloads. After installation, the Trojan can communicate with its command and control servers to receive instructions, which might include stealing sensitive information, downloading additional malware, or using the infected computer for malicious activities such as DDoS attacks.
Symptoms of Infection
Symptoms of a Trojan infection can vary widely depending on the specific goals of the malware. Common signs include unusual system behavior, such as slow performance, unexpected pop-ups, or changes to browser settings. Some Trojans are designed to operate stealthily, making them difficult to detect without specific security software. If your system has been flagged for Trojan.Farfli.FP, it's crucial to take the warning seriously, even if you don't notice any immediate symptoms, as the malware could be running in the background.
How to Remove Trojan.Farfli.FP
- Enter Safe Mode with Networking to prevent the malware from interfering with the removal process. This mode allows you to use the internet to download removal tools while limiting the malware's ability to run.
- Perform a full scan of your system using a reputable anti-malware tool such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the Trojan.
- Uninstall suspicious programs that you do not recognize or that were installed around the time the Trojan was detected. Be cautious and only remove programs you are sure are not essential to your system's operation.
- Reset your browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings changes made by the Trojan.
- Reboot your system and then perform another full scan to ensure the Trojan and any associated malware have been completely removed.
Conclusion
Removing Trojan.Farfli.FP from your system requires careful steps to ensure complete eradication. It's also a good opportunity to review your security practices, such as ensuring your operating system and software are up to date, using strong, unique passwords, and being cautious with emails and downloads from unknown sources. Regularly scanning your system with anti-malware tools and maintaining a robust security suite can help protect against future threats. Remember, prevention is key, but swift action upon detection can significantly mitigate the risks associated with malware infections.
Analysis Report
General information
| Family Name: | Trojan.Farfli.FP |
|---|---|
| Signature status: | No Signature |
Known Samples
Known Samples
This section lists other file samples believed to be associated with this family.|
MD5:
c997486974eeb266a3ab66f1d1d53f29
SHA1:
13815a78218c2403e3063eabca94ef56046b9cf5
SHA256:
FA419E4C3E1E13FACCA4F5ABE1499400C962A9CB667A218D8DAA4FA0614CEE61
File Size:
2.00 MB, 2002944 bytes
|
|
MD5:
2672ae0a91f2a2365269094d835d0ea8
SHA1:
3ca4bf1e4831d9656ca6c051c8be8864699d4625
SHA256:
627EB85BEA403E967AD280CFC68916B80B450C2B004B7C9E0EA13232B5360498
File Size:
2.76 MB, 2764860 bytes
|
|
MD5:
ca651ab5316fdb9d158fcff96b8388d9
SHA1:
8c04d05e303184b10f4c26ea61b9a20046abc885
SHA256:
77F8EF2E80553962AC8066B35C8CE895791BE8BABFD5119A3A7EFDE002BF0357
File Size:
45.06 KB, 45056 bytes
|
|
MD5:
3f860d177522945848b03e06c9a4a701
SHA1:
5ca099b1aeac2082346ad7ebcc3bd8f72ccf84a5
SHA256:
5567C3BED9EDF2927EAFFF84F4A88FC9C663E6C18C5121F9B8B988CB344DDB08
File Size:
2.04 MB, 2039808 bytes
|
|
MD5:
30058b79cd933ae85f81c051573d8206
SHA1:
99f34709fac2f949f97626656c80a00690c9de69
SHA256:
E944817D438EC152C82AB9D17B43BB2EC8B02EE1DBBE713D79ACC9A9E729EC4B
File Size:
1.19 MB, 1191936 bytes
|
Show More
|
MD5:
829474dbd67a7160ae392b171f9252a3
SHA1:
56d0414ccd37d3f133f2720a99c759047aee8035
SHA256:
7ECD511EB33B1B7FA8512B0C676F454562F17B2FFB2072E78D9C6607AAE81811
File Size:
2.06 MB, 2060288 bytes
|
|
MD5:
cbba5df81a8c8b50b000a1aec58222b6
SHA1:
59a5247fec86b1fea799228a29bae60aec4f4e7d
SHA256:
2A81749E3FA96BBB6434A1EDB6509DFFC9C95A7DC7B80CB6B511686A9F5D82C3
File Size:
438.27 KB, 438272 bytes
|
|
MD5:
8d84d9a404e3f4e6438a6fa56f07f6b4
SHA1:
18de5c0c3d52cd643f13b2927e5615bed31b25e8
SHA256:
302243BF9BF8BC9DAC3556B2932979BA2431D12741A34FBF68CA96CAD9966E58
File Size:
2.11 MB, 2113536 bytes
|
|
MD5:
5df8f122bafa344ab681d40a7c901206
SHA1:
ee97f34e4f61747e8941d6fe056adf1821160bc1
SHA256:
96485133E150D9617A2632D8C6DFBE54E179011394124100936A1769E86EF4A9
File Size:
450.56 KB, 450560 bytes
|
|
MD5:
79388626525f487cec5c4a128f7fd183
SHA1:
156e8283abe1519e5ec2fc687b5500a702a9cd6c
SHA256:
26560A32C80CC0043BC306D56A0FE7299202F24646AA59A776289B923ABAF1D6
File Size:
331.78 KB, 331776 bytes
|
|
MD5:
9bf903c93108822f4192d677d3e92f1c
SHA1:
81fe7107d480ed4ba3ad4429b9a68499457569be
SHA256:
3669551B0A5B32C73956B447EE3B6A5102F13CBBBC3B8C7DAEAFCFC90C6CE817
File Size:
172.03 KB, 172032 bytes
|
|
MD5:
a051a0f0a46e530b5823bd1e88952141
SHA1:
18e5abcb520df3661a00cdc96a85cc9625cc9e73
SHA256:
2A73AAC441375C4DF315B2B4EFCF3605B6121751FF49D7C393C88701DE9FE041
File Size:
380.93 KB, 380928 bytes
|
Windows Portable Executable Attributes
- File doesn't have "Rich" header
- File doesn't have debug information
- File doesn't have resources
- File doesn't have security information
- File has exports table
- File is 32-bit executable
- File is either console or GUI application
- File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
- File is Native application (NOT .NET application)
- File is not packed
Show More
- IMAGE_FILE_DLL is not set inside PE header (Executable)
- IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)
Windows PE Version Information
Windows PE Version Information
This section displays values and attributes that have been set in the Windows file version information data structure for samples within this family. To mislead users, malware actors often add fake version information mimicking legitimate software.| Name | Value |
|---|---|
| Company Name | Actions Semiconductor Co., LTD |
| File Description |
|
| File Version |
|
| Internal Name |
|
| Legal Copyright |
|
| Original Filename |
|
| Private Build | 5.43.03 |
| Product Name |
|
| Product Version |
|
| Special Build | 5.43.03 |
File Traits
- dll
- HighEntropy
- x86
Block Information
Block Information
During analysis, EnigmaSoft breaks file samples into logical blocks for classification and comparison with other samples. Blocks can be used to generate malware detection rules and to group file samples into families based on shared source code, functionality and other distinguishing attributes and characteristics. This section lists a summary of this block data, as well as its classification by EnigmaSoft. A visual representation of the block data is also displayed, where available.| Total Blocks: | 486 |
|---|---|
| Potentially Malicious Blocks: | 8 |
| Whitelisted Blocks: | 200 |
| Unknown Blocks: | 278 |
Visual Map
? - Unknown Block
x - Potentially Malicious Block
Windows API Usage
Windows API Usage
This section lists Windows API calls that are used by the samples in this family. Windows API usage analysis is a valuable tool that can help identify malicious activity, such as keylogging, security privilege escalation, data encryption, data exfiltration, interference with antivirus software, and network request manipulation.| Category | API |
|---|---|
| Syscall Use |
Show More
|
| Process Shell Execute |
|
| Anti Debug |
|
| Process Manipulation Evasion |
|
Shell Command Execution
Shell Command Execution
This section lists Windows shell commands that are run by the samples in this family. Windows Shell commands are often leveraged by malware for nefarious purposes and can be used to elevate security privileges, download and launch other malware, exploit vulnerabilities, collect and exfiltrate data, and hide malicious activity.
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\13815a78218c2403e3063eabca94ef56046b9cf5_0002002944.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\3ca4bf1e4831d9656ca6c051c8be8864699d4625_0002764860.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\8c04d05e303184b10f4c26ea61b9a20046abc885_0000045056.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5ca099b1aeac2082346ad7ebcc3bd8f72ccf84a5_0002039808.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\99f34709fac2f949f97626656c80a00690c9de69_0001191936.,LiQMAxHB
|
Show More
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\56d0414ccd37d3f133f2720a99c759047aee8035_0002060288.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\59a5247fec86b1fea799228a29bae60aec4f4e7d_0000438272.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\18de5c0c3d52cd643f13b2927e5615bed31b25e8_0002113536.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\ee97f34e4f61747e8941d6fe056adf1821160bc1_0000450560.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\156e8283abe1519e5ec2fc687b5500a702a9cd6c_0000331776.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\81fe7107d480ed4ba3ad4429b9a68499457569be_0000172032.,LiQMAxHB
|
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\18e5abcb520df3661a00cdc96a85cc9625cc9e73_0000380928.,LiQMAxHB
|