Threat Database Trojans Trojan.Farfli.LE

Trojan.Farfli.LE

By CagedTech in Trojans

Threat Scorecard

Popularity Rank: 10,958
Threat Level: 80 % (High)
Infected Computers: 59
First Seen: June 12, 2025
Last Seen: July 9, 2026
OS(es) Affected: Windows

The detection of Trojan.Farfli.LE on your system indicates a potential security threat that requires immediate attention. This Trojan-type threat can compromise your computer's integrity and put your personal data at risk. It is essential to understand the nature of this threat and take prompt action to remove it.

What Is Trojan.Farfli.LE?

Trojan.Farfli.LE is a type of malware that can infiltrate your system without your knowledge or consent. The term "Trojan" refers to a broad category of malicious software that can disguise itself as legitimate programs or files. Trojan.Farfli.LE, in particular, may be designed to evade detection and exploit vulnerabilities in your system to gain unauthorized access.

How Trojan.Farfli.LE Operates

Once installed, Trojan.Farfli.LE can operate in various ways, depending on its intended purpose. It may attempt to connect to remote servers to receive instructions or transmit stolen data. This malware can also create backdoors, allowing hackers to access your system and perform malicious activities. Additionally, it may try to disable security software or interfere with system updates to maintain its presence on your computer.

Symptoms of Infection

Identifying the symptoms of a Trojan.Farfli.LE infection can be challenging, as it often runs silently in the background. However, you may notice some unusual behavior, such as slow system performance, frequent crashes, or unfamiliar programs running on your computer. You may also experience issues with your internet connection, such as unexplained traffic or suspicious network activity. If you suspect that your system has been compromised, it is crucial to take immediate action to mitigate the threat.

How to Remove Trojan.Farfli.LE

To remove Trojan.Farfli.LE from your system, follow these steps:

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow you to download necessary removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove all instances of the malware.
  3. Uninstall any suspicious programs or applications that you do not recognize or that were installed without your consent.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your computer and perform another full scan to ensure that the malware has been completely removed.

It is essential to note that removing Trojan.Farfli.LE requires patience and caution. Be sure to follow the removal steps carefully and take the necessary precautions to prevent re-infection.

Conclusion

The detection of Trojan.Farfli.LE on your system is a serious issue that requires prompt attention. By understanding the nature of this threat and taking the necessary steps to remove it, you can protect your personal data and prevent further damage to your system. Remember to stay vigilant and take proactive measures to secure your computer, such as keeping your operating system and software up to date, using strong passwords, and being cautious when opening email attachments or downloading files from the internet.

Analysis Report

General information

Family Name: Trojan.Farfli.LE
Signature status: No Signature

Known Samples

MD5: 9134ef6a44e4a9cb311e1139e4590812
SHA1: 7ae8250a4afd225dbc8420183116e8af1cf15cfe
SHA256: 30000DE63DD389B0AEF61D01CDAE2ED38F4BC0E03CA04E585780CA7B55B47662
File Size: 2.96 MB, 2961408 bytes
MD5: 76bfc896991a80a2cd16e42c57f587e1
SHA1: baa5aa78d8a2c2349b508156f0c1d59f214a1802
SHA256: 5EDCCAA9AEA1641E764D14EB49A2667BE01C58BEA2C44441DB4C063C8BD623C9
File Size: 2.18 MB, 2184704 bytes
MD5: 020ef363798524bdbfdca6f7e31fcb7a
SHA1: f959bea7e2a98a303b2a807c6588871f3efb0780
SHA256: C74EADEB65B95E4A5DEC8C4405ED37B79C1F7A2A73BC57D4CC53EA4ACA0B5522
File Size: 111.62 KB, 111616 bytes
MD5: 0d876831e50bdbe4ce2c4999dbfebaff
SHA1: 207dfbc239789c98e50ac2d4d7cd94c2ab8569a4
SHA256: DC4936CA53CD4A2EF1FC3C4BAFC53391AFD434C6D9B2EB9AB6C527A32EE7B5F4
File Size: 2.96 MB, 2955776 bytes
MD5: eac25262c095597a74380ef80315af2a
SHA1: 9ecde51a5923e9a8a30ae3b62e5c272f7c44b758
SHA256: 3B04D27199912B5206CC2A87B3AAAF11915FF0321D5AA5097134C60D5AF2772D
File Size: 3.66 MB, 3662848 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have security information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name JessMA Open Source
File Description HPSocket for C DLL
File Version
  • 6.0.3
  • 5.9.3
  • 5.9.1
  • 5.6.4
Internal Name HPSocket4C.dll
Legal Copyright https://github.com/ldcsaa/HP-Socket
Original Filename HPSocket4C.dll
Product Name HP-Socket
Product Version
  • 6.0.3
  • 5.9.3
  • 5.9.1
  • 5.6.4

File Traits

  • dll
  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 5,174
Potentially Malicious Blocks: 699
Whitelisted Blocks: 3,065
Unknown Blocks: 1,410

Visual Map

0 x ? ? ? ? ? x 0 x x 0 0 x 0 x ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 ? ? x 0 ? x 0 0 ? 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 ? 0 0 0 x x x ? ? x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 ? ? 0 0 0 0 0 0 0 0 0 0 1 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 x ? x x x 0 0 0 0 0 x 0 0 0 0 0 0 x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x 0 0 x x x x x x x x x 0 0 0 0 x x x x x 0 0 0 0 x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x x x x 0 x x x x x x x 0 0 0 0 0 x x x x x 0 0 0 0 0 x x x 0 x x x 0 0 0 0 x x 0 x 0 0 x x x x 0 0 0 x 0 0 0 0 0 0 0 0 x 0 0 0 x x x x x x x x x 0 x x 0 x x 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? 0 0 ? ? 0 0 ? ? ? 0 x x x 0 0 x x 0 0 x x 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 1 0 0 0 0 x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 ? 0 ? 0 ? ? ? ? 0 0 0 0 0 x x x x x x x x x x x x 0 x x x x x x x x x ? 0 ? x x x 0 0 x 0 0 0 0 0 ? ? ? x 0 x ? 0 0 0 ? 0 0 0 ? 0 x ? 0 0 0 ? 0 0 0 ? 0 x ? 0 ? 0 0 x ? 0 0 ? 0 0 0 0 0 ? 0 0 0 x ? 0 0 ? 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 x x x x x x x 0 x x x x x 0 x x 0 0 0 ? 0 x x x ? 0 0 0 0 0 x ? 0 ? ? 0 0 x ? ? ? 0 ? ? ? 0 0 ? ? ? ? 0 0 x x 0 0 x 0 0 ? 0 x x ? 0 0 ? ? 0 x x 0 ? 0 ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? ? ? ? ? ? ? ? ? ? 0 0 ? 0 0 ? 0 0 0 ? ? ? ? ? ? ? ? 0 ? 0 0 0 x 0 0 ? 0 ? ? 0 0 0 0 0 x ? 0 0 ? ? ? ? x ? ? ? ? ? ? ? 0 0 0 0 ? 0 0 ? ? 0 ? ? 0 ? 0 ? ? 0 0 ? 0 0 1 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? 0 0 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 ? ? 0 0 ? ? ? 0 x x x 0 0 0 0 0 x x x x x x x 0 x x x 0 x 0 x x x x x x x x x x x 0 0 x ? 0 0 0 0 0 0 ? 0 x ? 0 0 0 0 0 0 ? 0 x ? 0 ? x 0 x x 0 0 ? 0 0 0 0 0 ? 0 0 0 x x 0 0 ? 0 0 0 0 0 ? 0 0 0 ? ? 0 0 0 0 0 0 0 0 ? 0 0 x x x ? 0 0 0 0 x x x 0 ? 0 x ? ? ? ? ? ? ? 0 0 ? ? ? ? 0 0 x x 0 0 x 0 0 ? 0 ? 0 0 ? 0 ? ? ? 0 x x 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? 0 ? ? x x 0 ? ? ? ? x ? ? ? ? ? ? ? ? 0 ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? 0 0 0 0 0 ? ? ? ? ? x ? 0 0 ? ? 0 ? ? ? x ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? 0 x 0 ? 0 x x x x ? 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? x ? 0 x 0 ? 0 x ? x x x x x x 0 x ? ? ? ? ? 0 0 x x 0 0 0 0 0 0 ? x ? x ? ? ? x ? ? ? x ? ? ? ? 0 0 x x 0 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? x x ? ? 0 ? ? ? 0 0 ? ? x ? ? x 0 ? ? ? ? 0 0 ? 0 ? ? 0 ? ? 0 ? ? 0 ? ? 0 ? x x 0 0 x 0 ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 ? 0 ? 0 0 x 0 0 0 0 ? ? ? ? 0 ? ? ? x ? 0 ? 0 ? ? 0 ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? x x x x ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? x x x x ? ? ? ? ? ? ? 0 ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? x ? 0 0 ? ? ? ? ? x ? 0 0 ? ? 0 0 0 0 0 0 0 ? x x 0 ? 0 0 ? ? ? ? 0 x 0 0 0 0 0 0 x x 0 0 0 ? 0 0 ? 0 0 ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 x ? 0 x ? ? ? ? ? ? ? 0 ? 0 ? 0 ? ? 0 ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 x ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? ? ? ? ? ? x ? 0 0 ? x ? ? 0 0 ? ? 0 0 0 x ? 0 ? 0 0 0 ? 0 ? x 0 ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? 0 ? 0 ? ? ? ? 0 0 ? ? ? 0 ? 0 ? x ? ? 0 ? ? 0 0 0 0 ? 0 0 ? 0 0 0 0 0 0 0 ? ? ? 0 0 0 0 ? ? 0 0 ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 ? ? ? 0 ? ? ? 0 ? 0 ? ? x 0 0 x x 0 ? ? 0 ? 0 ? 0 ? 0 0 0 ? 0 0 ? ? ? ? ? 0 x 0 0 0 0 0 ? ? ? 0 ? ? x 0 x x ? 0 ? 0 ? ? ? ? 0 ? ? ? 0 0 ? ? x ? ? 0 ? ? ? 0 0 0 0 0 0 0 ? 0 0 0 0 0 0 0 ? ? ? ? 0 0 0 0 0 ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? 0 ? ? ? 0 ? ? ? 0 0 ? 0 0 0 0 ? 0 0 0 ? x x 0 ? x 0 ? 0 ? x 0 0 0 ? ? 0 ? 0 ? ? 0 ? 0 0 ? ? ? ? 0 0 0 x 0 0 0 0 0 x 0 0 0 ? ? x x 0 0
... Data truncated
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\7ae8250a4afd225dbc8420183116e8af1cf15cfe_0002961408.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\baa5aa78d8a2c2349b508156f0c1d59f214a1802_0002184704.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\f959bea7e2a98a303b2a807c6588871f3efb0780_0000111616.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\207dfbc239789c98e50ac2d4d7cd94c2ab8569a4_0002955776.,LiQMAxHB
C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\9ecde51a5923e9a8a30ae3b62e5c272f7c44b758_0003662848.,LiQMAxHB

Trending

Most Viewed

Loading...