Threat Database Trojans Trojan.Farfli.V

Trojan.Farfli.V

By CagedTech in Trojans

Threat Scorecard

Threat Level: 80 % (High)
Infected Computers: 1
First Seen: June 8, 2021
Last Seen: December 6, 2024
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Trojan.Farfli.V
Signature status: No Signature

Known Samples

MD5: ef2f9e1fc682df0ea89f3203b0f72dd3
SHA1: d71c878d7450e18aef2afcc6efe15132c56ba52e
SHA256: ACCF5FDEEEED4285A8DA9956CB2A783A7D08429BFBF54BF28E2CF2F98480FB20
File Size: 305.66 KB, 305664 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 63
Potentially Malicious Blocks: 5
Whitelisted Blocks: 58
Unknown Blocks: 0

Visual Map

x 0 x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Farfli.FK
  • Farfli.V

Files Modified

File Attributes
c:\users\user\appdata\local\temp\5258.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\m3389.exe Generic Write,Read Attributes
c:\windows\syswow64\whpmel.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Em8� �v����$kF(�1�1HO@V�k�qw�nz��{b��P��/�����X��V�����v�j���r�m���z����$٢��a��8წ���=�S�]Q=)UcB1_OkhT�Vw�p,H��S�����%�������AE��D��&��$�����L��; RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Fm 8� �v����$kF(�1�1HO@V�k�qw�nz��{b��P��/�����X��V�������v�j���r�m���z����$٢��a��8წ���=�S�]Q=)UcB1_OkhT�Vw�p,H��S�����%�������AE��D��&��$�����L��; RegNtPreCreateKey
Show More
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc3475 隗ȁਪˣ鈯ˣ遙̃豤̃অˣ炑̃濖̃賬̃獖}਷ˣ邯̃뫯ʃ RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Gm%8� �v����$kF(�1�1HO@V�k�qw�nz��{b��P��/���7�M����X��V�������v�j���r�m��IV��z����$٢��a��8წ���(!��j��=�S�]Q=)UcB1_OkhT�Vw�`�Vp,H��S�����%�������AE��D��&�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Hm&8� �v����$kF(�1�1HO@V�k�qw�nz��{b��P��/���7�M�������X��V�������v�j���r�m��IV��z����$٢��a��8წ���(!��j��=�S�]Q=)UcB1_OkhT�Vw�`�Vp,H��S�����%�������AE��D�� RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 Im&8� �v����$kF(�1�1HO@V�k�qw�nz��{b��P��/���7�M�������X��V�������v�j���r�m��IV��z����$٢��a��8წ���(!��j��=�S�]Q=)UcB1_OkhT�Vw�`�Vp,H�R���S�����%�������AE�� RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • ShellExecute
Service Control
  • OpenSCManager
  • StartService

Shell Command Execution

open C:\Users\Npqytyyq\AppData\Local\Temp\m3389.exe
open C:\Users\Npqytyyq\AppData\Local\Temp\5258.exe
C:\WINDOWS\system32\cmd.exe /c del C:\Users\Npqytyyq\AppData\Local\Temp\5258.exe > nul