Backdoor

Backdoor:Win32/Farfli.ABM!MTB (file analysis)

Malware Removal

The Backdoor:Win32/Farfli.ABM!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.ABM!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to execute a powershell command with suspicious parameter/s
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Unusual version info supplied for binary

Related domains:

haohm.502ok.com

How to determine Backdoor:Win32/Farfli.ABM!MTB?


File Info:

crc32: A9AEC638
md5: c32c5cf83ba9a7db47665a58718fec6b
name: C32C5CF83BA9A7DB47665A58718FEC6B.mlw
sha1: 91ea9bff93cf65963e23b5923197a0a408449cd7
sha256: 0b31dca111a7eb743a40cea3c64dbf9bd4748c4af3d6f915ffce7184982c6538
sha512: 34cf90454fecdde6e87983f9cb5eada6ca83f79b9d20e7d1a07c91312245ad4bd0ff19304926368f6659dfe755b7bd9341f83b59dd644fe5bf95f91ffc5d5767
ssdeep: 1536:ATHH/ZkdQ7Y6nnMbvtNYO2m7hYu8DFLDe3ZWv7byp2B2kmZKjRqf:E/Zk6/nMtNYO2+iVFLapWzbypBIEf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: x7248x6743x6240x6709(C) 2013 C Microsoft Corporation. All rights reserved.
InternalName: OEMIG50
FileVersion: 6.0.3790.3959
CompanyName: x5927x4f17x6597x5730x4e3bx534fx4f1a
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: Microsoft(R) Windows(R) x5927x4f17x6597x5730x4e3bx534fx4f1a
SpecialBuild:
ProductVersion: 6, 0, 3, 1
FileDescription: Outlook Express Migration 5.0
OriginalFilename: OEMIG50.EXE
Translation: 0x0804 0x04b0

Backdoor:Win32/Farfli.ABM!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004fb2411 )
LionicTrojan.Win32.PsDownload.trJu
Elasticmalicious (high confidence)
DrWebTrojan.Damaged.1
CynetMalicious (score: 100)
ALYacGen:Variant.Graftor.464791
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.1848455
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 004fb2411 )
Cybereasonmalicious.83ba9a
CyrenW32/Zegost.EA.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.FHSE
APEXMalicious
AvastWin32:BackdoorX-gen [Trj]
ClamAVWin.Dropper.Gh0stRAT-9497859-0
KasperskyTrojan-Downloader.Win32.PsDownload.fwc
BitDefenderGen:Variant.Graftor.464791
NANO-AntivirusTrojan.Win32.Kryptik.eofuql
MicroWorld-eScanGen:Variant.Graftor.464791
TencentMalware.Win32.Gencirc.10b0cbf1
Ad-AwareGen:Variant.Graftor.464791
SophosMal/Generic-S
ComodoBackdoor.Win32.Zegost.FH@7qyj9h
BitDefenderThetaGen:NN.ZexaF.34170.hq0@aSWt81db
TrendMicroBKDR_ZEGOST.SM34
McAfee-GW-EditionPacked-MW!C32C5CF83BA9
FireEyeGeneric.mg.c32c5cf83ba9a7db
EmsisoftGen:Variant.Graftor.464791 (B)
SentinelOneStatic AI – Suspicious PE
JiangminBackdoor.Farfli.cno
AviraTR/Dropper.Gen7
eGambitUnsafe.AI_Score_99%
MicrosoftBackdoor:Win32/Farfli.ABM!MTB
GridinsoftTrojan.Win32.Kryptik.oa!s1
GDataGen:Variant.Graftor.464791
AhnLab-V3Backdoor/Win32.RL_Zegost.R300697
McAfeePacked-MW!C32C5CF83BA9
MAXmalware (ai score=86)
VBA32Backdoor.Farfli
MalwarebytesMalware.AI.3256505801
PandaTrj/Genetic.gen
TrendMicro-HouseCallBKDR_ZEGOST.SM34
RisingTrojan.Kryptik!1.AAD1 (CLASSIC)
YandexTrojan.GenAsa!Vw68EO0Xzeo
IkarusIM-Flooder.Win32.Hityou
FortinetW32/Kryptik.FHSE!tr
AVGWin32:BackdoorX-gen [Trj]
Paloaltogeneric.ml

How to remove Backdoor:Win32/Farfli.ABM!MTB?

Backdoor:Win32/Farfli.ABM!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment