Backdoor

How to remove “Backdoor:Win32/Farfli.BF!MTB”?

Malware Removal

The Backdoor:Win32/Farfli.BF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.BF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Loads a driver
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • CAPE detected the PCRat malware family
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

How to determine Backdoor:Win32/Farfli.BF!MTB?


File Info:

name: 52FDA059A6236E6536F6.mlw
path: /opt/CAPEv2/storage/binaries/185e4407076eab1b82daf99199df75ea12b6d2e44f4ee56d0104b21636ab87ec
crc32: B4F32247
md5: 52fda059a6236e6536f604a985defce3
sha1: 8f8b5e2bc850a0dbd32ee9a6621f30bf9c86d0fc
sha256: 185e4407076eab1b82daf99199df75ea12b6d2e44f4ee56d0104b21636ab87ec
sha512: a0b865f4c186e64e8dd43dea42e62334bd0c57ea227b6971d2d9b58cef3b8ff8d917b4435eacbead2672384fe8649effc622767a4cd36437a8720721183ec8c6
ssdeep: 24576:OBgsNuQ+MFsWjkf/nhXdESvW/eP1PGNS:MNheWjshtBD9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1BB557B591BAB4256DB5537B9C8A296940A090F532F68C0B46E311D1EBD2334FFC23EBD
sha3_384: 8ae33c490bf70337b4149e580f7d13147cd642491876a1e290071cbb7a0365d3a9ce242aa8cd0be10257cc193e685d35
ep_bytes: 558bec6aff6868535400686073540064
timestamp: 2022-03-30 01:45:31

Version Info:

0: [No Data]

Backdoor:Win32/Farfli.BF!MTB also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.DownLoader34.30708
MicroWorld-eScanDeepScan:Generic.KillMBR.A.DFCDCCEE
FireEyeGeneric.mg.52fda059a6236e65
ALYacDeepScan:Generic.KillMBR.A.DFCDCCEE
CylanceUnsafe
ZillyaTrojan.Farfli.Win32.41361
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan ( 005800661 )
K7GWTrojan ( 005800661 )
Cybereasonmalicious.9a6236
BitDefenderThetaAI:Packer.3D6DD7E51F
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Farfli.CTT
APEXMalicious
KasperskyTrojan.Win32.Vehidis.yqi
BitDefenderDeepScan:Generic.KillMBR.A.DFCDCCEE
AvastWin32:Trojan-gen
TencentTrojan.Win32.Farfli.wb
Ad-AwareDeepScan:Generic.KillMBR.A.DFCDCCEE
EmsisoftDeepScan:Generic.KillMBR.A.DFCDCCEE (B)
VIPREDeepScan:Generic.KillMBR.A.DFCDCCEE
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
Trapminemalicious.moderate.ml.score
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataDeepScan:Generic.KillMBR.A.DFCDCCEE
JiangminHeur:TrojanDropper.TDSS
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D8
ArcabitDeepScan:Generic.KillMBR.A.DFCDCCEE
MicrosoftBackdoor:Win32/Farfli.BF!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R333274
McAfeeGenericRXKB-WQ!52FDA059A623
MAXmalware (ai score=87)
VBA32BScope.Trojan.Wacatac
MalwarebytesBackdoor.Farfli
RisingTrojan.Generic@AI.100 (RDML:hEtQnDbgcsM5lh0aLclc9Q)
IkarusTrojan.Win32.Farfli
MaxSecureTrojan.Malware.163813058.susgen
FortinetW32/GenKryptik.DJUZ!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Backdoor:Win32/Farfli.BF!MTB?

Backdoor:Win32/Farfli.BF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment