Backdoor

Should I remove “Backdoor:Win32/Farfli.BW”?

Malware Removal

The Backdoor:Win32/Farfli.BW is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Backdoor:Win32/Farfli.BW virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
www.hack009.com
www.09sou.com
a.tomx.xyz

How to determine Backdoor:Win32/Farfli.BW?


File Info:

crc32: 5169EE88
md5: 18786c3e9c610d61c138e01625a16c35
name: 18786C3E9C610D61C138E01625A16C35.mlw
sha1: fa252a4bd2bf13aec8c9cc0f9ef3a635ed86c607
sha256: cf503c87b808b6eb151fbeba161a1edf55dc9d7585def926653ad4023b1cbfae
sha512: 6bc8df00f13e81b20d4a192976922ad02de29a5b79000d647d4774de0bc57e9aa69c32bd1831b548d2030ed539fa4e7f78bb7a06e700e37cb9da194cd459a2fe
ssdeep: 49152:kmVvN8VEjtLTjPUrvBo+6otzvyyW3Wu8qV8z:/KIt3wTO+6ybyvWu8qV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Backdoor:Win32/Farfli.BW also known as:

K7AntiVirusTrojan ( 0052c8a31 )
LionicTrojan.Win32.Hupigon.m!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Trojan.Heur.JP.4DW@aibWfmnb
CylanceUnsafe
ZillyaBackdoor.Hupigon.Win32.196348
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaBackdoor:Win32/Farfli.7b9a98d0
K7GWTrojan ( 0052c8a31 )
Cybereasonmalicious.e9c610
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Farfli.ARN
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Zegost-7495611-0
KasperskyBackdoor.Win32.Hupigon.axbr
BitDefenderGen:Trojan.Heur.JP.4DW@aibWfmnb
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
MicroWorld-eScanGen:Trojan.Heur.JP.4DW@aibWfmnb
TencentWin32.Backdoor.Hupigon.Dyqq
Ad-AwareGen:Trojan.Heur.JP.4DW@aibWfmnb
SophosMal/Generic-S
ComodoMalware@#1vdutmc4itw6a
BitDefenderThetaAI:Packer.9057289A1F
VIPRETrojan-Dropper.Win32.Resdro.b (v) (not malicious)
McAfee-GW-EditionBehavesLike.Win32.Ipamor.tc
FireEyeGeneric.mg.18786c3e9c610d61
EmsisoftGen:Trojan.Heur.JP.4DW@aibWfmnb (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Hupigon.vp
AviraHEUR/AGEN.1127530
eGambitUnsafe.AI_Score_99%
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftBackdoor:Win32/Farfli.BW
GDataGen:Trojan.Heur.JP.4DW@aibWfmnb
McAfeeBackDoor-EXZ
MAXmalware (ai score=81)
VBA32MalwareScope.Trojan-PSW.Game.16
MalwarebytesMalware.AI.2045708443
PandaTrj/CI.A
RisingTrojan.Generic@ML.99 (RDML:O7mmFmdOC8rfJgVXZ0gLaA)
YandexBackdoor.Hupigon!W5vB0bbN/gY
IkarusVirus.Win32.Heur
FortinetW32/Filecoder.FV!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Backdoor:Win32/Farfli.BW?

Backdoor:Win32/Farfli.BW removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment