Trojan

Trojan:Win32/Farfli.AX!MTB (file analysis)

Malware Removal

The Trojan:Win32/Farfli.AX!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Farfli.AX!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Farfli.AX!MTB?


File Info:

name: 7A63FDEBD6450EE8423C.mlw
path: /opt/CAPEv2/storage/binaries/bacf013a1229502619f2b91a9e0b039a390a9da46c9933a196a29ce8a9c70cba
crc32: 9EC65D14
md5: 7a63fdebd6450ee8423c4f426f9517db
sha1: de4dedf23c249673c2d6605657298baeafa5eac8
sha256: bacf013a1229502619f2b91a9e0b039a390a9da46c9933a196a29ce8a9c70cba
sha512: 58d8b195652a693e03426cc431d5a0f6ac08fcb4298ce48ac010484adf032a71c1dd4993cd6f0c5354bc1f2ee080d36cf0f69107202ff57b14917a0931e88fe7
ssdeep: 49152:14xnUT9/zd+0nSwDL4BtTWmmf9KVQvRedRZdhA4j9T4lMgaLzsvXgY+:gUT9/zfnSwDLDmVQvRedRZdh7jRDLzsN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T157959F3D3A5280B6D93335308A4DB3B9F6EEE9304E70929765951E392E701C39A1C76F
sha3_384: 513ee47e8759db0f25299cf01af191f9d4a955f4acf9a38ee6f4b92e175f6f207721a293702a5d8acae2ea7561006160
ep_bytes: e8f2e90000e989feffff8bff558bec53
timestamp: 2022-06-16 01:33:48

Version Info:

CompanyName:
FileDescription: MVCSphere Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: MVCSphere
LegalCopyright: 版权所有 (C) 2005
LegalTrademarks:
OriginalFilename: MVCSphere.EXE
ProductName: MVCSphere 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Trojan:Win32/Farfli.AX!MTB also known as:

LionicTrojan.Win32.Antavmu.4!c
MicroWorld-eScanTrojan.GenericKD.49207618
FireEyeGeneric.mg.7a63fdebd6450ee8
ALYacTrojan.GenericKD.49207618
CylanceUnsafe
VIPRETrojan.GenericKD.49207618
SangforTrojan.Win32.Antavmu.Vbpx
K7AntiVirusRiskware ( 00584baa1 )
AlibabaTrojan:Win32/Antavmu.217f5ad9
K7GWRiskware ( 00584baa1 )
CyrenW32/ABRisk.YGSN-2306
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Generik.DJLQGXU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Antavmu.gen
BitDefenderTrojan.GenericKD.49207618
AvastWin32:Malware-gen
TencentWin32.Trojan.Antavmu.Airz
Ad-AwareTrojan.GenericKD.49207618
EmsisoftTrojan.GenericKD.49207618 (B)
TrendMicroTROJ_GEN.R002C0WFM22
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
IkarusTrojan.Win32.Krypt
GDataTrojan.GenericKD.49207618
AviraHEUR/AGEN.1243018
ArcabitTrojan.Generic.D2EED942
MicrosoftTrojan:Win32/Farfli.AX!MTB
CynetMalicious (score: 99)
McAfeeArtemis!7A63FDEBD645
MAXmalware (ai score=82)
VBA32BScope.Trojan.Sabsik.FL
TrendMicro-HouseCallTROJ_GEN.R002C0WFM22
RisingTrojan.Antavmu!8.2A5 (CLOUD)
MaxSecureTrojan.Malware.12187866.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaF.34742.1v0@amWcIXhj
AVGWin32:Malware-gen
PandaTrj/Chgt.AB
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Farfli.AX!MTB?

Trojan:Win32/Farfli.AX!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment