Threat behavior
Backdoor:Win32/Farfli.I is a trojan that drops various files detected as malware into a system. It also has backdoor capabilities that allow it to contact a remote attacker and wait for instructions.
Installation
Upon execution, Backdoor:Win32/Farfli.I drops the following files in the system:
Some examples of <malware file 1>.sys are:
- winsawids.sys
- kisawids.sys
Some examples of <malware file 2>.dll are:
It may load its dropped DLL file by running the following command:
rundll32.exe %windir%\<malware file 2>.dll MyEntryPoint
Payload
Allows backdoor access and control
Backdoor:Win32/Farfli.I may try to connect to various Web sites via TCP port 80 to send the infected system's MAC address and to download arbitrary files. This notifies a remote attacker that the system is infected, possibly allowing the attacker to remotely control the infected system.
Some of the Web sites that it connects to are:
- w.qq-uc.cn
- baoge.9966.org
- mmd178.cn
- oiuyt.net
Analysis by Andrei Florin Saygo
Prevention