live casino online

BKDR_APOLMY.C

December 03, 2014
 Analysis by: Anthony Joe Melgarejo

 ALIASES:

Trojan:Win64/Apolmy.A (Microsoft)

 PLATFORM:

Windows 7 and later

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Backdoor

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This backdoor uses Windows Task Scheduler to create a scheduled task that executes the dropped copy.

It executes commands from a remote malicious user, effectively compromising the affected system.

It takes advantage of certain vulnerabilities.

  TECHNICAL DETAILS

File Size:

Varies

File Type:

EXE

Memory Resident:

No

Initial Samples Received Date:

26 Nov 2014

Arrival Details

This malware arrives via the following means:

  • - to execute C:\Public\test.exe with escalated privileges

NOTES:

The commands this backdoor receive has the following format:

  • {3-digit command ID}{data/command (optional)} e.g. 007 net user hacker y0ur0wn3d /add

The path this malware used are hardcoded. Therefore it only works in Windows 7 and later versions by default since C:\Users\Public and C:\Users\{username}\AppData\Local\Temp only existsi n the aforementioned versions.

The file C:\Users\Public\doc.exe is terminated and deleted after the execution of C:\Users\Public\test.exe.

  SOLUTION

Minimum Scan Engine:

9.700

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must to allow full scanning of their computers.

Step 2

Remove malware/grayware files dropped/downloaded by BKDR_APOLMY.C. (Note: Please skip this step if the threats listed below have already been removed.)