Analysis by: Anthony Joe Melgarejo

ALIASES:

Trojan:Win64/Apolmy.A (Microsoft)

 PLATFORM:

Windows

 OVERALL RISK RATING:
 DAMAGE POTENTIAL:
 DISTRIBUTION POTENTIAL:
 REPORTED INFECTION:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: No

  • In the wild: Yes

  OVERVIEW

This Trojan may be dropped by other malware.

It takes advantage of certain vulnerabilities. It deletes itself after execution.

  TECHNICAL DETAILS

File Size: 13824 bytes
File Type: EXE
Memory Resident: No
Initial Samples Received Date: 26 Nov 2014

Arrival Details

This Trojan may be dropped by the following malware:

  • - to execute the file C:\Public\test.exe, detected as BKDR_APOLMY.C, with escalated priviliges

It deletes itself after execution.

  SOLUTION

Minimum Scan Engine: 9.700

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Remove the malware/grayware file dropped/downloaded by TROJ64_APOLMY.C. (Note: Please skip this step if the threat(s) listed below have already been removed.)