W32/Kelvir.A!worm.im
Analysis
This 32-bit threat is an Internet worm designed to manipulate MSN Messenger in order to distribute itself to contacts found in the Messenger contact list. This threat attempts to download a copy of itself from a Comcast.net user account as the file "patch.exe". The file is not available at the time of this writing.
Recommended Action
Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option
Telemetry
Detection Availability
FortiClient | |
---|---|
Extreme | |
FortiMail | |
Extreme | |
FortiSandbox | |
Extreme | |
FortiWeb | |
Extreme | |
Web Application Firewall | |
Extreme | |
FortiIsolator | |
Extreme | |
FortiDeceptor | |
Extreme | |
FortiEDR |