W32/Kelvir.A!worm.im

description-logoAnalysis

This 32-bit threat is an Internet worm designed to manipulate MSN Messenger in order to distribute itself to contacts found in the Messenger contact list. This threat attempts to download a copy of itself from a Comcast.net user account as the file "patch.exe". The file is not available at the time of this writing.

recommended-action-logoRecommended Action

Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option

Telemetry logoTelemetry

Detection Availability

FortiClient
Extreme
FortiMail
Extreme
FortiSandbox
Extreme
FortiWeb
Extreme
Web Application Firewall
Extreme
FortiIsolator
Extreme
FortiDeceptor
Extreme
FortiEDR

Version Updates

Date Version Detail
2019-08-27 71.17600 Sig Updated
2019-07-21 70.15100 Sig Added