Security experts intercept Zhelatin mutant

By
Follow google news

Zhetlatin.o malware rated as 'moderate' risk.

Security experts intercept Zhelatin mutant
Security experts at Kaspersky Lab have identified a new mutant of the Zhelatin email worm.

Zhelatin.o was identified by the company on 4 February and is rated as a 'moderate' risk.

The worm spreads via email as an infected attachment. The subject line, message body and attachment are variable.

Zhelatin.o is a portable executable file packed with UPX. The worm copies itself to the hard disk and modifies the registry to ensure that it loads automatically on start up.

It then harvests email addresses from the hard disk and automatically sends itself via email by directly connecting to the recipient's SMTP server.

The malware also terminates a range of antivirus and firewall applications, and hides its own processes, files and registry changes using a kernel-mode rootkit.

David Emm, senior technology consultant at Kaspersky Lab, said: "This is the latest in a series of Zhelatin variants.

"Like many email worms, it uses social engineering in an attempt to lure users into double clicking on the infected attachment."

Removal guidelines can be found at Viruslist.com.
Got a news tip for our journalists? Share it with us anonymously here.
Copyright ©v3.co.uk
Tags:

Most Read Articles

Optus takes $826,000 hit for anti-scam breaches

Optus takes $826,000 hit for anti-scam breaches

Australia, US and UK sanction Russian cyber firms over ransomware links

Australia, US and UK sanction Russian cyber firms over ransomware links

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

JPMorgan, Citi, Morgan Stanley client data may be exposed by vendor's hack

Australia's AUKUS base to connect to subsea cables

Australia's AUKUS base to connect to subsea cables

Log In

  |  Forgot your password?