Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
From: claymore (claymoreADELPHIA.NET)
Date: Wed Mar 28 2001 - 13:46:32 CST
Yes, this appears to be a version of Hybris. Of course, without actually
seeing it I cannot be certain, but it fits the pattern.
Random 8 Character attachment name with no subject or message body.
Check your favorite AV vendor for "Hybris"
From: Incidents Mailing List [mailto:INCIDENTSSECURITYFOCUS.COM]On
Behalf Of Lee Hetherington
Sent: Wednesday, March 28, 2001 3:31 AM
Subject: ICQ Users a target Again!
I got an email today when I arrived at work which seemed to originate from
the MAILER-DAEMON account on one of our machines running Sendmail. The
message had no body but had one attatchment. The file LEOKIALE.EXE is 23Kb
in Size and Hasnt been opened...
It was to a personal address of my own which is only used in ICQ...
Received: (from rootlocalhost)
by XXX.asphost.net (8.11.0/8.8.7) id f2RGNGL32025
for leeasphost.net; Tue, 27 Mar 2001 17:23:16 +0100
Received: from isis.hol.gr (isis.hol.gr [188.8.131.52])
by XXX.asphost.net (8.11.0/8.8.7) with SMTP id f2RGLeZ32019
for <xxxxxxkerfuffle.net>; Tue, 27 Mar 2001 17:21:40 +0100
Date: Tue, 27 Mar 2001 17:21:40 +0100
Received: (qmail 6678 invoked from network); 27 Mar 2001 16:08:03 -0000
Received: from vdp201.ath02.cas.hol.gr (HELO r8f9e9) (184.108.40.206)
by isis.hol.gr with SMTP; 27 Mar 2001 16:08:03 -0000
Content-Type: multipart/mixed; boundary="--VE27O9EV0H27012FOLUR"
Anyone else seen this?
Production Network Engineer
Grey Matter Advanced Marketing Limited
T: +44 1242 237600 DL: +44 1242 246139 F: +44 1242 237633 W:
Suite 4, Fairview Court, Fairview Road. Cheltenham, Gloucestershire GL52 2EX