Blog for hpHosts, and whatever else I feel like writing about ....

Thursday, 8 December 2011

Fake Firefox e-mail leading to SpyEye trojan

This little chap arrived in my spam box today, and almost got over-looked (I was checking the newest e-mails leading to the Blackhole exploit (one of which, couldn't decide if it was from LinkedIn or the FDIC)), and not surprisingly, is fake.

The Payload, all 593KB of it, infects the unwitting victim with the SpyEye trojan. VT detection is utterly rubbish of course - only 2 vendors detecting it.

Quite why Sophos is calling it Ropian, is puzzling.

The URL you're linked to, is on a FastHosts IP, and redirects to a different folder on the same server, to download the actual payload.

--> hxxp://

ASN: 15418 FASTHOSTS-INTERNET Fasthosts Internet Ltd. Gloucester, UK

E-mail body (for those of us that use plain text)

Facebook <>


Facebook recommends that you upgrade to the
faster and smarter Firefox 8.

Get It Now <>

Introducing the new and improved Firefox 8, optimized for Facebook

• Browse faster than the previous version of Firefox.

• Easily organize and arrange your tabs into groups.

• Get on-the-go access to your saved Firefox settings across multiple computers.

• Access the new Facebook features as profile viewers and much more!

Get your free upgrade now <> .

Already upgraded? Thank you.


All your favorite stuff, all in one place. Make Facebook your home <> .

Visit Firefox on Facebook   <>

Share:  <> <> <>

Mozilla, Firefox, and the Firefox logo are trademarks or registered trademarks of Mozilla..

Update Marketing Preferences <>    |   Privacy Policy <>    |    Web Beacons in Email <>

RefID: sr-12012817

E-mail headers:

Return-Path: <>
X-Spam-Flag: YES
X-Spam-Score: 1.443
X-Spam-Level: *
X-Spam-Status: Yes, score=1.443 tagged_above=-9999 required=1.3
tests=[BAYES_00=-1.9, HTML_MESSAGE=0.001, HTML_MIME_NO_HTML_TAG=0.377,
Received: from ( [])
by (Postfix) with ESMTP id 33D76398366
for <>; Thu, 8 Dec 2011 02:35:20 +0000 (GMT)
Received: from ( [])
(authenticated bits=0)
by (8.14.4/8.14.3) with ESMTP id pB82kgOX025376
for <>; Wed, 7 Dec 2011 21:46:50 -0500
Date: Wed, 7 Dec 2011 21:46:50 -0500
Message-Id: <>
Content-Type: multipart/alternative; boundary="===============0038370588=="
MIME-Version: 1.0
Subject: [SPAM] Introducing the new and improved Firefox 8, optimized for
From: "Mozilla Firefox" <>
To: undisclosed-recipients:;

No comments: