Help - Search - Members - Calendar
Full Version: Phishing e-mail
B.I.S.S. Forums > Malware Research Forum > Malware IP Research Section
craig
So, I got a phishing e-mail today - nothing unusual there ...
CODE
Return-Path: <pw-conf@southtrust.com>
X-Spam-Status: No, hits=1.3 required=5.8
    tests=HTML_MESSAGE,HTML_TAG_BALANCE_TABLE,MIME_HTML_NO_CHARSET
X-Spam-Level: *
Received: from -1210392176 ([82.226.62.120])
    by mail.rennlist.net
    for <<my email>>;
    Sun, 7 May 2006 06:39:51 -0400
Received: from southtrust.com (-1210391776 [-1210843024])
    by mne69-4-82-226-62-120.fbx.proxad.net (Qmailv1) with ESMTP id AEA815C70E
    for <<<my e-mail>>>; Sun, 07 May 2006 06:43:09 -0400
Date: Sun, 07 May 2006 06:43:09 -0400
From: South Trust Bank <pw-conf@southtrust.com>
X-Mailer: The Bat! (v2.00.5) Personal
X-Priority: 3
Message-ID: <2604857818.20060507064309@southtrust.com>
To: <<my email>>

What I found new to me is when I looked at the html of the email for the "click here" bit, I found:
CODE
Please
confirm your
identity
here:
<a href="rnddomains.txt">Restore My
Online
Banking
Account</a>
and complete
the &quot;Steps
to Remove
Limitations.&quot;

I didn't click, but what is the href pointing at? There was no attachment? How does this work? I'm just curious ...
Aaron.Walkhouse
Copy the whole message and paste it. There was probably a script in there to generate
the URL or decode it because it was hidden from view to avoid spam filters.

If it still resists analysis export the message in whatever mode your program uses to
preserve all of it's structure and PM me for my email address.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.