Email [HTML]

The constant threat: viruses, trojans, spyware, ... the list goes on

Email [HTML]

Post by ademske on Sun Apr 17, 2011 5:00 am
([msg=56405]see Email [HTML][/msg])

Hi Guys,

I recently received a fake email from "facebook" containing some HTML, I have a ruff idea on what it is doing but not 100% sure. what do you think??

Code: Select all
<html>



<head>

<meta http-equiv="Content-Language" content="en-us">

<meta http-equiv="Content-Type" content="text/html; charset=windows-1252">

<title>New Page 1</title>

<style>

<!--

body {font-family:Tahoma,Verdana,Arial,sans-serif;line-height:normal;}BODY{font-size:83%}body{display:none;}body{display:block !important;}BODY.IE{cursor:progress;}.ExternalClass {font-family:Tahoma,Verdana,Arial,sans-serif;line-height:normal;}.ExternalClass{font-size:10pt;}-->

</style>

</head>



<body>



<div id="c_ic_menus">

   <div class="App Unmanaged BottomUnmanaged" id="PageElt">

      <div class="AppInner" style="BEHAVIOR: null; WIDTH: 76.29em; HEIGHT: 44.56em" __resizeAttached="true" _doResize="null" _willBeResized="false" _isResizing="null">

         <div class="Middle" id="Middle" style="BEHAVIOR: null; WIDTH: 76.27em; HEIGHT: 39.94em" __resizeAttached="true" _willBeResized="false" _isResizing="null">

            <div class="ContentRight WithSkyscraper" id="contentRight" style="WIDTH: auto" _doResize="null" _willBeResized="false">

               <form id="aspnetForm" name="aspnetForm" onsubmit="var btn=window.document.getElementById('psbtn');if(this.s &amp;&amp; btn){btn.click(); return false;}" method="post" target="_self" encType="multipart/form-data" action="http://sn130w.snt130.mail.live.com/mail/InboxLight.aspx?n=1417741028">

                  <div id="ManagedContentWrapper" style="BEHAVIOR: null; WIDTH: 63.4em; TOP: 4.44em; HEIGHT: 0em" __resizeAttached="true" _doResize="null" _willBeResized="false" _isResizing="null">

                     <div class id="MainContent" style="BEHAVIOR: null; WIDTH: 51.17em" __resizeAttached="true" _isResizing="null">

                        <div class="ReadMsgMode" id="mainContentContainer">

                           <div class="MsgListMainContainer" id="msgListMainContainer" style="BEHAVIOR: null; TOP: 0em">

                              <div class="ReadingPaneSplitPane ReadingPaneSplitPaneFull" id="readingPaneSplitPane" style="BEHAVIOR: null" _willBeResized="false">

                                 <div class="ReadingPaneContainer ReadingPaneContainerNoActionBar" id="readingPaneContainer" onscroll="InboxPage.onMessageScroll(this)">

                                    <div class="ClearBoth PreviousMessageDisabled" id="readingPaneContentContainer" mid="f54cde10-ab31-11df-8162-00237de3ede0">

                                       <div class="MsgPartsContainer ClearBoth" id="msgParts">

                                          <div class="HasLayout" fid="00000000-0000-0000-0000-000000000005" ci mad="2118|0|8CD0D55DE7EA150||0|0|0|9|" mid="f54cde10-ab31-11df-8162-00237de3ede0" nr="nr" ex="ex" fb="fb" hfb="hfb" hb="hb" ca="notification+i=p6rfef@facebookmail.com" cn="Facebook" ic="rmic1" pfx="mp0_" idx="0">

                                             <div class=" Expanded">

                                                <div class="ReadMsgContainer HasLayout ClearBoth FullPart NoHistory Unread RmIc ShowH" style="Z-INDEX: 600" _doResize="null" _willBeResized="false">

                                                   <div id="mp0_ctr">

                                                      <div class="MsgPartBody FullBody ClearBoth" id="mp0_msgPartFullBody">

                                                         <div nr="nr" pfx="mpf0_" sf="m" fa="Forward" raa="ReplyAll" ra="Reply" rfu="EditMessageLight.aspx?ReadMessageId=f54cde10-ab31-11df-8162-00237de3ede0&amp;FolderID=00000000-0000-0000-0000-000000000005&amp;Aux=2118%7c0%7c8CD0D55DE7EA150%7c%7c0%7c0%7c0%7c9%7c&amp;SenderEmail=notification%2bi%3dp6rfef%40facebookmail.com&amp;n=374738890&amp;Action={0}&amp;AllowUnsafe={1}">

                                                            <div class="ReadMsgBody" id="mpf0_readMsgBodyContainer" onclick="return Control.invoke('MessagePartBody','_onBodyClick',event);">

                                                               <div class="ExternalClass PlainTextMessageBody ContentFiltered" id="mpf0_MsgContainer">

                                                                  <pre>Emma commented on your photo.



Emma Brite wrote:

&quot;mmmm Nice Likee Likee Like <3!!! &quot;





Reply to this email to comment on this photo.



To see the comment thread, follow the link below:

<a onclick="onClickUnsafeLink(event);" target="_blank" style="color: #0066CC; text-decoration: none" href="http://mylovemusic.com/">http://www.facebook.com/n/?photo.php&amp;pid=295038&amp;id=1704181049&amp;mid=2d68770G6593bd39G80875fG9&amp;n_m=</a>



Thanks,

The Facebook Team



___

Find people from your Windows Live Hotmail address book on Facebook! Go to: <a href="http://mylovemusic.com/"><font color="#0066CC">http://www.facebook.com/find-friends/?ref=email</font></a>



This message was intended for. If you do not wish to receive this type of email from Facebook in the future, please follow the link below to unsubscribe.

<a href="http://mylovemusic.com/"><font color="#0066CC">http://www.facebook.com/o.php?k=d4ba22&amp;u=1704181049&amp;mid=2d68770G6593bd39G80875fG9</font></a>

Facebook, Inc. P.O. Box 10005, Palo Alto, CA 94303</pre>

ademske
New User
New User
 
Posts: 1
Joined: Sun Apr 17, 2011 4:53 am
Blog: View Blog (0)


Re: Email [HTML]

Post by goluhaque on Sun Apr 17, 2011 9:20 am
([msg=56406]see Re: Email [HTML][/msg])

ademske wrote:Hi Guys,

I recently received a fake email from "facebook" containing some HTML, I have a ruff idea on what it is doing but not 100% sure. what do you think??



Yeah, that shit is from a phisher.
Code: Select all
<[color=#FF0000]a href="http://mylovemusic.com/[/color]"><font color="#0066CC">http://www.facebook.com/o.php?k=d4ba22&amp;u=1704181049&amp;mid=2d68770G6593bd39G80875fG9</font></a>
(23:45:03) hauk: I guess you are over the best part of your life when 4-year-olds say "Are you an evil man?"
(23:46:19) hauk: and "Ima punch you in the pecker"
User avatar
goluhaque
Poster
Poster
 
Posts: 153
Joined: Mon Apr 13, 2009 12:08 am
Location: India
Blog: View Blog (0)


Re: Email [HTML]

Post by msbachman on Sun Apr 17, 2011 9:48 am
([msg=56407]see Re: Email [HTML][/msg])

And who's profile is this, anyway? (Taken from goluhaque post, the id, appended to profile.php?id=xxx, you get the idea).

OP or some random dude the phisher is using?
"I'm going to get into your sister. I'm going to get my hands on your daughter."
~Gatito
User avatar
msbachman
Contributor
Contributor
 
Posts: 685
Joined: Mon Jan 12, 2009 10:22 pm
Location: In the sky lol
Blog: View Blog (0)



Return to Malware

Who is online

Users browsing this forum: No registered users and 0 guests