Solved

encoded url's in spam email

Posted on 2004-10-18
9
164 Views
Last Modified: 2013-12-04
Anyone know of an app to decrypt url's like this one
http://%32%31%36%2E%32%30%37%2E%36%30%2E%33%36:%38%37/%73%74/%69%6E%64%65%78%2E%68%74%6D
I know these "phishing" emails all seem to point to some url and then port 87, i would like to decrypt this url to find the port 87 part.
Thanks.
0
Comment
Question by:TuscolaCounty
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
9 Comments
 
LVL 17

Expert Comment

by:Lobo042399
ID: 12338577
216.207.60.36:38/st/index.htm

Open your Character Map (Start>Programs>Accesories>System Tools). Select a Unicode font (look for any that has the big "O" icon.) Hitting on any of the regular letters and numbers will display their Unicode code.

Good Vibes!

Lobo
0
 
LVL 49

Accepted Solution

by:
sunray_2003 earned 250 total points
ID: 12338581
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 12338592
The above software , you can just open the software after installing.

Then go to Tasks --> URL decoder
paste the url that you have in the email and press OK and it should give you the result..
0
Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

 

Author Comment

by:TuscolaCounty
ID: 12338640
Which version of the software? Workstation?
And the character map thing, I am not able to find how to decode using that.
0
 

Author Comment

by:TuscolaCounty
ID: 12338647
wait, wrong software, i downloaded netdemon, will try. tnx
0
 

Author Comment

by:TuscolaCounty
ID: 12338670
ok, netdemon has decoded the url, here is it's findings: But it doesn't tell me which part of the coded url is the port 87 part.

http://%32%31%36%2E%32%30%37%2E%36%30%2E%33%36:%38%37/%73%74/%69%6E%64%65%78%2E%68%74%6D

--- Decoded all hex characters: (note: this result may not be a valid URL)

http://216.207.60.36:87/st/index.htm

--- Broken down URL components:

 Protocol:  http
     Host:  216.207.60.36
     Port:  0
     Path:  /st/
     File:  index.htm

--- Decoded URL:

http://216.207.60.36:0/st/index.htm

--- resolving IP [216.207.60.36], please wait...

 216-207-60-36.gssmail.com [216.207.60.36]
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 12338690
TuscolaCounty,

Why do you want to know about port 87 and where did you find it
0
 

Author Comment

by:TuscolaCounty
ID: 12338992
We receive "phishing" emails (spam of sort) and are trying to block them through our email server anti-spam filter. They are quite hard to block because there is reallyno unique body text, url, from address or anything else. The one thing they all seem to have in common is that whatever url they are pointing at is set to use port 87.
See above analisys from netdemon.
I have figured a way to block them though, set up a rule to block any email containing body text http://%
And it catches the encoded urls.
Giving the points to sunray 2003 for the link to netdemon.
0
 
LVL 49

Expert Comment

by:sunray_2003
ID: 12339011
Glad i was able to assist
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Article by: btan
The intent is not to repeat what many has know about Ransomware but more to join its dots of what is it, who are the victims, why it exists, when and how we respond on infection. Lastly, sum up in a glance to share such information with more to help…
OfficeMate Freezes on login or does not load after login credentials are input.
This video Micro Tutorial shows how to password-protect PDF files with free software. Many software products can do this, such as Adobe Acrobat (but not Adobe Reader), Nuance PaperPort, and Nuance Power PDF, but they are not free products. This vide…
In this video we outline the Physical Segments view of NetCrunch network monitor. By following this brief how-to video, you will be able to learn how NetCrunch visualizes your network, how granular is the information collected, as well as where to f…

724 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question