fake URL displayed within "phishing" messages

Whether you're a MailWasher veteran or complete newbie, all users are welcome to get together. Discussions include usage and possible problems.
stapel
Rattled Rabbit
Posts: 3
Joined: Tue Nov 11, 2008 1:57 am

fake URL displayed within "phishing" messages

Tue Nov 11, 2008 2:21 am

As do we all, I receive "phishing" e-mail messages. Generally they're easy to ignore, being, say, from banks with whom I've never done business. But every once in a while the apparent (but false) identity of the sender leads me to take a closer look.

By mousing over the "Click here to update your account information" link in the Mailwasher "preview" pane, it is usually obvious that a suspect link leads somewhere bad, and that the message is clearly not actually from, say, Chase Bank. However, sometimes I must "View Raw Source" in order to "see" the actual target URL. For instance, I received the following this morning:
A phisher wrote:...To access the form please click on the following link:http://chaseonline.chase.com/Secure/webform/OSL.aspx?LOB=
723882879499936098792271620242477102106597514524Thank you for being a valued customer.
This looks like it's legitimate, and the URL displayed on "hover" is the one displayed above. However, the raw coding of the message displays the following:
In the code, the phisher wrote:<p><font face=3D"Times New Roman, serif">To access the form please click =
on the following link:</font></p>
<p><font face=3D"Times New Roman, serif"><a href=3D"http://chaseonline.ch=
ase.com.id017.cz
/Secure/webform/OSL.aspx?LOB=3D72388287949993609879227162=
0242477102106597514524">http://chaseonline.chase.com/Secure/webform/OSL.a=
spx?LOB=3D723882879499936098792271620242477102106597514524</a></font></p>
<p><font face=3D"Times New Roman, serif">Thank you for being a valued cus=
tomer.</font></p>
Is this contradictory result due to the message having been "a multi-part message in MIME format"? Is the fake URL displaying in the "normal" preview pane because it is included in the "text/plain" part of the message, with the actual URL being "hidden" in the "text/html" part?

Is there any way to force the "preview" pane to accurately display the genuine URL, other than setting the default display to "raw source"?

Thank you.

Eliz.
Ikeb
Microsoft MVP with a slice of PITA
Contact:
Location: Ottawa, Ontario, Canada
Posts: 455
Joined: Thu Jul 24, 2008 3:56 pm

Re: fake URL displayed within "phishing" messages

Tue Nov 11, 2008 4:08 am

Clever. The phisher displays a valid URL but the html code has the real URL hidden. It certainly would be a good thing if MWP would dive into a URL irrespective of the view type in order to make this form of cloaking more obvious.

Return to “Troubleshooting and Help for MailWasher 5 and 6”