NameSilo

My First Phishing Email Supposedly From GoDaddy

Spaceship Spaceship
Watch
Impact
95
:hi:

I'm sure all of you are aware of the phishing emails that look as if they
came from a bank or PayPal or ebay.

Today I received one that supposedly came from GoDaddy.

I just want to give a heads up to everyone and remind you NOT to click on
any links in an email. Go directly to the site instead.

Below is the email I received. It is quite short but following the text is a whole bunch of invisible code.

I've colored the code so you can see it. Does anyone know what this code means or does?

I also cut the link given in the email so no one clicks on it.

Patrick

The email:

From GoDaddy Fri Aug 3 08:39:54 2007
X-Apparently-To: [email protected] via 216.252.100.139; Fri, 03 Aug 2007 08:39:54 -0700
X-YahooFilteredBulk: 201.92.128.67
X-Originating-IP: [201.92.128.67]
Return-Path: <[email protected]>
Authentication-Results: mta242.mail.re3.yahoo.com from=godaddy.com; domainkeys=neutral (no sig)
Received: from 201.92.128.67 (HELO 201-92-128-67.dsl.telesp.net.br) (201.92.128.67) by mta242.mail.re3.yahoo.com with SMTP; Fri, 03 Aug 2007 08:39:54 -0700
Received: from 02kmky1xgzbmsdfx.com (sexpopka.com.sexywivesads.com [42.18.152.0]) by labshost.com with SMTP id EQUT1K40EW for <[email protected]>; Fri, 03 Aug 2007 08:39:41 -0800
Received: from aol.com (HELO armpit.aol.com [33.48.120.116]) by spyderzwebz.com with SMTP id KIBXJ2P0VA for <[email protected]>; Fri, 03 Aug 2007 20:37:41 +0400
X-remove: 59284
From: "GoDaddy" <[email protected]> Add to Address BookAdd to Address Book Add Mobile Alert
To: Send an Instant Message "Ebargain" <[email protected]>
Subject: Alert - online form released! (message id: 2256245472645)
X-remove: 59284
User-Agent: Mozilla 4.61 [en]C-CCK-MCD C-UDP; (Win98; I)
X-Mailer: Mozilla 4.61 [en]C-CCK-MCD C-UDP; (Win98; I)
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/alternative; boundary="--VENC9ORFWU1PF97WS"
Content-Length: 3795
Dear GoDaddy Customer,
GoDaddy Customer Support Team requests you to complete GoDaddy Customer Online Form.
This procedure is obligatory for all customers of GoDaddy.
Please click hyperlink below to access GoDaddy Customer Online Form.
http://myaccount.session-93427745.godaddy.com/AccountConfirmation/
Please do not respond to this email.
This mail generated by an automated service.
Copyright ยฉ 1999 - 2007 GoDaddy.com, Inc. All rights reserved.


The Invisible Code:

=
0x88, 0x05616013, 0x429, 0x074, 0x2569 OZTN, cvs, IR3. 0x89012922 0x038, 0x629, 0x43128186, 0x7887, 0x5, 0x66728643 9VJ: 0x79468866, 0x48, 0x94265661, 0x49467091, 0x43, 0x6, 0x15, 0x44972197, 0x181, 0x51, 0x9846, 0x841, 0x36 0x7, 0x8115, 0x09, 0x61, 0x125, 0x11042443, 0x9, 0x0892, 0x55, 0x0231, 0x559, 0x4280, 0x6 api: 0x58067310, 0x227, 0x11, 0x7177, 0x83756260, 0x809, 0x348, 0x3226, 0x4, 0x7, 0x260 0x8896, 0x64, 0x05710517, 0x696, 0x8, 0x7391, 0x1120, 0x65450522, 0x28, 0x98744297 0x6826, 0x63, 0x3, 0x8, 0x0711, 0x88, 0x234, 0x6, 0x64920055, 0x3, 0x09, 0x522, 0x3, 0x28828313
YW4L: 0x9, 0x6243, 0x26361212, 0x4, 0x223, 0x4808, 0x8953 F2LZ: 0x6, 0x653, 0x5496, 0x09549471, 0x5, 0x05078192, 0x8976 0x4, 0x5687, 0x43428446, 0x512, 0x222, 0x690, 0x53, 0x29871485, 0x1, 0x4493, 0x7243 VEO4 69EC source update interface. start: 0x7203, 0x1829, 0x538, 0x56, 0x53, 0x26, 0x48735352, 0x742, 0x3, 0x7, 0x71632702, 0x19, 0x22643814, 0x5084 0x1, 0x9304, 0x15213262, 0x9335, 0x34 PJA cvs revision WFFD interface R3D exe 9GZO engine. 5P8K: 0x554, 0x25534661, 0x5932, 0x208, 0x86155241, 0x420, 0x39724043, 0x62040995, 0x84794706, 0x98618654, 0x8387 0x44549995, 0x0, 0x4463, 0x9, 0x9621, 0x37, 0x6, 0x8890, 0x1035, 0x301, 0x6226, 0x1157 start: 0x51058006, 0x69, 0x6826, 0x9422, 0x73265151, 0x80773216
0x6519, 0x93, 0x711, 0x4022, 0x8, 0x300, 0x46, 0x9117, 0x3511, 0x046, 0x6375 0x24227646, 0x0584, 0x3 UR3: 0x9, 0x424, 0x46, 0x12923251, 0x053, 0x8, 0x1955, 0x935, 0x5148, 0x00571306, 0x474, 0x36221962, 0x50, 0x07349194 0x797, 0x15473140, 0x69874341, 0x165, 0x8, 0x60, 0x8354, 0x66, 0x2487, 0x00049280 YOI, 954K HGS1, VUC0x45920592 serv: 0x212, 0x8, 0x3, 0x48, 0x08, 0x27316041, 0x3, 0x8, 0x50760274, 0x4, 0x74, 0x2, 0x63643985, 0x51901916 0x723, 0x04, 0x5, 0x35, 0x6, 0x1645 media, EOA, interface, L7Q, hex, UE8, media. update: 0x4
=
0x88, 0x05616013, 0x429, 0x074, 0x2569 OZTN, cvs, IR3. 0x89012922 0x038, 0x629, 0x43128186, 0x7887, 0x5, 0x66728643 9VJ: 0x79468866, 0x48, 0x94265661, 0x49467091, 0x43, 0x6, 0x15, 0x44972197, 0x181, 0x51, 0x9846, 0x841, 0x36 0x7, 0x8115, 0x09, 0x61, 0x125, 0x11042443, 0x9, 0x0892, 0x55, 0x0231, 0x559, 0x4280, 0x6 api: 0x58067310, 0x227, 0x11, 0x7177, 0x83756260, 0x809, 0x348, 0x3226, 0x4, 0x7, 0x260 0x8896, 0x64, 0x05710517, 0x696, 0x8, 0x7391, 0x1120, 0x65450522, 0x28, 0x98744297 0x6826, 0x63, 0x3, 0x8, 0x0711, 0x88, 0x234, 0x6, 0x64920055, 0x3, 0x09, 0x522, 0x3, 0x28828313
YW4L: 0x9, 0x6243, 0x26361212, 0x4, 0x223, 0x4808, 0x8953 F2LZ: 0x6, 0x653, 0x5496, 0x09549471, 0x5, 0x05078192, 0x8976 0x4, 0x5687, 0x43428446, 0x512, 0x222, 0x690, 0x53, 0x29871485, 0x1, 0x4493, 0x7243 VEO4 69EC source update interface. start: 0x7203, 0x1829, 0x538, 0x56, 0x53, 0x26, 0x48735352, 0x742, 0x3, 0x7, 0x71632702, 0x19, 0x22643814, 0x5084 0x1, 0x9304, 0x15213262, 0x9335, 0x34 PJA cvs revision WFFD interface R3D exe 9GZO engine. 5P8K: 0x554, 0x25534661, 0x5932, 0x208, 0x86155241, 0x420, 0x39724043, 0x62040995, 0x84794706, 0x98618654, 0x8387 0x44549995, 0x0, 0x4463, 0x9, 0x9621, 0x37, 0x6, 0x8890, 0x1035, 0x301, 0x6226, 0x1157 start: 0x51058006, 0x69, 0x6826, 0x9422, 0x73265151, 0x80773216
0x6519, 0x93, 0x711, 0x4022, 0x8, 0x300, 0x46, 0x9117, 0x3511, 0x046, 0x6375 0x24227646, 0x0584, 0x3 UR3: 0x9, 0x424, 0x46, 0x12923251, 0x053, 0x8, 0x1955, 0x935, 0x5148, 0x00571306, 0x474, 0x36221962, 0x50, 0x07349194 0x797, 0x15473140, 0x69874341, 0x165, 0x8, 0x60, 0x8354, 0x66, 0x2487, 0x00049280 YOI, 954K HGS1, VUC0x45920592 serv: 0x212, 0x8, 0x3, 0x48, 0x08, 0x27316041, 0x3, 0x8, 0x50760274, 0x4, 0x74, 0x2, 0x63643985, 0x51901916 0x723, 0x04, 0x5, 0x35, 0x6, 0x1645 media, EOA, interface, L7Q, hex, UE8, media. update
 
Last edited:
0
•••
The views expressed on this page by users and staff are their own, not those of NamePros.
Unstoppable Domains โ€” AI StorefrontUnstoppable Domains โ€” AI Storefront
tricolorro said:
:hi:

I'm sure all of you are aware of the phishing emails that look as if they
came from a bank or PayPal or ebay.

Today I received one that supposedly came from GoDaddy.

I just want to give a heads up to everyone and remind you NOT to click on
any links in an email. Go directly to the site instead.

Below is the email I received. It is quite short but following the text is a whole bunch of invisible code.

I've colored the code so you can see it. Does anyone know what this code means or does?

I also cut the link given in the email so no one clicks on it.

Patrick

Thanks for the heads up tricolorro

I'm one of those guys who clicks on just about anything (except my own ads of course) :)

NoRest
 
0
•••
Dynadot โ€” .com TransferDynadot โ€” .com Transfer
Appraise.net
Domain Recover
DomainEasy โ€” Payment Flexibility
  • The sidebar remains visible by scrolling at a speed relative to the pageโ€™s height.
Back