The URLs
To locate the active URL in the e-mail, you must
look at the source code. Depending on your mail client the URL will resemble one of the following:
http://www.geek.scif.mx.com|net.fr.
com-rules.com:80/geek/scifigeekmaster/
http://www.hi4.twidd.mx^T^B^T^E^T.com|net.fr^B^E^T^B^T^E^T^T.
londonville.org:80/hi4/twiddlez/"
http://www.ri2.itslg.mx=14=02=14=05=14.com|net.fr=02=05
=14=02=14=05=14=14.oooooooooooooooooo.com:80/ri2/itslgsot/"
http://www.id2.lasog.mx|.com|net.fr

.oooooooooooooooooo.com:80/id2/lasoghsgw/
http:// www.rh085.com|corbis.fr
\020\005\020\002\020\005\020\002\020\005
\020\002.clza.com:80/wa2/eoqeralsks/
http://www.myband.worldonfire.mx%3D14%3D02%3D14%3D05%3D14.com%7Cnet.fr
%3D02%3D05%3D14%3D%3D02%3D14%3D05%3D14%3D14.com-rules.com
%3A80%/myband/worldonfire
So, the way to find the active URL in the source code is to look for a long URL containing what appear to be boxes(
),control
characters(^T), equal sign followed by a number (=2), ampersand and number sign followed by a number (), three digit numbers separated by backslash(\020\) or a percent sign and number (%20) series.
Immediately following this series will be a domain name possibly followed by a":80" or another port number. Just after the number or the domain name will be a forward slash (/). The next two sets of entries will be the address for the page on angelfire. Currently
ET is using jjjjjjjj.com, previous names have included Londonville.org and com-rules.com, these may be different in your
spam as these change usually monthly.
In mid November, there was a new version posted that did not use the control
characters. This version did not go through a page at Angelfire, all other
properties remained the same.
- Current
Sites
- This link
leads to a page that contains the most recent URLs from the
stealth window spams. Each URL will show the date added, and the
decoded links to the final site.
- Lart
Targets
- This link
contains contact addresses for the parties involved in hosting the
websites and nameservers. Use the information on the Current Sites
for the locations, then look here for contact information
regarding those sites.