Saturday, August 06, 2011

Phishing Attack: Fake Twitter Email not marked as Spam

I got an email in my Gmail account from "Twitter Support" "with subject "Your account has been suspended" with no text content but an image (that I have disabled of course for security reasons). The image content was something like "We detected unusual activity ..."

This phishing email is nothing new but what came to my attention was that Gmail was not able to detect the spam even though the full headers from the message are showing how Google identified it as a candidate for Spam "Authentication-Results: mx.google.com; spf=hardfail (google.com: domain of support@twitter.com does not designate 203.115.131.123 as permitted sender) smtp.mail=support@twitter.com"

Any software is plenty of bugs. Even with the best developers on board you are still vulnerable. Good that "Report phishing" option is available albeit a little bit hidden behind an arrow close to the Reply link. User experience should be helping better here I would say but regardless the important lesson to learn is to be always suspicious up front. Do not trust any bad news (account hacked or compromised) or too good news (You just won a million dollar) you receive.

See below for the full headers of the message:
Delivered-To: nestor.urquiza@gmail.com
Received: by 10.236.179.100 with SMTP id g64cs68259yhm;
        Fri, 5 Aug 2011 22:37:44 -0700 (PDT)
Received: from mr.google.com ([10.142.187.15])
        by 10.142.187.15 with SMTP id k15mr3461337wff.111.1312609063904 (num_hops = 1);
        Fri, 05 Aug 2011 22:37:43 -0700 (PDT)
Received: by 10.142.187.15 with SMTP id k15mr2917056wff.111.1312609063502;
        Fri, 05 Aug 2011 22:37:43 -0700 (PDT)
Return-Path: <support@twitter.com>
Received: from vsfilter2.roc.bti.net.ph (vsf-mx4.bti.net.ph [203.115.131.123])
        by mx.google.com with ESMTP id w1si282094wfw.62.2011.08.05.22.37.42;
        Fri, 05 Aug 2011 22:37:43 -0700 (PDT)
Received-SPF: fail (google.com: domain of support@twitter.com does not designate 203.115.131.123 as permitted sender) client-ip=203.115.131.123;
Authentication-Results: mx.google.com; spf=hardfail (google.com: domain of support@twitter.com does not designate 203.115.131.123 as permitted sender) smtp.mail=support@twitter.com
X-IronPort-Anti-Spam-Filtered: true
X-IronPort-Anti-Spam-Result: AqA2AOHRPE7Lc4NugWdsb2JhbAAoEwcXgjgBD4NgjV+EQwGOLRNcAQEWJiVxSxISGQELCk0BAQECDQ4MJAJQh3oKIgGeN5I1jSaDLQyCLl8Eh1qYFoMBgQaCYTA
Received: from smtp4-roc.bti.net.ph (HELO smtp1.skyinet.net) ([203.115.131.110])
  by vsfilter2.roc.bti.net.ph with ESMTP; 06 Aug 2011 13:37:41 +0800
Received: from 110.55.232.159.BTI.NET.PH (unknown [110.55.236.20])
 by smtp4-roc.bti.net.ph (Postfix) with ESMTP id 55F8793DB3A
 for <nestor.urquiza@gmail.com>; Sat,  6 Aug 2011 13:37:41 +0800 (PHT)
From: "Twitter Support" <support@twitter.com>
Subject: Your account has been suspended
To: "nestor.urquiza" <nestor.urquiza@gmail.com>
Content-Type: multipart/alternative; charset="iso-8859-10"; boundary="LMRJGCZhTXlUeMlXLirvgZD=_SMWAE68zR"
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Date: Sat, 6 Aug 2011 13:37:37 +0800
Message-Id: <20110806053741.55F8793DB3A@smtp4-roc.bti.net.ph>

This is a multi-part message in MIME format

--LMRJGCZhTXlUeMlXLirvgZD=_SMWAE68zR
Content-Type: text/plain ; charset="iso-8859-10"
Content-Transfer-Encoding: quoted-printable




--LMRJGCZhTXlUeMlXLirvgZD=_SMWAE68zR
Content-Type: text/html ; charset="iso-8859-10"
Content-Transfer-Encoding: quoted-printable

<HTML><HEAD>
<META name=3DGENERATOR content=3D"MSHTML 8.00.6001.23019"></HEAD>
<BODY>
<P><A href=3D"mexico.cnn.com/redirectComplete.php?url=3D//emailus%2Eit=
%2Etc/2ule3B"><IMG border=3D0 src=3D"http://3.bp.blogspot.com/-u_sWLHS=
Yjes/TjyqVZ73vrI/AAAAAAAAAEQ/hX5mKS-R7-g/s1600?2ule3B"></A> </P>
<P>&nbsp;</P></BODY></HTML>


--LMRJGCZhTXlUeMlXLirvgZD=_SMWAE68zR--                                                                                                                                                                                                                                                    

No comments:

Followers