Saturday, August 06, 2011

Phishing Attack: Fake Twitter Email not marked as Spam

I got an email in my Gmail account from "Twitter Support" "with subject "Your account has been suspended" with no text content but an image (that I have disabled of course for security reasons). The image content was something like "We detected unusual activity ..."

This phishing email is nothing new but what came to my attention was that Gmail was not able to detect the spam even though the full headers from the message are showing how Google identified it as a candidate for Spam "Authentication-Results:; spf=hardfail ( domain of does not designate as permitted sender)"

Any software is plenty of bugs. Even with the best developers on board you are still vulnerable. Good that "Report phishing" option is available albeit a little bit hidden behind an arrow close to the Reply link. User experience should be helping better here I would say but regardless the important lesson to learn is to be always suspicious up front. Do not trust any bad news (account hacked or compromised) or too good news (You just won a million dollar) you receive.

See below for the full headers of the message:
Received: by with SMTP id g64cs68259yhm;
        Fri, 5 Aug 2011 22:37:44 -0700 (PDT)
Received: from ([])
        by with SMTP id k15mr3461337wff.111.1312609063904 (num_hops = 1);
        Fri, 05 Aug 2011 22:37:43 -0700 (PDT)
Received: by with SMTP id k15mr2917056wff.111.1312609063502;
        Fri, 05 Aug 2011 22:37:43 -0700 (PDT)
Return-Path: <>
Received: from ( [])
        by with ESMTP id w1si282094wfw.62.2011.;
        Fri, 05 Aug 2011 22:37:43 -0700 (PDT)
Received-SPF: fail ( domain of does not designate as permitted sender) client-ip=;
Authentication-Results:; spf=hardfail ( domain of does not designate as permitted sender)
X-IronPort-Anti-Spam-Filtered: true
Received: from (HELO ([])
  by with ESMTP; 06 Aug 2011 13:37:41 +0800
Received: from (unknown [])
 by (Postfix) with ESMTP id 55F8793DB3A
 for <>; Sat,  6 Aug 2011 13:37:41 +0800 (PHT)
From: "Twitter Support" <>
Subject: Your account has been suspended
To: "nestor.urquiza" <>
Content-Type: multipart/alternative; charset="iso-8859-10"; boundary="LMRJGCZhTXlUeMlXLirvgZD=_SMWAE68zR"
MIME-Version: 1.0
Content-Transfer-Encoding: 8bit
Date: Sat, 6 Aug 2011 13:37:37 +0800
Message-Id: <>

This is a multi-part message in MIME format

Content-Type: text/plain ; charset="iso-8859-10"
Content-Transfer-Encoding: quoted-printable

Content-Type: text/html ; charset="iso-8859-10"
Content-Transfer-Encoding: quoted-printable

<META name=3DGENERATOR content=3D"MSHTML 8.00.6001.23019"></HEAD>
<P><A href=3D"
%2Etc/2ule3B"><IMG border=3D0 src=3D"
Yjes/TjyqVZ73vrI/AAAAAAAAAEQ/hX5mKS-R7-g/s1600?2ule3B"></A> </P>


No comments: