We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Unusual http in spam mail?

I was rolling someones computer back from windows 10 to 7 and helping them have a sortout and block some spam.

They have lots, mostly 1 liners with buy this or get something free, a couple had their first name. Either linked to proper URLs or IP addresses directly.

But a few had http....://....0xd84b3e07 (without the full stops) I have not attempted
to try them yet.



Think HexDecimal format but im stumped on producing a URL or IP from it? Anyone?

Thanks.
Censorship Reigns Supreme in Troll City...

Comments

  • esuhl
    esuhl Posts: 9,409 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    Maybe that part of the URL is a unique identifier for the user, so the spammers know who clicked the link in the email?

    So long as the domain is there, I guess (I'm no expert) that the server could interpret the rest of the URL as it liked (using the hex value as a parameter, rather than pointing to a specific web page).
  • tronator
    tronator Posts: 2,859 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    I was rolling someones computer back from windows 10 to 7 and helping them have a sortout and block some spam.

    They have lots, mostly 1 liners with buy this or get something free, a couple had their first name. Either linked to proper URLs or IP addresses directly.

    But a few had http....://....0xd84b3e07 (without the full stops) I have not attempted
    to try them yet.



    Think HexDecimal format but im stumped on producing a URL or IP from it? Anyone?

    Thanks.

    https://www.miniwebtool.com/ip-address-to-hex-converter/
  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper Photogenic
    The hex string you entered converts to ip address : 0.216.75.62
  • tronator
    tronator Posts: 2,859 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    AndyPix wrote: »
    The hex string you entered converts to ip address : 0.216.75.62

    More like 216.75.62.7

    The "0x" at the beginning only describes that the following is hexadecimal.
  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper Photogenic
    Of course it does

    My bad
  • forgotmyname
    forgotmyname Posts: 32,946 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    esuhl wrote: »
    Maybe that part of the URL is a unique identifier for the user, so the spammers know who clicked the link in the email?

    So long as the domain is there, I guess (I'm no expert) that the server could interpret the rest of the URL as it liked (using the hex value as a parameter, rather than pointing to a specific web page).

    That is the URL and yes the spam mails do have unique ID strings that will identify them. It did seem a little odd that so many emails had that same URL but appeared to come from different email senders. I didnt want to ask and pry.
    Censorship Reigns Supreme in Troll City...

  • forgotmyname
    forgotmyname Posts: 32,946 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    Anyone have a clue as to who that IP address belongs to or is is one where they share it out and the characters after point towards the site or page that collects the users data?

    All the emails did have 4 - 6 characters after the 3e07.

    And yep i had forgotten about the 0x just meaning hex. Thanks.
    Censorship Reigns Supreme in Troll City...

  • AndyPix
    AndyPix Posts: 4,847 Forumite
    Fifth Anniversary 1,000 Posts Name Dropper Photogenic
    ip resolves to saldo.nbaarchives.net

    And it seems like they don't want to be traced .. Whodathunkit ??

    http://whois.icann.org/en/lookup?name=saldo.nbaarchives.net
  • forgotmyname
    forgotmyname Posts: 32,946 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    42c96cd3 = 66.201.108.211 (vietfoot.net) ?
    Another one registered in Panama.

    I asked the awkward question and it seems they had debts which they hid from and said the email address they are getting the spam on is one they used for the credit cards.
    Whilst the debt collectors were chasing them they would receive emails with offers for cheap items like TV's and consoles etc.

    They wondered if the debt collectors were responsible because the emails also have their name?
    But its an AOL account and im pretty sure they had a security breach where emails and account details were compromised. So mayb the the name and email were linked from that?
    Censorship Reigns Supreme in Troll City...

  • forgotmyname
    forgotmyname Posts: 32,946 Forumite
    Part of the Furniture 10,000 Posts Name Dropper
    They received 60 spam emails yesterday. I checked a few with URLs and the same HEX address pops up a lot, but a few others also popup.

    They all seem to be registered in PANAMA.

    So glad i use a different email for virtually everything. If that happened to me i could just close the email and move onto another one.

    They have they banking etc on the same email address, they are going to start shifting stuff across and do not like my method of lots of accounts.

    Got them to have 3 so better than nothing, one for sensitive data like banking etc, one for family and another for forums etc.
    Censorship Reigns Supreme in Troll City...

This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.