How to send email like this?

blackhat777

Elite Member
Joined
Jun 25, 2011
Messages
1,784
Reaction score
671
Hi friends,

I don't know where to put this thread, Mods, please move this to appropriate section, if required.

I received an email on one of my id. The email says it's from paypal.
This is what I get on the header of the email:



Date: Fri, 1 Jun 2012 18:50:34 -0500 [06/01/2012 06:50:34 PM CDT]
From: [email protected] <[email protected]>
Bcc: Undisclosed Recipients
Reply-To: [email protected]
Subject: Your account has been limited until we hear from you
Priority: 1




Now, i know that this email is not from paypal as the link they gave in the email body is from an infected site and I don't have a paypal id with this email.
But, how did they fake the from part in this mail?

Any guesses?

Thanks
 
Please pardon the bad color which comes in the post..
I just copy pasted it..


Edit - Corrected it now..
 
Email spoofing FTW!

Can't talk much about it here, but you can do some good research and you'll find some snippets to do that with ease. Although hitting 100% inbox is quite tricky, but if you can manage it, it's a piece of cake.
 
Why cant we talk about email spoofing here... This is Black Hat World, isn't it?
 
just because it is blackhatworld you cannot talk about everything here...
...it`s not crimehatworld, fraudhatworld, scamhatworld etc.

every place has it`s rules and given reasons for them...
...should be obvious if you think about it.
 
This is what people call email spoofing. The sender just try to make it really come from PayPal. The purpose of that email is to stole your PayPal account. The sender just send it to his/her random email list and hope some people fall to his/her trap. So basically he/she don't know if the email target really attached to PayPal account or not. Be careful with this shit all you Guys.
 
ok good question but whats the point of this answer? are you tryin to do the same to other people so you know how to do that??
no offense :)
 
This can be done exactly how you see in the header, you put everything you want in sender field like this [email protected] <[email protected]>. You can try and see for urself. This is not some magic thing, but i wonder if you got the email in inbox, cus if is yes then these guys are really good.
 
Phishing for paypal account information is wrong, unethical and highly illegal. Changing your header information, including the 'from address' is against most anti-spam policies. Instead of going into exactly how this is done I'm going to share with you a guide I wrote on how to detect the location of the original person that sent this message. In this example I'll go through an actual 5pam message that I received.

Step 1 - View the message source
You can easily view the message source of any message. However, there are a plethora of different mailing clients and services. So your best bet is simply Google

How to view message source of "EMAIL CLIENT"

Replace the word "Email Client" with whatever you're using to read emails.

Step 2 - Analyze the Header Information
Now that you can see the source or 'header' information of the email go over to this website:

http://www.mxtoolbox.com/EmailHeaders.aspx

Paste the header information in the box provided and click 'Analyze Header'. You'll receive the path that the email took to get to you. But you'll want to pay special attention to the very first hop.

In this case I can see that this genius is coming from the IP of 41.203.64.130.

Step 3 - Determine if the IP is a known 5pam agent
For this we'll go over to our friends at 5pamhaus. They have a page where you can plug in an IP to determine if it's on their block list (or others).

http://www.5pamhaus.org/lookup/

(note: replace 5 with the letter s in the above URL)

In this case nothing has been reported (yet).

Step 4 - Determine geographical location of sender
You can do this by simply going to any number of websites that translates IP addresses to geographical locations. Here's a site that does a pretty good job:

http://www.ip2location.com/demo

I can see our genius is from Nigeria. Hmmm...

Now what about the offending server?

Step 5 - Determine contact information of server

Based on the information from MX tools we can see that this email came from exch.hwdistributors.com. Whenever you see a period or dot within a domain that's known as a subdomain. In this case exch.hwdistributors.com returns a 404 error, however, hwdistributors.com looks to be a well established company.

From there you could do a simple ‘Whois' search to determine the contact information but wait! There's already a contact page with a phone number?

http://www.hbcdistributors.com/contactus/index.htm

This website seems to be a credible one. So what happened? We have a 5pam message from Nigeria whose sending email from a furniture website from the USA. Compromised server? Disgruntled website owner? Who knows, but atleast now we know how to track down their information...
 
ok great info but if they would use ex HMA then you can not get the IP?Or else whats the point of having proxies?
 
Thanks a lot for the explanation.
Phishing for paypal account information is wrong, unethical and highly illegal. Changing your header information, including the 'from address' is against most anti-spam policies. Instead of going into exactly how this is done I'm going to share with you a guide I wrote on how to detect the location of the original person that sent this message. In this example I'll go through an actual 5pam message that I received.

Step 1 - View the message source
You can easily view the message source of any message. However, there are a plethora of different mailing clients and services. So your best bet is simply Google

How to view message source of "EMAIL CLIENT"

Replace the word "Email Client" with whatever you're using to read emails.

Step 2 - Analyze the Header Information
Now that you can see the source or 'header' information of the email go over to this website:

http://www.mxtoolbox.com/EmailHeaders.aspx

Paste the header information in the box provided and click 'Analyze Header'. You'll receive the path that the email took to get to you. But you'll want to pay special attention to the very first hop.

In this case I can see that this genius is coming from the IP of 41.203.64.130.

Step 3 - Determine if the IP is a known 5pam agent
For this we'll go over to our friends at 5pamhaus. They have a page where you can plug in an IP to determine if it's on their block list (or others).

http://www.5pamhaus.org/lookup/

(note: replace 5 with the letter s in the above URL)

In this case nothing has been reported (yet).

Step 4 - Determine geographical location of sender
You can do this by simply going to any number of websites that translates IP addresses to geographical locations. Here's a site that does a pretty good job:

http://www.ip2location.com/demo

I can see our genius is from Nigeria. Hmmm...

Now what about the offending server?

Step 5 - Determine contact information of server

Based on the information from MX tools we can see that this email came from exch.hwdistributors.com. Whenever you see a period or dot within a domain that's known as a subdomain. In this case exch.hwdistributors.com returns a 404 error, however, hwdistributors.com looks to be a well established company.

From there you could do a simple ‘Whois' search to determine the contact information but wait! There's already a contact page with a phone number?

http://www.hbcdistributors.com/contactus/index.htm

This website seems to be a credible one. So what happened? We have a 5pam message from Nigeria whose sending email from a furniture website from the USA. Compromised server? Disgruntled website owner? Who knows, but atleast now we know how to track down their information...
 
just because it is blackhatworld you cannot talk about everything here...
...it`s not crimehatworld, fraudhatworld, scamhatworld etc.

every place has it`s rules and given reasons for them...
...should be obvious if you think about it.
Bahaha I love this!
 
In fact I'm pretty sure there are a lot of "paypal scam" sites etc that maybe you will be better suited there
 
Back
Top