The Latest in IT Security

The Hexadecimal URL Obfuscation Resurgence

02
May
2013

For that past several days, Symantec has observed an increase in spam messages containing hexadecimal obfuscated URLs. Hexadecimal character codes are simply the hexadecimal number to letter representation for the ASCII character set. To a computer, hexadecimal is just one out of the many systems for address expressions on the Internet.

The following samples are different hexadecimal representations for http://www.symantec.com.

Hexadecimal only:

http://www.

symantec.co&#x006d

Hexadecimal and ASCII characters:   

(“http” and “com” are in ASCII characters and the rest of the URL is in hexadecimal)

http://www.sym

antec.com 

(“http://www” is in hexadecimal and the rest of the URL is in ASCII characters)

http://www.symantec.com

Symantec has observed several hexadecimal URL obfuscation techniques used by spammers.
 

Hexadecimal resurgence 1.png

Figure 1. Spam email using hexadecimal URL obfuscation techniques
 

Hexadecimal resurgence 2.png

Figure 2. Source code of spam email (Figure 1.) using hexadecimal URL obfuscation techniques
 

Hexadecimal URL obfuscation is not a new spamming technique. The technique is used to evade anti-spam filters because anti-spam engines are sensitive to every single character in a message body. With the recent spike in hexadecimal spam volumes, Symantec will continue to monitor these attacks and will react accordingly.

Leave a reply


Categories

THURSDAY, MARCH 28, 2024
WHITE PAPERS

Mission-Critical Broadband – Why Governments Should Partner with Commercial Operators:
Many governments embrace mobile network operator (MNO) networks as ...

ARA at Scale: How to Choose a Solution That Grows With Your Needs:
Application release automation (ARA) tools enable best practices in...

The Multi-Model Database:
Part of the “new normal” where data and cloud applications are ...

Featured

Archives

Latest Comments