An easy way to de-obfuscate this is to give your browser this URL. Works
at least with Mozilla, but I think other browsers support the javascript:
pseudo-protocol, too.
javascript:alert(decodeURI('<obfuscated-URL-here>'))
We have seen this done and exploited *mostly* on IRC spam (directed at the mIRC client).
Let's decode a URL that may end up making IE destroying the PC or emailing our passwords.. or downloading a dropper or,,, :o)
Gadi
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
