Reverse Engineering Obfuscated Javascript
I keep getting these spam emails which are making it past Gmail’s spam filter. Basically, it looks like a ‘delivery failed’ notification, with an HTML attachment which you are supposed to think is the original email. So you click on the attachment and open it, to find out which email you sent failed to go through. I finally got curious enough to see what exactly was going on. Here’s how the email looks like in Gmail:

Here’s the actual full contents of the email (some ip / email addresses removed to protect the innocent)
(more…)
