actually after doing a tad bit of research, it was an {img}{/img} link to an html page that had iframe html code encoded in hexadecimal. I don't think it even really rendered. I could be wrong though.
actually.. lesse...
test
yeah, with a test html url, the forum software does the same behavior. It's a damn good thing that this forum has no ability to render iframes, which is this malware's main form of atack