Wrath of the Lich King Beta Phishing
There is a phishing scam being sent out with a hook of beta participation in World of Warcraft's next expansion, Wrath of the Lich King.
This takes the form of a reasonably well formatted mail (broken in gmail, though, which was the first thing that seemed off to me). It purportedly comes from "WotLK Development Team <wotlkBETA@blizzard.com>". Actual headers are below, for anyone interested.
It has the text:
You have been selected by Blizzard Entertainment to take part in our special World of Warcraft: Wrath of the Lich King BETA testing. To participate simply log into your account at the special World of Warcraft: Wrath of the Lich King site at http://www.worldofwarcraft.com/wotlkbeta . After logging in and confirming your identity, you will be taken to a download page for the Worlf of Warcraft: Wrath of the Lich King BETA Client. We thank you for your help and participation in this process, as customer feedback is one of our most powerful tools in creating an outstanding game for all of our customers. If you do not wish to participate, simply take no action, and your account will remain as it is now.
Blizzard Entertainment Inc
Account Administration Team
P.O. Box 18979, Irvine, CA 92623
Wrath of the Lich King Development Team
Blizzard Entertainment Inc.
Looks convincing enough, except for a few small details of style, but the link text doesn't go to that address; it goes to:
... which is obviously not good (the URL actually given resolves to a 404 error).
There, it asks for your username and password for WoW. That's all anyone needs to steal your account, really.
If you've got that mail, and filled in your details, then first, change your password, and second, contact customer support at Blizzard as soon as possible.
And obviously, letting people in your guild know that this scam is out there would also be good.
The actual headers of the mail I got:
Delivered-To: email@example.com Received: by 10.114.234.6 with SMTP id g6cs368113wah; Wed, 3 Oct 2007 08:55:17 -0700 (PDT) Received: by 10.114.106.1 with SMTP id e1mr4216559wac.1191426916444; Wed, 03 Oct 2007 08:55:16 -0700 (PDT) Return-Path:
Received: from smartws01.smartweb.net (246.173.218.209.transedge.com [18.104.22.168]) by mx.google.com with ESMTP id b32si695980ana.2007.10.03.08.55.15; Wed, 03 Oct 2007 08:55:16 -0700 (PDT) Received-SPF: neutral (google.com: 22.214.171.124 is neither permitted nor denied by best guess record for domain of firstname.lastname@example.org) client-ip=126.96.36.199; Authentication-Results: mx.google.com; spf=neutral (google.com: domain of wotlkBETA@blizzard.com does not designate 188.8.131.52 as permitted sender) email@example.com Received: from smartws01.smartweb.net (smartws01.smartweb.net [127.0.0.1]) by smartws01.smartweb.net (8.12.8/8.12.8) with ESMTP id l93Fx5M4026689 for ; Wed, 3 Oct 2007 11:59:05 -0400 Received: (from root@localhost) by smartws01.smartweb.net (8.12.8/8.12.8/Submit) id l93Fx5W4026687; Wed, 3 Oct 2007 11:59:05 -0400 Date: Wed, 3 Oct 2007 11:59:05 -0400 Message-Id: <200710031559.l93Fx5W4026687@smartws01.smartweb.net> To: firstname.lastname@example.org Subject: Wrath of the Lich King BETA From: WotLK Development Team Content-Type: text/html
Posted by Drew Shiel at October 3, 2007 6:12 PM