Wrath of the Lich King Beta Phishing
There is a phishing scam being sent out with a hook of beta participation in World of Warcraft's next expansion, Wrath of the Lich King.
This takes the form of a reasonably well formatted mail (broken in gmail, though, which was the first thing that seemed off to me). It purportedly comes from "WotLK Development Team <wotlkBETA@blizzard.com>". Actual headers are below, for anyone interested.
It has the text:
Greetings,You have been selected by Blizzard Entertainment to take part in our special World of Warcraft: Wrath of the Lich King BETA testing. To participate simply log into your account at the special World of Warcraft: Wrath of the Lich King site at http://www.worldofwarcraft.com/wotlkbeta . After logging in and confirming your identity, you will be taken to a download page for the Worlf of Warcraft: Wrath of the Lich King BETA Client. We thank you for your help and participation in this process, as customer feedback is one of our most powerful tools in creating an outstanding game for all of our customers. If you do not wish to participate, simply take no action, and your account will remain as it is now.
Blizzard Entertainment Inc
Account Administration Team
P.O. Box 18979, Irvine, CA 92623Regards,
Wrath of the Lich King Development Team
Blizzard Entertainment Inc.
Looks convincing enough, except for a few small details of style, but the link text doesn't go to that address; it goes to:
http://wowtlk-beta.awardspace.co.uk/index.html
... which is obviously not good (the URL actually given resolves to a 404 error).
There, it asks for your username and password for WoW. That's all anyone needs to steal your account, really.
If you've got that mail, and filled in your details, then first, change your password, and second, contact customer support at Blizzard as soon as possible.
And obviously, letting people in your guild know that this scam is out there would also be good.
The actual headers of the mail I got:
Delivered-To: gothwalk@gmail.com Received: by 10.114.234.6 with SMTP id g6cs368113wah; Wed, 3 Oct 2007 08:55:17 -0700 (PDT) Received: by 10.114.106.1 with SMTP id e1mr4216559wac.1191426916444; Wed, 03 Oct 2007 08:55:16 -0700 (PDT) Return-Path:Received: from smartws01.smartweb.net (246.173.218.209.transedge.com [209.218.173.246]) by mx.google.com with ESMTP id b32si695980ana.2007.10.03.08.55.15; Wed, 03 Oct 2007 08:55:16 -0700 (PDT) Received-SPF: neutral (google.com: 209.218.173.246 is neither permitted nor denied by best guess record for domain of root@smartws01.smartweb.net) client-ip=209.218.173.246; Authentication-Results: mx.google.com; spf=neutral (google.com: domain of wotlkBETA@blizzard.com does not designate 209.218.173.246 as permitted sender) smtp.mail=root@smartws01.smartweb.net Received: from smartws01.smartweb.net (smartws01.smartweb.net [127.0.0.1]) by smartws01.smartweb.net (8.12.8/8.12.8) with ESMTP id l93Fx5M4026689 for ; Wed, 3 Oct 2007 11:59:05 -0400 Received: (from root@localhost) by smartws01.smartweb.net (8.12.8/8.12.8/Submit) id l93Fx5W4026687; Wed, 3 Oct 2007 11:59:05 -0400 Date: Wed, 3 Oct 2007 11:59:05 -0400 Message-Id: <200710031559.l93Fx5W4026687@smartws01.smartweb.net> To: gothwalk@gmail.com Subject: Wrath of the Lich King BETA From: WotLK Development Team Content-Type: text/html
Be warned!
Posted by Drew Shiel at October 3, 2007 6:12 PM
I really want to check out wrath of the lich king
Posted by: Stephen O'Reilly at January 12, 2008 12:39 AMi realy want to play the new game pls
Posted by: kieran at January 12, 2008 7:29 PMcan i plz get the beta i want to check the Death Knight and dungeons
Posted by: Jonas at January 17, 2008 4:29 PMI'll let my guild know. I'll bet a ton of people fall for it - especially as it gets closer to launch. Wonder how much gold people buy is actually stolen :(
Posted by: Video Games = Road Rage at January 26, 2008 4:18 AMwe i be able to play atest of a death kniht?
Posted by: Galbatron at January 31, 2008 6:18 AMi want to beta
Posted by: phillipwow at March 27, 2008 5:57 PMi would like a beta please
Posted by: at April 30, 2008 11:17 PMI would like to have a chance to beta WOTLK if blizzard needs beta testers.
Posted by: Cameron at May 16, 2008 6:21 PMI know I'm a bit late posting but I love how all the comments are, "PLEASE PLEASE PLEASE LET ME IN THE BETA". These fools are asking to be scammed.
Posted by: Chris at May 24, 2008 8:38 PMi want join wotlk beta before i want see the powerful dath kniht and hope i will see arthas too
Guys, this is not a mail from Blizzard that asks if you would like to reply so you can join the Beta, it shows you there is a scammer around that steals your account, if Blizzard would announce the Wotlk beta testing, it would be shown most likely ingame (at the logging screen at your left, it's where most big announcements are set
Posted by: Eldaïr at May 31, 2008 7:18 PMrofl dont be noob. blizzard NEVER asking about your account name / pass only when u log in, in wow and only in wow-europe.com or worldofwarcraft.com
im tryin to warn people, DONT DOWNLOAD ANY WOTLK-beta 3.1.exe its a FUCKING virus (im not infected thx 4 NOD32 ;> . what they want with these files? scam u, they wanna know ur acc info and hax ur acc, get ur gold, sell your epic items etc etc.
and wtf is these posts: "i want join wotlk beta before i want see the powerful dath kniht and hope i will see arthas too"
roflmao!
If blizzard offers u a chance to a BETA then they wont ask for password, they already got the account info (such as password and e-mail) so they dont need to ask.
Posted by: Anti-Scammer at November 17, 2007 6:54 AM