Super real-looking phishing email.

#0 - Aug. 16, 2010, 2:18 a.m.
Blizzard Post
I got this email

Subject: World of Warcraft Account code protection
From: "Blizzard Entertainment" <[email protected]>
Date: Sat, August 14, 2010 3:10 pm
To: ****@****.com
Priority: Normal

Greetings!
Recently, the problem of account invasion is getting worse and worse which cause
enormous players??equipments and virtual currency stolen. This severely damages the
benefits of mass players, also causes our company lose a lot of customers.
Our company has to adopt some measures to safeguard our common benefits in order to
strengthen the safety of mass players'accounts, and firmly resist the account to be
stolen again.Through our company's research and investigation to most of us
customers, we will make the following decisions: we launch a package of updated code
strengthen system and dynamic code protection card which can effectively prevent the
accounts invaded. We will send this package of code protection system to players
free of charge.
Please open this connection:https://www.battle.net/account/support/login-support.xml
If your account passes the check successfully, we will send this package of dynamic
code protection card to you in the form of e-mail.
In 3 days after you receiving the e-mail, if you don't submit your information, we
have right to freeze your account, every player is obligated to protect the safety
of the account. You must work together with us to be determined to crack down all
the behaviors of destroying games.
If you had already authenticator your account, please disregard this automatic
notification.
Regards,
The World of Warcraft Support Team
Blizzard Entertainment
http://www.blizzard.com/support/wowindex/


This is the full header:

Viewing Full Header - View message
Return-Path: <[email protected]>
Delivered-To: ****@****.com
Received: (qmail 27823 invoked by uid 89); 14 Aug 2010 19:11:02 -0000
Received: from unknown (HELO mx6.hrnoc.net) (216.120.251.187)
by 0 with ESMTPS (DHE-RSA-AES256-SHA encrypted); 14 Aug 2010 19:11:02 -0000
Received-SPF: softfail (0: transitioning SPF record at spf-d.hotmail.com does not designate 216.120.251.187 as permitted sender)
Received: (qmail 7798 invoked by uid 89); 14 Aug 2010 20:41:37 -0000
Received: by simscan 1.2.0 ppid: 7783, pid: 7789, t: 0.5571s
scanners: spam: 3.1.7
X-Spam-Checker-Version: SpamAssassin 3.2.4 (2008-01-01) on spamd3.hrnoc.net
X-Spam-Level: *
X-Spam-Status: No, score=1.5 required=7.0 tests=HTML_MESSAGE,
MSGID_FROM_MTA_HEADER autolearn=disabled version=3.2.4
Received: from blu0-omc2-s18.blu0.hotmail.com (65.55.111.**)
by 0 with SMTP; 14 Aug 2010 20:41:37 -0000
Received-SPF: pass (0: SPF record at spf-a.hotmail.com designates 65.55.111.** as permitted sender)
Received: from BLU0-SMTP11 ([65.55.111.71]) by blu0-omc2-s18.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
Sat, 14 Aug 2010 12:11:02 -0700
X-Originating-IP: [58.19.10.68]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Return-Path: [email protected]
Received: from yeq ([58.19.10.68]) by BLU0-SMTP11.blu0.hotmail.com over TLS secured channel with Microsoft SMTPSVC(6.0.3790.4675);
Sat, 14 Aug 2010 12:11:01 -0700
From: "Blizzard Entertainment" <[email protected]>
To: <****@****.com>
Subject: World of Warcraft Account code protection
Date: Sun, 15 Aug 2010 03:10:49 +0800
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary="----=_NextPart_000_0DBA_01495C2A.19D4DFE0"
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
X-OriginalArrivalTime: 14 Aug 2010 19:11:02.0110 (UTC) FILETIME=[6F996FE0:01CB3BE4]



So many people would fall for this, but I know that Blizz never issues ultimatums like that. What I want to know is, how did they get the email that I use for Blizzard in the first place?
#8 - Aug. 16, 2010, 6:58 a.m.
Blizzard Post
Q u o t e:
"Greetings!
Recently, the problem of account invasion is getting worse and worse which cause
enormous players??equipments and virtual currency stolen.."

Bad grammar is usually a huge tip-off. " Account invasion cause enormous players?"

Also, check the headers.


<.<
>.>

I've always found the enormous players equipments one rather humorous.

I think this author must moonlight writing other spam adds - you know, the ones that start with a V.

/pads back into the bamboo. Yeah! I did go there!