New email scam spoofed to look like Blizzard

#0 - Sept. 3, 2010, 7:56 a.m.
Blizzard Post
Well, one email got through all it all. There's a new email going around, and it has Blizzard's EXACT email address.

Unfortunately for them, I know how to get the original email headers.

Here's a copy of the email. Thought a GM or higher up might want to see this if it hasn't already been brought to their attention.

--------------------------------------
[email protected] to me

Greetings,

We are excited to announce the World of Warcraft: Cataclysm beta opt-in is now available.

In the beta test you will be given an opportunity to provide your feedback on the overall gameplay experience as well as experience new playable worgen and goblin races, new zones, professions and more. For a full list of features please follow this link: <bad link gets clipped and spanked and sent to timeout>

We will be selecting account holders of Battle.net and World of Warcraft accounts who opted-in at random to participate in the World of Warcraft: Cataclysm Beta Test. To opt-in for the beta test please visit the World of Warcraft: Cataclysm website which can be accessed here.

In order to be eligible for the World of Warcraft: Cataclysm - Beta Opt In you will need to have a valid World of Warcraft subscription in good standing when the beta test is scheduled to commence. Should you be selected to participate in the beta test you will be able to transfer your characters onto our test realm and embark on the epic journey against the dreaded Deathwing!

We look forward to working with you in the World of Warcraft: Cataclsym Beta test.

Regards,

Beta Account Support
Blizzard Entertainment
-------------------------------------

Of course, our friends at Firefox have filtered it and thankfully for those who follow the link will be shown a huge warning saying the website is a forgery. Props.

Original headers are as follows:

------------------------------------------------
Delivered-To: <my email clip clip>
Received: by 10.220.202.75 with SMTP id fd11cs30322vcb;
Wed, 1 Sep 2010 09:01:17 -0700 (PDT)
Received: by 10.213.39.196 with SMTP id h4mr11748837ebe.42.1283356875837;
Wed, 01 Sep 2010 09:01:15 -0700 (PDT)
Return-Path: <[email protected]>
Received: from blu0-omc3-s21.blu0.hotmail.com (blu0-omc3-s21.blu0.hotmail.com [65.55.116.96])
by mx.google.com with ESMTP id w58si25256626eeh.40.2010.09.01.09.01.15;
Wed, 01 Sep 2010 09:01:15 -0700 (PDT)
Received-SPF: pass (google.com: domain of [email protected] designates 65.55.116.96 as permitted sender) client-ip=65.55.116.96;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of [email protected] designates 65.55.116.96 as permitted sender) [email protected]
Received: from BLU0-SMTP201 ([65.55.116.73]) by blu0-omc3-s21.blu0.hotmail.com with Microsoft SMTPSVC(6.0.3790.4675);
Wed, 1 Sep 2010 08:59:41 -0700
X-Originating-IP: [123.185.196.75]
X-Originating-Email: [[email protected]]
Message-ID: <[email protected]>
Return-Path: [email protected]
Received: from idcp ([123.185.196.75]) by BLU0-SMTP201.phx.gbl over TLS secured channel with Microsoft SMTPSVC(6.0.3790.4675);
Wed, 1 Sep 2010 08:59:37 -0700
Reply-To: <[email protected]>
From: "[email protected]" <[email protected]>
To: <my email clip clip>
Subject: Cataclysm Beta Opt-In
Date: Wed, 1 Sep 2010 23:59:31 +0800
---------------------------------------------------------
#3 - Sept. 3, 2010, 8:11 p.m.
Blizzard Post
It's VERY common anymore - I'd say even standard for them to spoof the FROM line.

They also will use a 'real' email and doctor the links to go to fake sites.

ALWAYS pays to check the internal routing headers of any email to verify the sender.