OH GOD!!!!!

#0 - Sept. 20, 2010, 2:20 a.m.
Blizzard Post
the spammers have gotten (a little) smarter.

Greetings!

This is an automated notification regarding the recent change(s) made to your World of Warcraft account.

Your Information has recently been attempt modified through the Account Management website.


*** If you made this Information change, please disregard this notification.

However, if you did NOT make changes to your Information, Please log in : worldofwarcraft-christmas
Cancel Changes.
If you are unable to successfully retrieve your password using the automated system, please contact Billing & Account Services at 1-800-59-BLIZZARD (1-800-592-5499) Mon-Fri, 8am-8pm Pacific Time or at .

Account security is solely the responsibility of the accountholder. Please be advised that in the event of a compromised account, Blizzard representatives typically must lock the account. In these cases the Account Administration team will require faxed receipt of ID materials before releasing the account for play.

Regards,

The World of Warcraft Support Team
Kbz2rrmfC77HX

ok thats not the smart part. heres the header and this is the smart part.

X-Apparently-To: via 216.252.111.119; Sun, 19 Sep 2010 16:49:12 -0700
Return-Path: <noreply blizzard >
X-YahooFilteredBulk: 112.111.152.54
Received-SPF: fail (mta1159.mail.mud.yahoo.com: domain of noreply blizzard does not designate 112.111.152.54 as permitted sender)
X-YMailISG: 5Y1l7ngcZApSGeZF4hF1U1Ga9FqbfRuBG58bHDxXl_db0oBO JNjasSyQqeVrhijJzMD_K_xnw80_CXa.suhKmqIojo93eq0Hi8Gdf8iG_7fl bH7nXJsrO02N.zYzu97R9obAp5BCeVWxhh4S0KZL4ReiWXXB7Xx8WCqIav2C WOdBU.7JE2fjVPb9bKrO4wt22pnxY6R6tQ5w7..09ZPkF_UHO3oYi0qkTNe0 SkfTfxIDUIpbII4eWeag96BEwkm2m2iqMxmK4GSp_zgg2teLlfuysP6cvrvy A0.ib31jXeOdodCBGNaVs0dTv6JgIEjQjmU4Fp.EQ500y8lN1HTRGIOZHalQ i9LtBt5rWhfPzDlA7wI5Lz_hIMtmQ6OtXGNGMspo_g87TSIFZWaP4aoTd4CO GK2qgJtnhHNAQrBnKIS9oENTp7j.uWFL9NPq_v_jI0XgYCJQ5ohdfECtRkC5 niStb4thKem8N2u7zu_RhG9p9QuDsPrxVkWf9T6.Tam278EilHyH3AlR5w_D t5eK7Q4kVPy6__ye49Q-
X-Originating-IP: [112.111.152.54]
Authentication-Results: mta1159.mail.mud.yahoo.com from=blizzard.com; domainkeys=neutral (no sig); from=blizzard.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (HELO blizzard.com) (112.111.152.54) by mta1159.mail.mud.yahoo.com with SMTP; Sun, 19 Sep 2010 16:49:11 -0700
Received: from i2k6c36zxi.com (unknown [192.168.1.103]) by i2k6c36zxi.net witch CMailServer 6.6.1 SMTP; Sun, 19 Sep 2010 23:27:49 +0800
Date: Sun, 19 Sep 2010 23:27:49 +0800
From:
=?GB2312?B?QmxpenphcmQgRW50ZXJ0YWlubWVudA==?= <noreply blizzard >
Add sender to Contacts
To:
Reply-To: noreply blizzard
Subject: =?GB2312?B?V29ybGQgb2YgV2FyY3JhZnQgQWNjb3VudCBzdGV2ZW9kZWVkIC0gQWNjb3VudCBDaGFuZ2UgTm90aWNl?=
Message-ID: <1284910069.noreply blizzard >
MIME-Version: 1.0
Content-Type: text/plain; charset="GB2312"
Content-Transfer-Encoding: base64
Content-Length: 1406

as you can see they made it from noreply at blizzard dot com but the english in the "meat" of the message is full of crap and i don't belive it. i checked my account and i can still log in just fine so its bull. just wanted to warn people that the scammers, phishers, hacker, ect have gotten a bit smarter but still dumb as hell.

please don't click on any links in any phishing e-mails just log on to your account on wow and check there or call blizz. also i hope i got all the links and emails out of this, if i didn't let me know and ill fix it or if you want to you can fix it
#6 - Sept. 20, 2010, 6:28 a.m.
Blizzard Post
There is a wealth of information available in an internal email header.

It's pretty standard practice for them to spoof the FROM address in any phish. That's just about as easy as writing a fake return address on an envelope.

While the internal header may be a bit hard to read, looking up the IP is always a dead give-away.

We aren't going to be sending you emails from Longyan, China :)