Posted: 10/2/2012 9:29:30 PM EDT
|
Got this email and thought I would pass it off to you guys. Never had an account or even registered for one. Firefox blocked the site for phishing software. Sender uses the following email but masks it: [email protected]
_______________________________________________________________________________________________________________ Greetings! It has come to our attention that you are trying to sell your personal Diablo III account(s). As you may not be aware of, this conflicts with the EULA and Terms of Agreement. If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership. You can confirm that you are the original owner of the account to this secure website with: https://us.battle.net/login/en/?ref=http%3A%2F%2Fus.battle.net%2Fd3%2Fen%2Findex&app=com-d3 <––––- DO NOT GO TO LINK Login to your account, In accordance following template to verify your account. * First and Surname * Secret Question and Answer Show * Please enter the correct information If you ignore this mail your account can and will be closed permanently. Once we verify your account, we will reply to your e-mail informing you that we have dropped the investigation. Regards, Account Administration Team Blizzard Entertainment http://www.blizzard.com/support/ Diablo III , Blizzard Entertainment 2012 |
|
Quoted:
I don't know about all the crap afterward but us.battle.net is from blizzard and seems to be a legit Really? Let's take a look again and see if this doesn't seem right: "If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership. " "If you ignore this mail your account can and will be closed permanently. " Go for it dude.
|
|
Quoted:
Quoted:
I don't know about all the crap afterward but us.battle.net is from blizzard and seems to be a legit Really? Let's take a look again and see if this doesn't seem If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership. " "If you ignore this mail your account can and will be closed permanently. " Go for it dude. ![]() yeah the email seems like BS and I did not go to your link all I know is us.battle.net is a blizzard sight |
|
Quoted:
Quoted:
Quoted:
I don't know about all the crap afterward but us.battle.net is from blizzard and seems to be a legit Really? Let's take a look again and see if this doesn't seem If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership. " "If you ignore this mail your account can and will be closed permanently. " Go for it dude. ![]() yeah the email seems like BS and I did not go to your link all I know is us.battle.net is a blizzard sight Ever heard of godaddy.com, tiny URL and those other sites? I can name a URL whatever I want. |
|
yeah if i actually go through the blizzard sight to log in I get a url like this
https://us.battle.net/login/en/?ref=https%3A%2F%2Fus.battle.net%2Faccount%2Fmanagement%2Fd3%2Fdashboard-gateway.html&app=bam&cr=true not too far off but different for sure. I would guess it's set up to look the same and capture your log in info. |
|
Quoted:
Quoted:
Quoted:
Quoted:
I don't know about all the crap afterward but us.battle.net is from blizzard and seems to be a legit Really? Let's take a look again and see if this doesn't seem If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership. " "If you ignore this mail your account can and will be closed permanently. " Go for it dude. ![]() yeah the email seems like BS and I did not go to your link all I know is us.battle.net is a blizzard sight Ever heard of godaddy.com, tiny URL and those other sites? I can name a URL whatever I want. No, you can't. You can't register a URL that conflicts with one that already exists –– i.e. if us.battle.net is registered, you cannot register us.battle.net, no other registrar will allow that to happen. What you can do is make an HTML email appear to link to that URL, but instead link to another URL, using a variety of relatively simple (or even somewhat complex) techniques. Which is why html email is the devil and should never be used. |
|
Quoted:
Quoted:
I don't know about all the crap afterward but us.battle.net is from blizzard and seems to be a legit Really? Let's take a look again and see if this doesn't seem If this proves to be true, your account can and will be disabled. It will be ongoing for further investigation by Blizzard Entertainment's employees. If you wish to not get your account suspended you should immediately verify your account ownership. " "If you ignore this mail your account can and will be closed permanently. " Go for it dude. ![]() The link you posted is legitimate. If I had a D3 account it'd login. That said, on your email it could be a mask for when YOU click it, it takes you to a phish site. You could post the email source code here. But we all know the whole email isn't legitimate so there wouldn't be much of a point. |
|
I used to have a WoW account that got hacked long ago and has since been disbanded. Ever since now about every 2-3 days I get a WoW or Diablo 3 warning that I am selling my account and being investigated blah blah blah and that I should go to this link.
The display link above is actually correct https://us.battle.net is the valid website for their site. HOWEVER the embedded link is not, it is not shown above but if you hover over the link in your email and look in the bottom left of your browser window you will see the address it is trying to take you too which will be different. The fun shit is I am now also getting American Express fraud phishing emails too |