Guild Wars Forums - GW Guru
 
 

Go Back   Guild Wars Forums - GW Guru > The Outer Circle > Off-Topic & the Absurd

Notices

Reply
 
Thread Tools Display Modes
Old Jan 04, 2010, 03:45 AM // 03:45   #1
Ascalonian Squire
 
Join Date: Feb 2008
Advertisement

Disable Ads
Default Account Hacked spam emails

With all the hacker problems recently, I wanted to share a spam email I've received. Keep your eye out for it. I did forward to Anet as well. No response from them yet.

The spam arrived from an email address that was definitely not Anet (sina.com). Also, I do not have an Aion account. And the web link they sent to check my login was not correct.


**********The Email Below***************
Password Reset Success‏
From: NCsoft Support ([email protected])
Sent: Sun 1/03/10 5:31 AM
To: (my email address)

Someone at 210.259.232.57 has reset your Aion Game Account password for account . If you did not make this change, please contact support immediately.

Last edited by Neo Nugget; Jan 04, 2010 at 05:44 AM // 05:44.. Reason: Delinkified.
furpigs is offline   Reply With Quote
Old Jan 04, 2010, 04:04 AM // 04:04   #2
Desert Nomad
 
shoyon456's Avatar
 
Join Date: Jul 2006
Profession: D/
Default

I've been getting the same spam emails about my WoW account (hint, I do not have a WoW account now or ever).

It's just fishing for someone to hit their fake link and put in their account info. Notice how the url is "ncsofts" not "ncsoft." You're just one of many that's getting them. All they need are a few people who have accounts to click on the link and put in their info to make sure their account is ok, then its gone.

I've forwarded them to Blizzard, but I get so many now, its just easier to delete them all.
shoyon456 is offline   Reply With Quote
Old Jan 04, 2010, 04:05 AM // 04:05   #3
Krytan Explorer
 
Ninja Ninja's Avatar
 
Join Date: Dec 2006
Profession: W/
Default

If this really is a hacker email you really shouldn't post a link to the website.
Ninja Ninja is offline   Reply With Quote
Old Jan 04, 2010, 04:31 AM // 04:31   #4
Lion's Arch Merchant
 
Saph's Avatar
 
Join Date: Feb 2009
Profession: R/
Default

Good thing you pointed out the extra s on ncsoft. Someone might panic if they receive an email saying their account info has been changed, and overlook that small detail.
Saph is offline   Reply With Quote
Old Jan 04, 2010, 05:36 AM // 05:36   #5
Older Than God (1)
 
Martin Alvito's Avatar
 
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
Default

Nasty.

I agree that you should take the URL code out, or at least break it so it doesn't work.
Martin Alvito is offline   Reply With Quote
Old Jan 04, 2010, 05:56 AM // 05:56   #6
Grotto Attendant
 
Arduin's Avatar
 
Join Date: May 2005
Location: The Netherlands
Guild: Limburgse Jagers [LJ]
Profession: R/
Default

Quote:
Originally Posted by furpigs View Post
**********The Email Below***************
Password Reset Success‏
From: NCsoft Support ([email protected])
Sent: Sun 1/03/10 5:31 AM
To: (my email address)

Someone at 210.259.232.57 has reset your Aion Game Account password for account xxxxxx. If you did not make this change, please contact support immediately.
Did you just post your accountname?
Arduin is offline   Reply With Quote
Old Jan 04, 2010, 06:11 AM // 06:11   #7
Forge Runner
 
Join Date: Jan 2007
Default

Quote:
Originally Posted by Arduin View Post
Did you just post your accountname?
I think he said he doesn't even own an Aion account. These hackers are getting desperate now just shooting out random emails to random people hoping to get a bite.

LOL..I also just noticed the IP is totally fake. 259 is an impossible range. its 0-255, (preferably 0-254).

Last edited by Bob Slydell; Jan 04, 2010 at 06:16 AM // 06:16..
Bob Slydell is offline   Reply With Quote
Old Jan 04, 2010, 06:54 AM // 06:54   #8
Grotto Attendant
 
zwei2stein's Avatar
 
Join Date: Jun 2006
Location: Europe
Guild: The German Order [GER]
Profession: N/
Default

Did you use email address that this was sent to for something aion or gw related? Fansite, etc.
zwei2stein is offline   Reply With Quote
Old Jan 04, 2010, 07:41 AM // 07:41   #9
Furnace Stoker
 
pumpkin pie's Avatar
 
Join Date: Jul 2006
Location: behind you
Guild: bumble bee
Profession: E/
Default

210.259.232.57

on one IP lookup, says the ip address is invalid

another one says the ip is from SOFTBANK TELECOM CORP, Yokohama, Japan,
pumpkin pie is offline   Reply With Quote
Old Jan 04, 2010, 10:33 AM // 10:33   #10
Guest
 
Join Date: Jan 2007
Default

I expect a lot more people will be getting hit this way. In their hack panic, they will give away their account(s) info.
gone is offline   Reply With Quote
Old Jan 04, 2010, 12:13 PM // 12:13   #11
So Serious...
 
Fril Estelin's Avatar
 
Join Date: Jan 2007
Location: London
Guild: Nerfs Are [WHAK]
Profession: E/
Default

Quote:
Originally Posted by flubber View Post
I expect a lot more people will be getting hit this way. In their hack panic, they will give away their account(s) info.
In particular if they've been reading the security threads on Guru. Everyone must be feeling like everyone else is a potential hacker by now ;P.

EDIT: Security-induced brain explosion: what if the OP is a hacker attempting to cause more trouble by pointing to a fake phishing attempt?

Last edited by Fril Estelin; Jan 04, 2010 at 12:16 PM // 12:16..
Fril Estelin is offline   Reply With Quote
Old Jan 04, 2010, 12:20 PM // 12:20   #12
Desert Nomad
 
Join Date: Apr 2007
Default

General advice:

Use a text-only email client, do not enable html or any kind of executable.

Don't click links in emails, forum posts etc. Ever. Use your own favourites/bookmarks, to make sure you land on genuine sites - or carefully type the URL's yourself (beware of fake sites created using common mispellings of URLs).

If you MUST click on links...

...Use Firefox with Noscript, Adblock, Flashblock (or an equivelent browser setup), to help prevent infection by malware

...Do not enable script, or flash for ANY site unless you absolutely HAVE to, and even then - only after you are sure the site is genuine and trustworthy.

...Make sure you are running respectable anti-malware (firewall, antivirus, antispyware, antirootkit)

...Double-check the spelling of URL's - especially if the site is asking for any information.

Does that sound inconvenient or complicated? It really isn't. Make it a habit, and it's like driving a car - you won't even notice you're doing it.
Riot Narita is offline   Reply With Quote
Old Jan 04, 2010, 12:23 PM // 12:23   #13
Krytan Explorer
 
Join Date: Aug 2007
Location: The Netherlands
Profession: W/
Default

Use an email filter and get rid of the garbage before it ever hits your pc.
isildorbiafra is offline   Reply With Quote
Old Jan 04, 2010, 03:32 PM // 15:32   #14
Desert Nomad
 
Big_Iron's Avatar
 
Join Date: Dec 2005
Location: The Edge
Guild: Tormented Weapons [emo]
Default

Quote:
Originally Posted by pumpkin pie View Post
210.259.232.57

on one IP lookup, says the ip address is invalid

another one says the ip is from SOFTBANK TELECOM CORP, Yokohama, Japan,
One quick glance will tell an IT guy this isn't a valid IP address. The second octet is invalid. It's outside of any IP range.
Big_Iron is offline   Reply With Quote
Old Jan 04, 2010, 04:34 PM // 16:34   #15
Ascalonian Squire
 
Join Date: Feb 2008
Default

Sorry, I realize that I should not have posted the bad link. I was trying to help.

I do not own an Aion account and the account name in the email was not any account that I have for anything.

The email address they sent it to was at one time associated to an NCSoft master account, but no longer. The email address was not the login to the gw's account.
furpigs is offline   Reply With Quote
Old Jan 07, 2010, 05:21 PM // 17:21   #16
Guest
 
Join Date: Jan 2007
Default

Quote:
Originally Posted by Fril Estelin View Post
In particular if they've been reading the security threads on Guru. Everyone must be feeling like everyone else is a potential hacker by now ;P.
Well, if they have any sort of sense, NO. Logging into/out of a site and obtaining a random's account info, isn't hacking. It is site failure. no matter what the thundercat team thinks.

Quote:
Originally Posted by Fril Estelin View Post
EDIT: Security-induced brain explosion: what if the OP is a hacker attempting to cause more trouble by pointing to a fake phishing attempt?
I don't think anyone would waste the time, unless trolling.
gone is offline   Reply With Quote
Old Jan 07, 2010, 05:41 PM // 17:41   #17
Grotto Attendant
 
upier's Avatar
 
Join Date: Mar 2006
Location: Done.
Guild: [JUNK]
Default

A mail I received today:
Quote:
Subject: Aion Account Check
When you receive this message at the same time means that you have a routine account of our recent examination, was checking your account we have the evidence to prove that involved in the controversial game currency transaction so we had to take the necessary measures.
Please visit our web site XXXXXXXX as soon as possible to activate your account or we will suspend your account.

The NCsoft Team
(Removed the link and replaced it with XXXXXXXX.)


Forwarded it to support - got this back:
Quote:
Greetings,

Thank you for writing in this report. This is a scam email used to steal account information. Please do not follow any links that are listed in that email. If you have anymore in-game questions or concerns please let me know. Thank you.

Regards,
GM Redcommander


I know one of more person that got it today also. Neither of us has an AION account.

Last edited by upier; Jan 07, 2010 at 05:51 PM // 17:51.. Reason: More info.
upier is offline   Reply With Quote
Old Jan 07, 2010, 05:46 PM // 17:46   #18
Older Than God (1)
 
Martin Alvito's Avatar
 
Join Date: Aug 2006
Guild: Clan Dethryche [dth]
Default

I also got the e-mail that upier received. I don't play Aion either, and the odd thing about it was that it was sent to a forwarding e-mail address I almost never give to anyone.

Pretty poor phish attempt if you ask me. At least the Nigerian prince had a reason for his English being so poor.
Martin Alvito is offline   Reply With Quote
Old Jan 07, 2010, 05:48 PM // 17:48   #19
Forge Runner
 
BenjZee's Avatar
 
Join Date: Dec 2006
Guild: The Overacheivers [Club]
Profession: Mo/
Default

Have you got your email address linked on any fansites or commonly used usernaes? Also lol at that IP address
BenjZee is offline   Reply With Quote
Old Jan 07, 2010, 06:15 PM // 18:15   #20
Ascalonian Squire
 
Join Date: Jul 2009
Location: Somewhere in Ascalon
Profession: Me/E
Default

These must be just mass emails going out. Because I received a WoW one on an email account that has never been registered anywhere on any site.
Miscreant_Moon is offline   Reply With Quote
Reply

Share This Forum!  
 
 
           

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump


All times are GMT. The time now is 09:22 PM // 21:22.


Powered by: vBulletin
Copyright ©2000 - 2016, Jelsoft Enterprises Ltd.
jQuery(document).ready(checkAds()); function checkAds(){if (document.getElementById('adsense')!=undefined){document.write("_gaq.push(['_trackEvent', 'Adblock', 'Unblocked', 'false',,true]);");}else{document.write("