Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Battle.net phishers part 2.
- twitter.com/_St0rm
- pastebin.com/u/_St0rm
- So I recieved an email from blizzard.
- tldr: it was fake. My name is not Zhang, the link was broken, and I don't play wow.
- After finding the raw output of the email, which is here: http://pastebin.com/F5RJkPwU
- I found 3 main hostname/ips
- Here are my results:
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Raw output from email
- Received-SPF: pass (google.com: domain of [email protected] designates 121.254.166.47 as permitted sender) client-ip=121.254.166.47;
- Received: from kw1-web-24-blade06.wowadmin.net (kw1-web-24-blade06.wowadmin.net [10.52.55.86])
- Message-ID: <458130787.1329229976062.JavaMail.tomcat@kw1-admin-smtp-vip.wowadmin.net>
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Looking up 121.254.166.47
- IP: 121.254.166.47
- Hostname: ext-smtp11.kr.battle.net
- Timezone: Asia/Seoul
- Country: Korea
- Continent: Asia
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Browser changes
- if you ping kr.battle.net, you get: 121.254.166.38
- If you go directly to 121.254.166.38 in your URL, you get
- "Forbidden"
- If you go to 121.254.166.47 you get:
- "121.254.166.47 took too long to respond."
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Doing a whois of 121.254.166.47
- KRNIC is not an ISP but a National Internet Registry similar to APNIC.
- [ Network Information ]
- IPv4 Address : 121.254.128.0 - 121.254.255.255 (/17)
- Service Name : KIDC
- Organization Name : LG DACOM KIDC
- Organization ID : ORG137200
- Address : KIDC, 261-1, Nonhyun-dong, Kangnam-gu
- Zip Code : 135-010
- Registration Date : 20060602
- [ Admin Contact Information ]
- Name : IP Administrator
- Phone : +82-2-2086-2924
- E-Mail : [email protected]
- [ Tech Contact Information ]
- Name : IP manager
- Phone : +82-2-2086-2924
- E-Mail : [email protected]
- [ Network Abuse Contact Information ]
- Name : Network Abuse
- Phone : +82-2-2086-2878
- E-Mail : [email protected]
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Kidc
- So, 121.254.166.47 is ext-smtp11.kr.battle.net being hosted on kidc.net
- kidc.net is a Korean isp.
- Either possibly hijacked, or it is legitly owned.
- It's the korean battlenet server.
- So no real luck here, trying different ip from raw output.
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Next IP to analyse.
- Received: from kw1-web-24-blade06.wowadmin.net (kw1-web-24-blade06.wowadmin.net [10.52.55.86])
- When you go to wowadmin.net or www.wowadmin.net you get a DNS failure.
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Whois wowadmin.net
- ..So it's owned by godaddy.com. Let's see if battle.net is owned by godaddy.com...
- Yup. It's also owned by godaddy.com
- Registrant:
- Blizzard Entertainment
- P.O. Box 18979
- Irvine, California 92623
- United States
- Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
- Domain Name: WOWADMIN.NET
- Created on: 12-Aug-03
- Expires on: 31-Jan-13
- Last Updated on: 29-Dec-11
- Administrative Contact:
- Entertainment, Blizzard [email protected]
- P.O. Box 18979
- Irvine, California 92623
- United States
- +1.9499551382
- Technical Contact:
- Entertainment, Blizzard [email protected]
- P.O. Box 18979
- Irvine, California 92623
- United States
- +1.9499551382
- Domain servers in listed order:
- NS-WEST.CERF.NET
- NS-EAST.CERF.NET
- Registry Status: clientDeleteProhibited
- Registry Status: clientRenewProhibited
- Registry Status: clientTransferProhibited
- Registry Status: clientUpdateProhibited
- Comparing battle.net and wowadmin.net, battle contains lots more content.
- Possibly thinking wowadmin.net is fake.
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Google can be your friend.
- # Googling Irvine, California 92623
- You get blizzard address.
- Example: http://orangecounty.citysearch.com/profile/572289/irvine_ca/blizzard_entertainment.html
- # Googling wowadmin.net
- BINGO - http://www.lancope.com/images/uploads/blog/6a010536b4f156970c011571f55525970b-700wi-lrg.jpg
- Not just me who's been recieving spam!
- So it seems to me that someone created wowadmin.net, somehow has a list of email address's that could be connected to wow.
- Or could be a potential MMORPG gamer.
- So I guess it's time to find more about wowadmin.net hmm??
- -------------------------------------------------------------------------------------------------------------------------------------------
- # Last raw ip
- Message-ID: <458130787.1329229976062.JavaMail.tomcat@kw1-admin-smtp-vip.wowadmin.net>
- So still on wowadmin.net
- With a hefty ammount of sub domains. Time to start finding more about em.
- -------------------------------------------------------------------------------------------------------------------------------------------
- End of part 2.
- -------------------------------------------------------------------------------------------------------------------------------------------
Advertisement
Add Comment
Please, Sign In to add comment