_St0rm

Battle.net phishers part 2

Feb 15th, 2012
624
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 5.69 KB | None | 0 0
  1. Battle.net phishers part 2.
  2.  
  3. twitter.com/_St0rm
  4. pastebin.com/u/_St0rm
  5.  
  6. So I recieved an email from blizzard.
  7.  
  8. tldr: it was fake. My name is not Zhang, the link was broken, and I don't play wow.
  9.  
  10. After finding the raw output of the email, which is here: http://pastebin.com/F5RJkPwU
  11.  
  12. I found 3 main hostname/ips
  13. Here are my results:
  14. -------------------------------------------------------------------------------------------------------------------------------------------
  15. # Raw output from email
  16.  
  17. Received-SPF: pass (google.com: domain of [email protected] designates 121.254.166.47 as permitted sender) client-ip=121.254.166.47;
  18.  
  19. Received: from kw1-web-24-blade06.wowadmin.net (kw1-web-24-blade06.wowadmin.net [10.52.55.86])
  20.  
  21. Message-ID: <458130787.1329229976062.JavaMail.tomcat@kw1-admin-smtp-vip.wowadmin.net>
  22. -------------------------------------------------------------------------------------------------------------------------------------------
  23. # Looking up 121.254.166.47
  24.  
  25. IP: 121.254.166.47
  26. Hostname: ext-smtp11.kr.battle.net
  27. Timezone: Asia/Seoul
  28. Country: Korea
  29. Continent: Asia
  30. -------------------------------------------------------------------------------------------------------------------------------------------
  31. # Browser changes
  32.  
  33. if you ping kr.battle.net, you get: 121.254.166.38
  34. If you go directly to 121.254.166.38 in your URL, you get
  35. "Forbidden"
  36.  
  37. If you go to 121.254.166.47 you get:
  38. "121.254.166.47 took too long to respond."
  39.  
  40. -------------------------------------------------------------------------------------------------------------------------------------------
  41. # Doing a whois of 121.254.166.47
  42.  
  43.  
  44. KRNIC is not an ISP but a National Internet Registry similar to APNIC.
  45.  
  46. [ Network Information ]
  47. IPv4 Address : 121.254.128.0 - 121.254.255.255 (/17)
  48. Service Name : KIDC
  49. Organization Name : LG DACOM KIDC
  50. Organization ID : ORG137200
  51. Address : KIDC, 261-1, Nonhyun-dong, Kangnam-gu
  52. Zip Code : 135-010
  53. Registration Date : 20060602
  54.  
  55. [ Admin Contact Information ]
  56. Name : IP Administrator
  57. Phone : +82-2-2086-2924
  58.  
  59. [ Tech Contact Information ]
  60. Name : IP manager
  61. Phone : +82-2-2086-2924
  62.  
  63. [ Network Abuse Contact Information ]
  64. Name : Network Abuse
  65. Phone : +82-2-2086-2878
  66.  
  67. -------------------------------------------------------------------------------------------------------------------------------------------
  68. # Kidc
  69.  
  70. So, 121.254.166.47 is ext-smtp11.kr.battle.net being hosted on kidc.net
  71. kidc.net is a Korean isp.
  72.  
  73. Either possibly hijacked, or it is legitly owned.
  74. It's the korean battlenet server.
  75.  
  76. So no real luck here, trying different ip from raw output.
  77. -------------------------------------------------------------------------------------------------------------------------------------------
  78. # Next IP to analyse.
  79.  
  80. Received: from kw1-web-24-blade06.wowadmin.net (kw1-web-24-blade06.wowadmin.net [10.52.55.86])
  81.  
  82. When you go to wowadmin.net or www.wowadmin.net you get a DNS failure.
  83. -------------------------------------------------------------------------------------------------------------------------------------------
  84. # Whois wowadmin.net
  85.  
  86.  
  87. ..So it's owned by godaddy.com. Let's see if battle.net is owned by godaddy.com...
  88. Yup. It's also owned by godaddy.com
  89.  
  90.  
  91. Registrant:
  92. Blizzard Entertainment
  93. P.O. Box 18979
  94. Irvine, California 92623
  95. United States
  96.  
  97. Registered through: GoDaddy.com, LLC (http://www.godaddy.com)
  98. Domain Name: WOWADMIN.NET
  99. Created on: 12-Aug-03
  100. Expires on: 31-Jan-13
  101. Last Updated on: 29-Dec-11
  102.  
  103. Administrative Contact:
  104. Entertainment, Blizzard [email protected]
  105. P.O. Box 18979
  106. Irvine, California 92623
  107. United States
  108. +1.9499551382
  109.  
  110. Technical Contact:
  111. Entertainment, Blizzard [email protected]
  112. P.O. Box 18979
  113. Irvine, California 92623
  114. United States
  115. +1.9499551382
  116.  
  117. Domain servers in listed order:
  118. NS-WEST.CERF.NET
  119. NS-EAST.CERF.NET
  120.  
  121.  
  122. Registry Status: clientDeleteProhibited
  123. Registry Status: clientRenewProhibited
  124. Registry Status: clientTransferProhibited
  125. Registry Status: clientUpdateProhibited
  126.  
  127. Comparing battle.net and wowadmin.net, battle contains lots more content.
  128. Possibly thinking wowadmin.net is fake.
  129. -------------------------------------------------------------------------------------------------------------------------------------------
  130. # Google can be your friend.
  131.  
  132. # Googling Irvine, California 92623
  133.  
  134. You get blizzard address.
  135.  
  136. Example: http://orangecounty.citysearch.com/profile/572289/irvine_ca/blizzard_entertainment.html
  137.  
  138. # Googling wowadmin.net
  139.  
  140. BINGO - http://www.lancope.com/images/uploads/blog/6a010536b4f156970c011571f55525970b-700wi-lrg.jpg
  141.  
  142. Not just me who's been recieving spam!
  143.  
  144. So it seems to me that someone created wowadmin.net, somehow has a list of email address's that could be connected to wow.
  145. Or could be a potential MMORPG gamer.
  146.  
  147. So I guess it's time to find more about wowadmin.net hmm??
  148. -------------------------------------------------------------------------------------------------------------------------------------------
  149. # Last raw ip
  150.  
  151. Message-ID: <458130787.1329229976062.JavaMail.tomcat@kw1-admin-smtp-vip.wowadmin.net>
  152.  
  153. So still on wowadmin.net
  154. With a hefty ammount of sub domains. Time to start finding more about em.
  155. -------------------------------------------------------------------------------------------------------------------------------------------
  156. End of part 2.
  157. -------------------------------------------------------------------------------------------------------------------------------------------
Advertisement
Add Comment
Please, Sign In to add comment