e-Mail from "ArenaNet?" Please read! [merged]
in Account & Technical Support
Posted by: Titan Solidus.6835
in Account & Technical Support
Posted by: Titan Solidus.6835
I just got one of these e-mails myself and to aid the guys/girls at GW i have decoded the header for you.
Header If its form
x-store-info:qAUQJzZ73IJCLUJ+0n7ZQ0tyh3aLbvsRGm3bfjfOypLENkkWLOmrlK9dn1IUgzodabvd9iOvsJffWpHaZRU4k3W0UkvtFNskaTMlmZoSoEIWykQpljCJBRkqjr33k31LaWbT9R+G7pA=
Authentication-Results: hotmail.com; spf=none (sender IP is 220.231.188.82) smtp.mailfrom=gy@WWW-9763E06E580.org; dkim=none header.d=guildwars2.com; x-hmca=none header.id=noreply@guildwars2.com
X-SID-PRA: noreply@guildwars2.com
X-AUTH-Result: NONE
X-SID-Result: NONE
X-Message-Status: n:n
X-Message-Delivery: Vj0xLjE7dXM9MDtsPTA7YT0wO0Q9MztHRD0zO1NDTD02
X-Message-Info: 6YO/4nwP5t3FuUJkWugtSn3ohwZ6tAFHt71xK8xpG2lasF+CTLdRcGgZHFcuKVK6Zpe2npRMWUZAsvgIlUvDzw8+Ok6cJam7yRzljgHaz85b00EJz6+GdrMvJ7A843a9wP4zh+kLqyoSWOxhf0HrehwK7FLCdEaJ/QVocEK/iUM=
Received: from WWW-9763E06E580.org ([220.231.188.82]) by COL0-MC1-F20.Col0.hotmail.com with Microsoft SMTPSVC; Sat, 29 Jun 2013 15:32:06 -0700
Message-ID: <67F637AA18B3587B2D5C14C668951528@WWW-9763E06E580.org>
From: \“ArenaNet\” <noreply@guildwars2.com>
To: <xxxxxxxxx@live.com> (Blanked for a Reason)
Subject: Guild Wars 2 – Account Abuse
Date: Sun, 30 Jun 2013 06:32:09 +0800
MIME-Version: 1.0
Content-Type: text/html; charset=\“utf-8\”
Content-Transfer-Encoding: base64
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook Express 6.00.2900.5512
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.5512
Return-Path: gy@WWW-9763E06E580.org
X-OriginalArrivalTime: 29 Jun 2013 22:32:07.0054 (UTC) FILETIME=[7C9B4AE0:01CE7518]
Decoded Information
The source IP address is 220.231.188.82.
Country China
State/Region 30
City Shenzhen
Latitude 22.5333
Longitude 114.1333
What is scary the whole e-mail is base64 encrypted but lucky i have decrypted it for you. This Paste bin link is safe.
WARNING! Do not copy the link from the pastebin file to your browser and run it. Its a Phishing E-mail designed to steal your information i am only posting this to aid other users of this community.
It also aid the GW Mods/Teams to track down and hopefully get that site blocked.
The phishing scams are getting better and better so we need to be one step in front.
Sorry for sending you a PM, I was merely trying to get something important out, basically merely trying to help. Sorry once again if i am one of the offenders.
Contact support they will be able to help you.
Open a support ticket. They will be able to help you
Remember to 1+ me for correct info
Meithar it sounds like you clicked Remember my network hence it didn’t require you to re-input the auth key code.
I suggest you contact support to remove any saved Network IP’s. I am concerned about this option myself. with the recent raise in GW2 account hijacks this is just one option that personally should be disabled although the chances of a hijacker being in the same IP range as you if they was they will also not need to verify the account.
Hope this helps!
Contact Support Here: http://en.support.guildwars2.com/
Try and fill in all you can. If it will not accept the form in Char just but Not Made Yet or something on them lines with a copy of Purchase.
Hope this helps
Hi all it seems Hotmail has a issue with its system.
To date a couple of my friends Hotmail accounts has been hijacked and their GW accounts stolen.
What seems to be happening is They are hijacking Hotmail accounts then using them to take GW accounts by posing as the account holder.
Of course what makes it worse is Most people have hotmail accounts and still have the Guildwars 2 Serial Number on them.
So there for seems that Microsoft are not really taking the issue seriously in efforts to stop accounts being hijacked is for All Members of Guildwars to simply Upon getting there keys if using hotmail is to simply take a copy of the Key and then removing the E-mail with the Serial attached.
As it seems the hijackers are using the Serial Keys to gain control of the GW2 accounts.
In all my mates accounts the password has been strong and there has been no viruses at all on the PC’s.
So Some Advisory steps if using Hotmail for your Guildwars Accounts.
1) Upon Getting your Key Print the E-mail Out and Then Delete The E-mail (A Must as CD Keys is part of Account Recovery!!!!)
2) Make Sure your Guildwars Account has a completely Different password to your hotmail account. (I see too many people using the same password for Everything, If you have to make a Print Out with All Your Username and Passwords then keep them in a safe place, Never use the same password for more then 1 account system!)
3) Start thinking about using some other E-mail system. Hotmail accounts seemed to be recently the hijackers fav targert using another e-mail system such as Gmail, Yahoo etc might be better (Personally i use Gmail since i have moved here no issues with hacked accounts. I was with Hotmail and fell victim myself with my GW account. No more am i having this issue.)
4) Enable Account Security If you have a Windows / Android / iPhone enable two step security the best form of defence. ( Just remember not to click Remember Network!! Reason: If some one on the same IP Range you, which you had when you did click Saved network verification can gain access to your your account without Verification and there for your account is at risk. I would ask Areanet/Guildwars Team to simply remove this option. Though i makes life easier it also makes it easier for the account stealers!!! with this option enabled. Remove it please!)
5) Change your passwords regularly (This will also help try not to rely on just one security feature. Do the same with any accounts you have its good practice to change passwords often. Doesn’t have to every day you can make it Week, Bi-Weekly, Monthly.)
6) Enjoy your Guildwars 2 Account
Information about 2 Step Verification can be found here along with other information about account security: https://www.guildwars2.com/en/news/mike-obrien-on-account-security/
Last final Point for all. Areanet/Guildwars Team Doesn’t send any e-mails or make calls asking for such information. If you do get any e-mail posing as either do not reply or click any links.
Hope this helps all.
(edited by Titan Solidus.6835)
Not affiliated with ArenaNet or NCSOFT. No support is provided.
All assets, page layout, visual style belong to ArenaNet and are used solely to replicate the original design and preserve the original look and feel.
Contact /u/e-scrape-artist on reddit if you encounter a bug.