On Sun, Apr 24, 2022 at 11:02:42PM -0400, John R Levine via mailop wrote: > I've gotten several copies of this phish sent to an address stolen > from a closed Robinhood brokerage account. It's sent from Sendgrid, > with a link to a web host at AWS that does a couple of web redirects > to a web server at 176.113.115.238 in St Petersburg. The web site > purports to be Metamask, which is a crypto wallet. I suppose people > wth Robinhood accounts would be good targets. > > Anyone else seeing this?
Yes, the Koli-Lõks spamtraps have the same. Not in great quantities, but some trickled in both yesterday and today. > > Copy of the spam here: http://spample.iecc.com/rvj/23695345 > > R's, > John -- Atro Tossavainen, Founder, Partner Koli-Lõks OÜ (reg. no. 12815457, VAT ID EE101811635) Tallinn, Estonia tel. +372-5883-4269, http://www.koliloks.eu/ _______________________________________________ mailop mailing list mailop@mailop.org https://list.mailop.org/listinfo/mailop