This isn't a healthy pancake

in LeoFinance2 years ago (edited)

I suspect this email is because somewhere my ETH address is linked to this email. Pretty sure this is phishy.

Be careful out there.

B67B26E7-4805-45C0-9FB2-D01E53945F1E.png

Posted Using LeoFinance Beta

Updating with the full text with all its horrific spelling and grammar:

Early today we detected some unusual access to your wallet from this location : 

Country :    Netherlands (NL)

If this not you who performe this conexion we invit you to : 

- reset your wallet acces by following the steps on the link bellow 

- make full scanne on your device to be sure it's not compromised 

we stay serving you on the background by monitoring any unusual activity, 



Best Regards, 
PancakeSwap Security Team

The headers of the email contain:

Received: from frhb44129flex.ikexpress.com ([178.170.102.152]:63096 helo=FRHB44129FLEX.home)
    by ----------------- with esmtps  (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384
    (Exim 4.94.2)
    (envelope-from <[email protected]>)
    id 1mkTUa-0007ag-Pa
    for ---------------; Tue, 09 Nov 2021 15:57:06 +0000
Sort:  

@belemo you might have opened something like this prior to your hack.

Posted Using LeoFinance Beta

Yeah my dad received a similar email. The pancakeswap team does not email users at all, this is 110% a scam attempt.

If I hadn't been on mobile I'd have copy pasted the ridiculously bad text. Should do that now.

Looks 100% phishy

Posted Using LeoFinance Beta

I recognised the foul stench the moment I saw the subject line....
untitled.gif