A phishing scam that spoofs Poste Italiane transmitted spam email via IP 151.22.57.58 and relayed it via tanintechnology.net; IP 151.22.57.58 may be blacklisted. The email generates a fraudulent HTLM form that collects passwords and financial data. It uses a POST service that is provided by
hXXp://www.emo-ett.si/done.php
which logs the stolen passwords before redirecting to the legitimate Poste Italiane site.
Acknowledgment: SpamCop posted a specimen of the spam email. For updated status and details, see the report at
http://www.phishtank.com/phish_detail.php?phish_id=1346220