Canadian Pharmacy Spam – cheaprxpharmonline.com

Buying Precription Drugs Online May Be Dangerous
– Consumer Alert –
Drug Enforcement Administration Says

warning1

National Association of Boards of Pharmacy (NABP)

Warning

“The Canadian Pharmacy, Canadian/European Pharmacy”, “Canadian Healthcare” and “US Drugstore” are brands of one of the most disgusting illegal online pharmacy group well organized CRIMINAL OPERATION of all times. “GREED” is the driving force behind this operation. Don’t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don’t care that you will endanger your health by taking those dangerous counterfeit drugs.

Behind The Online Pharma

Today a shadowy, transnational network of illicit drug manufacturers, traders, doctors, Web site operators, spammers and criminals makes up the online pharma world.

cheaprxpharmonline

Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
122.56.218.44 New Zealand (Auckland)* Whois Google DNSStuff Urgentmessage.org
207.115.20.183 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

From Harold Messer Wed Jul 29 18:44:25 2009
Return-Path:
Authentication-Results: mta153.sbc.mail.mud.yahoo.com from=sm.luth.se; domainkeys=neutral (no sig); from=sm.luth.se; dkim=neutral (no sig)
Received: from 122.56.218.44 (EHLO flpi181.prodigy.net) (207.115.20.183)
by mta153.sbc.mail.mud.yahoo.com with SMTP; Wed, 29 Jul 2009 18:44:40 -0700
Received: from 7n8k622 (122-56-218-44.mobile.telecom.co.nz [122.56.218.44] (may be forged))
by flpi181.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n6U1hWEk003354;
Wed, 29 Jul 2009 18:44:37 -0700
Message-ID: <000701ca10b7$44cbffc0$627e0202@sm.luth.se>
Reply-To: “Harold Messer” <haroldmesser_zw@sm.luth.se
From: “Harold Messer” <haroldmesser_zw@sm.luth.se
To: , ,
Subject: Need some help focusing?.. get Ritalin!
Date: Wed, 29 Jul 2009 18:44:25 -0700
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
Content-Length: 219

VicodinES, XanaxAmbien, Codeine, Phentermin and many more!
No Doctor or Prescription Needed! Brand & Generic Names Available!
Fast Trackable USPS Shipping!
Browse Our Site Today –> http://cheaprxpharmonline.com

SmartFilter Category: Not Categorized
Make Category Suggestions
IP: 60.12.166.154
Nameservers: ns1.cheaprxpharmonline.comns2.cheaprxpharmonline.comns3.cheaprxpharmonline.com

ns4.cheaprxpharmonline.com

nameservers missing in zone
hot1gaming.com X X
ns1.bd4ns.com X X
ns1.cheaprxpharmonline.com
X X
ns2.cheaprxpharmonline.com
X X
ns2.ef2ns.com X X
ns3.br4ns.com X X
ns3.cheaprxpharmonline.com
X X
ns4.cheaprxpharmonline.com
X X
sdavaiteres.com
hostnames sharing ip with a-records
*.sdavaiteres.com
hot1gaming.com


ns1.listendns.com


ns1.sdavaiteres.com


ns2.sdavaiteres.com


ns3.fa6ns.com


ns3.sdavaiteres.com


ns4.sdavaiteres.com


sdavaiteres.com


www.softokors.com

Address lookup

canonical name cheaprxpharmonline.com.
aliases
addresses 60.12.166.154

Domain Whois record

Queried whois.internic.net with “dom cheaprxpharmonline.com“…

   Domain Name: CHEAPRXPHARMONLINE.COM
   Registrar: XIAMEN ENAME NETWORK TECHNOLOGY CORPORATION LIMITED DBA 
ENAME CORP
   Whois Server: whois.ename.com
   Referral URL: http://www.ename.com
   Name Server: NS1.BD4NS.COM
   Name Server: NS2.EF2NS.COM
   Name Server: NS3.BR4NS.COM
   Status: clientDeleteProhibited
   Status: clientTransferProhibited
   Updated Date: 28-jul-2009
   Creation Date: 03-apr-2009
   Expiration Date: 03-apr-2010

 Last update of whois database: Thu, 30 Jul 2009 15:12:12 UTC <<<

Queried whois.ename.com with “cheaprxpharmonline.com“…

Domain Name : cheaprxpharmonline.com

Registrant Contact Information :
XINGYUNRI
XINGYUNRI
baobao7802@hotmail.com
TONGLUOWAN15, 026974
tel: +86 086482179624
fax: +86 086482179624 

Administrative Contact Information :
XINGYUNRI
XINGYUNRI
baobao7802@hotmail.com
TONGLUOWAN15, 026974
tel: +86 086482179624
fax: +86 086482179624 

Technical Contact Information :
XINGYUNRI
XINGYUNRI
baobao7802@hotmail.com
TONGLUOWAN15, 026974
tel: +86 086482179624
fax: +86 086482179624 

Billing Contact Information :
XINGYUNRI
XINGYUNRI
baobao7802@hotmail.com
TONGLUOWAN15, 026974
tel: +86 086482179624
fax: +86 086482179624 

Status :
clientDeleteProhibited
clientTransferProhibited

Domain Name Server :
ns1.bd4ns.com
ns2.ef2ns.com
ns3.br4ns.com

Registration Date :2009-4-3
Expiration Date : 2010-4-3

For more information, please go to http://whois.ename.com.

Network Whois record

Queried whois.apnic.net with “60.12.166.154“…

inetnum:      60.12.0.0 - 60.12.255.255
netname:      UNICOM-ZJ
descr:        China Unicom Zhejiang province network
descr:        China Unicom
country:      CN
admin-c:      CH1302-AP
tech-c:       JQ16-AP
remarks:      service provider
mnt-by:       APNIC-HM
mnt-lower:    MAINT-CNCGROUP-ZJ
mnt-routes:   MAINT-CNCGROUP-RR
status:       ALLOCATED PORTABLE
remarks:      -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks:      This object can only be updated by APNIC hostmasters.
remarks:      To update this object, please contact APNIC
remarks:      hostmasters and include your organisation's account
remarks:      name in the subject line.
remarks:      -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed:      hm-changed@apnic.net 20040629
changed:      hm-changed@apnic.net 20060124
changed:      hm-changed@apnic.net 20090507
changed:      hm-changed@apnic.net 20090508
source:       APNIC

route:        60.12.0.0/16
descr:        CNC Group CHINA169 Zhejiang Province Network
country:      CN
origin:       AS4837
mnt-by:       MAINT-CNCGROUP-RR
changed:      abuse@cnc-noc.net 20060118
source:       APNIC

person:       ChinaUnicom Hostmaster
nic-hdl:      CH1302-AP
e-mail:       abuse@chinaunicom.cn
address:      No.21,Jin-Rong Street
address:      Beijing,100140
address:      P.R.China
phone:        +86-10-66259940
fax-no:       +86-10-66259764
country:      CN
changed:      abuse@chinaunicom.cn 20090408
mnt-by:       MAINT-CNCGROUP
source:       APNIC

person:       Jianhuaq Qian
nic-hdl:      JQ16-AP
e-mail:       chenrenhai@china-netcom.com
address:      No 1,Hangzhou University Road,Hangzhou, Zhejiang,China
phone:        +86-571-28868063
fax-no:       +86-571-28868069
country:      CN
changed:      wuhong@china-netcom.com 20050421
mnt-by:       MAINT-CNCGROUP-ZJ
source:       APNIC

DNS records

DNS query for 154.166.12.60.in-addr.arpa returned an error from the server: NameError

name class type data time to live
cheaprxpharmonline.com IN SOA
server: ns1.domain.com
email: admin.domain.com
serial: 1
refresh: 300
retry: 300
expire: 300
minimum ttl: 86400
86400s (1.00:00:00)
cheaprxpharmonline.com IN NS ns3.cheaprxpharmonline.com 86400s (1.00:00:00)
cheaprxpharmonline.com IN NS ns2.cheaprxpharmonline.com 86400s (1.00:00:00)
cheaprxpharmonline.com IN NS ns1.cheaprxpharmonline.com 86400s (1.00:00:00)
cheaprxpharmonline.com IN A 60.12.166.154 86400s (1.00:00:00)
cheaprxpharmonline.com IN NS ns4.cheaprxpharmonline.com 86400s (1.00:00:00)

Service scan

FTP – 21 Error: ConnectionRefused
SMTP – 25 Error: ConnectionRefused
HTTP – 80
POP3 – 110 Error: ConnectionRefused
IMAP – 143 Error: ConnectionRefused

— end —

Advertisement

One thought on “Canadian Pharmacy Spam – cheaprxpharmonline.com

  1. Jeff says:

    Domain of “www.onlinepharmaciescanada .com”, much different than the main DNS info of the main site, RBN changes the domain and entire setup of the lookup,

    DNS servers
    ns15.dnsmadeeasy.com
    ns14.dnsmadeeasy.com
    ns10.dnsmadeeasy.com
    ns12.dnsmadeeasy.com
    ns13.dnsmadeeasy.com
    ns11.dnsmadeeasy.com

    Answer records
    onlinepharmaciescanada.com TXT v=spf1 mx a:smtp.tnorth.ca a:smtp2.tnorth.ca a:smtp1.tnorth.ca ip4:209.216.229.0/25 ip4:67.207.220.0/24 ip4:206.71.184.232/29 -all 1800s
    onlinepharmaciescanada.com NS ns14.dnsmadeeasy.com 86400s
    onlinepharmaciescanada.com NS ns11.dnsmadeeasy.com 86400s
    onlinepharmaciescanada.com NS ns12.dnsmadeeasy.com 86400s
    onlinepharmaciescanada.com NS ns13.dnsmadeeasy.com 86400s
    onlinepharmaciescanada.com NS ns15.dnsmadeeasy.com 86400s
    onlinepharmaciescanada.com NS ns10.dnsmadeeasy.com 86400s
    onlinepharmaciescanada.com A 66.199.160.199 172800s
    onlinepharmaciescanada.com MX preference: 20
    exchange: mx2.tnorth.ca
    172800s
    onlinepharmaciescanada.com MX preference: 30
    exchange: mx3.tnorth.ca
    172800s
    onlinepharmaciescanada.com MX preference: 10
    exchange: mx1.tnorth.ca
    172800s
    onlinepharmaciescanada.com SOA server: ns10.dnsmadeeasy.com
    email: dns@dnsmadeeasy.com
    serial: 2009010110
    refresh: 43200
    retry: 3600
    expire: 1209600
    minimum ttl: 180

    Domain Name: ONLINEPHARMACIESCANADA.COM
    Registrar: URL SOLUTIONS INC.
    Whois Server: whois.pananames.com
    Referral URL: http://www.panamanames.com
    Name Server: NS10.DNSMADEEASY.COM
    Name Server: NS11.DNSMADEEASY.COM
    Name Server: NS12.DNSMADEEASY.COM
    Name Server: NS13.DNSMADEEASY.COM
    Name Server: NS14.DNSMADEEASY.COM
    Name Server: NS15.DNSMADEEASY.COM
    Status: clientTransferProhibited
    Updated Date: 02-nov-2010
    Creation Date: 01-jul-2002
    Expiration Date: 01-jul-2020

    Domain Name: ONLINEPHARMACIESCANADA.COM

    Registrant:
    PrivacyProtect.org
    Domain Admin (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note – All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

    Creation Date: 01-Jul-2002
    Expiration Date: 01-Jul-2020

    Domain servers in listed order:
    ns10.dnsmadeeasy.com
    ns11.dnsmadeeasy.com
    ns12.dnsmadeeasy.com
    ns13.dnsmadeeasy.com
    ns14.dnsmadeeasy.com
    ns15.dnsmadeeasy.com

    Administrative Contact:
    PrivacyProtect.org
    Domain Admin (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note – All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

    Technical Contact:
    PrivacyProtect.org
    Domain Admin (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note – All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

    Billing Contact:
    PrivacyProtect.org
    Domain Admin (contact@privacyprotect.org)
    ID#10760, PO Box 16
    Note – All Postal Mails Rejected, visit Privacyprotect.org
    Nobby Beach
    null,QLD 4218
    AU
    Tel. +45.36946676

    Status:LOCKED

    And last,

    NetRange: 66.199.160.192 – 66.199.160.255
    CIDR: 66.199.160.192/26
    OriginAS:
    NetName: PEER1-TRUENORTH-01
    NetHandle: NET-66-199-160-192-1
    Parent: NET-66-199-128-0-1
    NetType: Reassigned
    RegDate: 2009-10-29
    Updated: 2009-10-29
    Ref: http://whois.arin.net/rest/net/NET-66-199-160-192-1

    CustName: True North Management Inc.
    Address: #2001 – 7495 132nd Street
    City: Surrey
    StateProv: BC
    PostalCode: V3W-1J8
    Country: CA
    RegDate: 2009-10-29
    Updated: 2011-03-19
    Ref: http://whois.arin.net/rest/customer/C02348859

    OrgAbuseHandle: NSA-ARIN
    OrgAbuseName: Peer 1 Network AUP Enforcement
    OrgAbusePhone: +1-604-484-2588
    OrgAbuseEmail: abuse@peer1.net
    OrgAbuseRef: http://whois.arin.net/rest/poc/NSA-ARIN

    OrgTechHandle: ZP55-ARIN
    OrgTechName: PEER 1 Network Inc
    OrgTechPhone: +1-604-683-7747
    OrgTechEmail: net-admin@peer1.net
    OrgTechRef: http://whois.arin.net/rest/poc/ZP55-ARIN

    RTechHandle: ZP55-ARIN
    RTechName: PEER 1 Network Inc
    RTechPhone: +1-604-683-7747
    RTechEmail: net-admin@peer1.net
    RTechRef: http://whois.arin.net/rest/poc/ZP55-ARIN

    And as with my last comments, this site and others are randomly advertised by allbestlinks .info and top-low-price-sites .com.

Leave A Comment

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s

This site uses Akismet to reduce spam. Learn how your comment data is processed.