What Are Botnets – Understanding Them

Botnets Are The Threats To The Global Infrastructure
There Are Approximately
100 – 150 Million Botnets Computers Worldwide

Advertisement

Canadian Pharmacy Spam – allthebestatyourfingertips.com

Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
68.142.207.168 United States (Sunnyvale)* Whois Google DNSStuff Urgentmessage.org
216.100.91.6 United States (Orange)* Whois Google DNSStuff Urgentmessage.org
207.115.20.18 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

O0rder all your Favorite_Medications 0nline!
Browse Our Selection Today! -> http://allthebestatyourfingertips.com

From Ronda Morris Fri Sep 25 03:12:24 2009
X-Apparently- Fri, 25 Sep 2009 10:12:31 -0700
Return-Path: <rondamorris_yd@resmed.com.au>
X-YahooFilteredBulk: 216.100.91.6
X-YMailISG: ZVkpBtYWLDus6bK24BEw6wDy_AzUhvchxxHMuHz21VQUqtGfsANfuLs.2DrfYv8SQ_.OW0gp2CS2_DQktjA5dCJib.x99JuqYcpWnJdFhd6qmHUcY66BcQhLyycD2L7VfG_5KYUTHkjblhzFg3bIuYGfCDe9N0PsK18E7ZWY9OWUj36o.eLTkiGEmG7KDBtMJVaJDc4gIu_61lL1_ruYoay2WWX4aDE8enWF0Pr6Kis68CfceTNFahxRmJZVPTVd2.WVj9NsyQj3yNiaEaz4t8whmFSMGNqJ92rNfIom9qKMCQmzKLkEZn.g4Al_91376LnsQAfZTaYhIBWG2E3G
X-Originating-IP: [216.100.91.6]
Authentication-Results: mta111.sbc.mail.gq1.yahoo.com from=resmed.com.au; domainkeys=neutral (no sig); from=resmed.com.au; dkim=neutral (no sig)
Received: from 216.100.91.6 (EHLO flph260.prodigy.net) (207.115.20.18)
by mta111.sbc.mail.gq1.yahoo.com with SMTP; Fri, 25 Sep 2009 10:12:31 -0700
X-Header-NoReverseIP: IP.name.lookup.failed[216.100.91.6]
X-Originating-IP: [216.100.91.6]
Received: from jwu8wm2 ([216.100.91.6])
by flph260.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n8PHAsnV003600;
Fri, 25 Sep 2009 10:12:27 -0700
Message-ID: <000701ca3dc8$ad9272d0$627e09ca@resmed.com.au>
Reply-To: “Ronda Morris” <rondamorris_yd@resmed.com.au>
From: “Ronda Morris” <rondamorris_yd@resmed.com.au>
To: ,
Subject: Get RxMed without a Doctor online!
Date: Fri, 25 Sep 2009 03:12:24 -0700 championrxsource.com
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Office Outlook, Build 11.0.5510
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1807
Content-Length: 118

Address lookup

canonical name allthebestatyourfingertips.com.
aliases
addresses 60.12.166.154
Domain Whois record

Queried whois.internic.net with “dom allthebestatyourfingertips.com”…

Domain Name: ALLTHEBESTATYOURFINGERTIPS.COM
Registrar: CHINA SPRINGBOARD INC.
Whois Server: whois.namerich.cn
Referral URL: http://www.namerich.cn
Name Server: NS1.UBR34NS.COM
Name Server: NS2.UBR34NS.COM
Name Server: NS3.BIDOKODJU.COM
Name Server: NS4.BIDOKODJU.COM
Name Server: NS5.HOSTLIFE45.COM
Name Server: NS6.HOSTLIFE45.COM
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 22-sep-2009
Creation Date: 16-sep-2009
Expiration Date: 16-sep-2010

>>> Last update of whois database: Fri, 25 Sep 2009 21:54:58 UTC <<<
Queried whois.namerich.cn with “allthebestatyourfingertips.com”…

; This data is provided by China Springboard Inc.
; for information purposes, and to assist persons obtaining information
; about or related to domain name registration records.
; China Springboard Inc. does not guarantee its accuracy.
; By submitting a WHOIS query, you agree that you will use this data
; only for lawful purposes and that, under no circumstances, you will
; use this data to
; 1) allow, enable, or otherwise support the transmission of mass
; unsolicited, commercial advertising or solicitations via E-mail
; (spam); or
; 2) enable high volume, automated, electronic processes that apply
; to this WHOIS server.
; These terms may be changed without prior notice.
; By submitting this query, you agree to abide by this policy.

DomainName : allthebestatyourfingertips.com

RSP: China Springboard Inc.
URL: http://www.namerich.cn

Name Server………………….NS5.HOSTLIFE45.COM
Name Server………………….NS1.UBR34NS.COM
Name Server………………….NS2.UBR34NS.COM
Name Server………………….NS4.BIDOKODJU.COM
Name Server………………….NS6.HOSTLIFE45.COM
Name Server………………….NS3.BIDOKODJU.COM
Status………………………clientTransferProhibited
Status………………………clientDeleteProhibited
Creation Date ………………2009-09-16
Expiration Date ……………..2010-09-16
Last Update Date ……………2009-09-23

Registrant ID ……………….V-X-58522-14215
Registrant Name ……………..ZHANG WENQI
Registrant Organization ………ZHANG WENQI
Registrant Address …………..JIAOTONGLU16
Registrant City………………DL
Registrant Province/State …….LN
Registrant Country Code ………CN
Registrant Postal Code ……….116049
Registrant Phone Number ………+86.041128805621
Registrant Fax ………………+86.041128805621
Registrant Email …………….kaokga@126.com

Administrative ID ……………V-X-58522-14215
Administrative Name ………….ZHANG WENQI
Administrative Organization …..ZHANG WENQI
Administrative Address ……….JIAOTONGLU16
Administrative City…………..DL
Administrative Province/State …LN
Administrative Country Code …..CN
Administrative Postal Code ……116049
Administrative Phone Number …..+86.041128805621
Administrative Fax …………..+86.041128805621
Administrative Email …………kaokga@126.com

Billing ID ………………….V-X-58522-14215
Billing Name ………………..ZHANG WENQI
Billing Organization …………ZHANG WENQI
Billing Address ……………..JIAOTONGLU16
Billing City…………………DL
Billing Province/State ……….LN
Billing Country Code …………CN
Billing Postal Code ………….116049
Billing Phone Number …………+86.041128805621
Billing Fax …………………+86.041128805621
Billing Email ……………….kaokga@126.com

Technical ID ………………..V-X-58522-14215
Technical Name ………………ZHANG WENQI
Technical Organization………..ZHANG WENQI
Technical Address ……………JIAOTONGLU16
Technical City……………….DL
Technical Province/State………LN
Technical Country Code ……….CN
Technical Postal Code ………..116049
Technical Phone Number ……….+86.041128805621
Technical Fax ……………….+86.041128805621
Technical Email ……………..kaokga@126.com

; Please register your domains at
; http://www.namerich.cn
Network Whois record

Queried whois.apnic.net with “60.12.166.154”…

inetnum: 60.12.0.0 – 60.12.255.255
netname: UNICOM-ZJ
descr: China Unicom Zhejiang province network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: JQ16-AP
remarks: service provider
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP-ZJ
mnt-routes: MAINT-CNCGROUP-RR
status: ALLOCATED PORTABLE
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation’s account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20040629
changed: hm-changed@apnic.net 20060124
changed: hm-changed@apnic.net 20090507
changed: hm-changed@apnic.net 20090508
source: APNIC

route: 60.12.0.0/16
descr: CNC Group CHINA169 Zhejiang Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060118
source: APNIC

person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: abuse@chinaunicom.cn
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: abuse@chinaunicom.cn 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC

person: Jianhuaq Qian
nic-hdl: JQ16-AP
e-mail: chenrenhai@china-netcom.com
address: No 1,Hangzhou University Road,Hangzhou, Zhejiang,China
phone: +86-571-28868063
fax-no: +86-571-28868069
country: CN
changed: wuhong@china-netcom.com 20050421
mnt-by: MAINT-CNCGROUP-ZJ
source: APNIC
DNS records

DNS query for 154.166.12.60.in-addr.arpa returned an error from the server: NameError

name class type data time to live
allthebestatyourfingertips.com IN A 60.12.166.154 162s (00:02:42)
— end —

Saturn Group – saturn-groupsvc.com/e/

The Purpose of This Post Is To ALERT You That The Job You Are About To APPLY TO or May Have Applied For or is CONSIDERING APPLYING FOR Is Fraudulent. A LEGITIMATE COMPANY IDENTITY HAS BEEN STOLEN OR A BOGUS ONE CREATED

These job postings are an attempt to lure you into cashing counterfeit checks and have you wire funds via Western Union or MoneyGram -Essentially You Become A Money or RePackage Mule

Money Mule Explained

Read All About This at Symantec Corp.

See Bobbear.co.uk – The Encyclopedia of Money Mules

Financial Manager

Location: USA, statewide Saturn Group2
Availability: currently available
Employment type: Part-time employment
Number of employees required: 3

CANDIDATE REQUIREMENTS.

* not less than 18 years old
* internet access to reply emails promptly
* availability by phone (1-2 hours a day)
* a bank account to process payments
* good credit history with your bank (new bank account is an option)
* no criminal offense or convictions
* experience in the field of finance is preferred

DUTIES

We are searching for people to process payments coming from our clients. Saturn Group will provide an agent with detailed instructions as regards payment processing operations including sender full name and amount total for each separate case.

When funds enter employee’s bank account, Financial Agent’s duty is to withdraw cash and transfer the funds via International Wire Transfer or Western Union/Money Gram money transfer systems. The main advantage of our services is the shortest possible time within which the seller can receive money for the services/goods sold. If this operation is delayed, our clients are entitled to cancel their contract with us and we suffer financial loss. Therefore, successful applicant must be very responsible and careful!

TRIAL PERIOD POLICY

Successful applicants are offered the position on a probationary period basis (1 month). This is the period when a new employee will be trained and receive online support while working and being paid. A personal supervisor can recommend termination during/after the trial period depending on agent’s activity. New employee should be responsible and strictly follow supervisor’s recommendations to pass the Probationary Period successfully and be employed by us on a regular basis.

SALARY

During the probationary period we offer USD 2,300 monthly salary plus 8% commission for each payment processing operation. For example, an average $5,000 payment will entail $400 commission (but WU/MG fee is paid from this money, please see for more details below). Furthermore, we offer $50 bonus for each transaction completed by 11 a.m. (local time). With the current number of clients, on average, your overall income will amount to up to USD 4,000 per month. A successful agent may ask for additional tasks and earn more. After the probationary period base salary will be as high as USD 3,000 per month plus 8% commission. Base salary ($2,300) will be transferred at the end of each month to employee’s bank account. Commission (8%) is to be deducted from the processed money.

IMPORTANT DETAILS

* Financial Agent is supposed to process received assets during one business day, i.e. from the moment of money entering his bank account to the moment of re-send to our client in accordance with contract terms. If money enters employee’s account on a day-off or holiday, all payment processing procedures have to be completed during the next working day.
* Financial Agent receives invoices for each transaction every 14 days. This document is a confirmation of transaction validity, and in case of any (if any at all) unforeseen circumstances it will evidence your personal non-participation. All invoices will contain detailed information on money sender and will be both sealed and certified with President’s signature.
*After the Probationary Period completion, invoices will be sent every business day.
* Since business transfers can be processed with delays, Financial Manager should specify each transfer as a private remittance. This provision is also applicable in case of a third party interest in the transfer.
* Our clients appreciate our operational efficiency and are ready to pay extra fee for shorter transaction terms. If we manage to deliver goods to buyer within 10 days, the deal is considered to be fulfilled at the earliest possible date.
* All the fees (WU/MG) are paid from employee’s commission. HOWEVER, our company undertakes to reimburse part of expenses which are incurred in connection with money transfer (WIRE or by Western Union/Money gram system) should money transfer charges exceed 3%. All in all, your net profit will amount to 5-8% of the total amount of each payment processing operation.
* We don’t ask for any investment to start cooperating with our company.
* The company offers incentive bonus program based on work results with regard to several factors, i.e. total sum of money transferred, payment processing time, etc.

OUR BENEFITS

Probationary period imposes restrictions on the employment benefits of our corporation. Financial Manager will be able to receive Saturn Group employment benefits only after probationary period completion. Employment benefits will include:

* stock options
* child-care subsidies
* flex-time
* business casual attire
* free training and professional development programs

*Detailed information concerning the employment benefits will be provided after probationary period successful completion.
xxxxxx

Address lookup

canonical name saturn-groupsvc.com.
aliases
addresses 222.35.137.238

Domain Whois record

Queried whois.internic.net with “dom saturn-groupsvc.com“…

   Domain Name: SATURN-GROUPSVC.COM
   Registrar: ALANTRON BLTD.
   Whois Server: whois.alantron.com
   Referral URL: http://www.alantron.com.tr
   Name Server: NS1.DUMMYKEATH.CC
   Name Server: NS1.TOTALLYSMILED.CN
   Status: clientTransferProhibited
   Updated Date: 28-jul-2009
   Creation Date: 28-jul-2009
   Expiration Date: 28-jul-2010

>>> Last update of whois database: Fri, 25 Sep 2009 20:07:59 UTC <<<

Queried whois.alantron.com with “saturn-groupsvc.com“…

@
@
____________________________TURKCE_________________________________
--- Asagida verilen kisisel bilgiler sadece Turk Yasalarinda
--- kabul edilen sinirlar cercevesinde kullanilabilir.
--- http://www.tk.gov.tr/Duzenlemeler/Hukuki/yonetmelikler/Kisisel_Bil_Yon_06_02_04.pdf
--- Bu bilgilerin ticari kullanimi kesinlikle yasaktir.
--- Alan adinin muktesep ve yetkilileri hususunda sadece ICANN UDRP
--- http://www.icann.org/udrp/udrp.htm hukumleri gecerlidir.
___________________________________________________________________

____________________________ENGLISH_______________________________
--- The use of the given personal information is restricted by
--- Turkish laws.
--- http://www.tk.gov.tr/Duzenlemeler/Hukuki/yonetmelikler/Kisisel_Bil_Yon_06_02_04.pdf
--- Commercial use of this information is strictly forbidden.
--- ICANN UDRP http://www.icann.org/udrp/udrp.htm rules apply
--- for the disputes on the ownership and contacts of the domain.
__________________________________________________________________

Arastirilan alan adi: saturn-groupsvc.com
	Ad / Name	  Vladimir Zhilinsky
	Adres	ul.Inzhenernaya d.62 kv.206 Pskov Pskovskaya oblast 180019
	Tel	+7.8112723058
	Faks	+7.8112723058
	E-posta   jelly@infotorrent.ru
	Guncelleme / Updated  

        Ad    gizli
        Ad / Name      Vladimir Zhilinsky
        Adres ul.Inzhenernaya d.62 kv.206 Pskov Pskovskaya oblast 180019
        Tel   +7.8112723058
        Faks     +7.8112723058
        E-posta   jelly@infotorrent.ru
        Guncelleme / Updated	

        Ad    gizli
        Ad / Name     Vladimir Zhilinsky
        Adres ul.Inzhenernaya d.62 kv.206 Pskov Pskovskaya oblast 180019
        Tel   +7.8112723058
        Faks     +7.8112723058
        E-posta   jelly@infotorrent.ru
        Guncelleme / Updated 

Alan Adi Sunucusu1 / DNS1       ns1.totallysmiled.cn
Alan Adi Sunucusu1 IP / DNS1 IP
Alan Adi Sunucusu2 / DNS2       ns1.dummykeath.cc
Alan Adi Sunucusu2 IP / DNS2 IP
Son Guncelleme/ Last Updated
Kayit Tarihi / Registration Date	2009-07-28
SKT / Exp. Date				2010-07-28
Statu					Aktif

2009-09-25

Network Whois record

Queried whois.apnic.net with “222.35.137.238“…

inetnum:      222.32.0.0 - 222.63.255.255
netname:      CRTC
descr:        CHINA RAILWAY TELECOMMUNICATIONS CENTER
descr:        22F Yuetan Mansion,Xicheng District,Beijing,P.R.China
country:      CN
admin-c:      LQ112-AP
tech-c:       LM273-AP
status:       ALLOCATED PORTABLE
mnt-by:       MAINT-CNNIC-AP
changed:      hm-changed@apnic.net 20030902
source:       APNIC

route:        222.32.0.0/11
descr:        China TieTong Telecommunications Corporation
country:      CN
origin:       AS9394
mnt-by:       MAINT-CNNIC-AP
changed:      ipas@cnnic.net.cn 20090908
source:       APNIC

person:       LV QIANG
nic-hdl:      LQ112-AP
e-mail:       crnet_mgr@chinatietong.com
address:      22F Yuetan Mansion,Xicheng District,Beijing,P.R.China
phone:        +86-10-51892111
fax-no:       +86-10-51847845
country:      CN
changed:      ipas@cnnic.net.cn 20060911
mnt-by:       MAINT-CNNIC-AP
source:       APNIC

person:       liu min
nic-hdl:      LM273-AP
e-mail:       abuse@chinatietong.com
address:      22F Yuetan Mansion,Xicheng District,Beijing,P.R.China
phone:        +86-10-51848796
fax-no:       +86-10-51842426
country:      CN
changed:      ipas@cnnic.net.cn 20041208
mnt-by:       MAINT-CNNIC-AP
source:       APNIC

inetnum:      222.32.0.0 - 222.63.255.255
netname:      CRTC
descr:        CHINA RAILWAY TELECOMMUNICATIONS CENTER
descr:        22F Yuetan Mansion,Xicheng District,Beijing
country:      CN
admin-c:      LQ112-CN
tech-c:       LM273-CN
status:       ALLOCATED PORTABLE
changed:      hm-changed@apnic.net 20030902
mnt-by:       MAINT-CNNIC-AP
source:       CNNIC

person:       LV QIANG
nic-hdl:      LQ112-CN
e-mail:       crnet_mgr@chinatietong.com
address:      22F Yuetan Mansion,Xicheng District,Beijing
phone:        +86-10-51892111
fax-no:       +86-10-51847845
country:      CN
changed:      ipas@cnnic.cn 20060419
mnt-by:       MAINT-CNNIC-AP
source:       CNNIC

person:       liu min
nic-hdl:      LM273-CN
e-mail:       crnet_tec@chinatietong.com
address:      22F Yuetan Mansion,Xicheng District,Beijing,P.R.China
phone:        +86-10-51848796
fax-no:       +86-10-51842426
country:      CN
changed:      ipas@cnnic.net.cn 20041208
mnt-by:       MAINT-CNNIC-AP
source:       CNNIC

DNS records

DNS query for 238.137.35.222.in-addr.arpa returned an error from the server: NameError

name class type data time to live
saturn-groupsvc.com IN SOA
server: ns1.dummykeath.cc
email: root.ns1.dummykeath.cc
serial: 909251159
refresh: 300
retry: 120
expire: 86400
minimum ttl: 60
120s (00:02:00)
saturn-groupsvc.com IN A 222.35.137.238 120s (00:02:00)
saturn-groupsvc.com IN NS ns1.totallysmiled.cn 120s (00:02:00)
saturn-groupsvc.com IN NS ns1.dummykeath.cc 120s (00:02:00)
saturn-groupsvc.com IN MX
preference: 10
exchange: mx.saturn-groupsvc.com
120s (00:02:00)

— end —

A DISPATCHER AND ACCOUNT PAYABLE CLERK IS NEEDED

The Purpose of This Post Is To ALERT You That The Job You Are About To APPLY TO or May Have Applied For or is CONSIDERING APPLYING FOR Is Fraudulent. A LEGITIMATE COMPANY IDENTITY HAS BEEN STOLEN OR A BOGUS ONE CREATED

These job postings are an attempt to lure you into cashing counterfeit checks and have you wire funds via Western Union or MoneyGram -Essentially You Become A Money or RePackage Mule

Money Mule Explained

Read All About This at Symantec Corp.

A dispatcher and account payable clerk is needed.We pay good salary and take good care of our worker.apply now.

  • Compensation: salary
  • Telecommuting is ok.
  • This is a part-time job.
  • This is an internship job
  • OK to highlight this job opening for persons with disabilities
  • Principals only. Recruiters, please don’t contact this job poster.
  • Please, no phone calls about this job!
  • Please do not contact job poster about other services, products or commercial interests.