Day: September 25, 2009
Canadian Pharmacy Spam – allthebestatyourfingertips.com
Header Analysis
The following IP addresses were extracted from your headers:
IP Address | Probable Country | Additional Info | |||
68.142.207.168 | United States (Sunnyvale)* | Whois | DNSStuff | Urgentmessage.org | |
216.100.91.6 | United States (Orange)* | Whois | DNSStuff | Urgentmessage.org | |
207.115.20.18 | United States (Richardson)* | Whois | DNSStuff | Urgentmessage.org | |
* The last IP listed is usually the originating IP address |
Here is the text you submitted, with the IP addresses highlighted:
O0rder all your Favorite_Medications 0nline!
Browse Our Selection Today! -> http://allthebestatyourfingertips.com
From Ronda Morris Fri Sep 25 03:12:24 2009
X-Apparently- Fri, 25 Sep 2009 10:12:31 -0700
Return-Path: <rondamorris_yd@resmed.com.au>
X-YahooFilteredBulk: 216.100.91.6
X-YMailISG: ZVkpBtYWLDus6bK24BEw6wDy_AzUhvchxxHMuHz21VQUqtGfsANfuLs.2DrfYv8SQ_.OW0gp2CS2_DQktjA5dCJib.x99JuqYcpWnJdFhd6qmHUcY66BcQhLyycD2L7VfG_5KYUTHkjblhzFg3bIuYGfCDe9N0PsK18E7ZWY9OWUj36o.eLTkiGEmG7KDBtMJVaJDc4gIu_61lL1_ruYoay2WWX4aDE8enWF0Pr6Kis68CfceTNFahxRmJZVPTVd2.WVj9NsyQj3yNiaEaz4t8whmFSMGNqJ92rNfIom9qKMCQmzKLkEZn.g4Al_91376LnsQAfZTaYhIBWG2E3G
X-Originating-IP: [216.100.91.6]
Authentication-Results: mta111.sbc.mail.gq1.yahoo.com from=resmed.com.au; domainkeys=neutral (no sig); from=resmed.com.au; dkim=neutral (no sig)
Received: from 216.100.91.6 (EHLO flph260.prodigy.net) (207.115.20.18)
by mta111.sbc.mail.gq1.yahoo.com with SMTP; Fri, 25 Sep 2009 10:12:31 -0700
X-Header-NoReverseIP: IP.name.lookup.failed[216.100.91.6]
X-Originating-IP: [216.100.91.6]
Received: from jwu8wm2 ([216.100.91.6])
by flph260.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n8PHAsnV003600;
Fri, 25 Sep 2009 10:12:27 -0700
Message-ID: <000701ca3dc8$ad9272d0$627e09ca@resmed.com.au>
Reply-To: “Ronda Morris” <rondamorris_yd@resmed.com.au>
From: “Ronda Morris” <rondamorris_yd@resmed.com.au>
To: ,
Subject: Get RxMed without a Doctor online!
Date: Fri, 25 Sep 2009 03:12:24 -0700
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Office Outlook, Build 11.0.5510
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1807
Content-Length: 118
Address lookup
canonical name allthebestatyourfingertips.com.
aliases
addresses 60.12.166.154
Domain Whois record
Queried whois.internic.net with “dom allthebestatyourfingertips.com”…
Domain Name: ALLTHEBESTATYOURFINGERTIPS.COM
Registrar: CHINA SPRINGBOARD INC.
Whois Server: whois.namerich.cn
Referral URL: http://www.namerich.cn
Name Server: NS1.UBR34NS.COM
Name Server: NS2.UBR34NS.COM
Name Server: NS3.BIDOKODJU.COM
Name Server: NS4.BIDOKODJU.COM
Name Server: NS5.HOSTLIFE45.COM
Name Server: NS6.HOSTLIFE45.COM
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 22-sep-2009
Creation Date: 16-sep-2009
Expiration Date: 16-sep-2010
>>> Last update of whois database: Fri, 25 Sep 2009 21:54:58 UTC <<<
Queried whois.namerich.cn with “allthebestatyourfingertips.com”…
; This data is provided by China Springboard Inc.
; for information purposes, and to assist persons obtaining information
; about or related to domain name registration records.
; China Springboard Inc. does not guarantee its accuracy.
; By submitting a WHOIS query, you agree that you will use this data
; only for lawful purposes and that, under no circumstances, you will
; use this data to
; 1) allow, enable, or otherwise support the transmission of mass
; unsolicited, commercial advertising or solicitations via E-mail
; (spam); or
; 2) enable high volume, automated, electronic processes that apply
; to this WHOIS server.
; These terms may be changed without prior notice.
; By submitting this query, you agree to abide by this policy.
DomainName : allthebestatyourfingertips.com
RSP: China Springboard Inc.
URL: http://www.namerich.cn
Name Server………………….NS5.HOSTLIFE45.COM
Name Server………………….NS1.UBR34NS.COM
Name Server………………….NS2.UBR34NS.COM
Name Server………………….NS4.BIDOKODJU.COM
Name Server………………….NS6.HOSTLIFE45.COM
Name Server………………….NS3.BIDOKODJU.COM
Status………………………clientTransferProhibited
Status………………………clientDeleteProhibited
Creation Date ………………2009-09-16
Expiration Date ……………..2010-09-16
Last Update Date ……………2009-09-23
Registrant ID ……………….V-X-58522-14215
Registrant Name ……………..ZHANG WENQI
Registrant Organization ………ZHANG WENQI
Registrant Address …………..JIAOTONGLU16
Registrant City………………DL
Registrant Province/State …….LN
Registrant Country Code ………CN
Registrant Postal Code ……….116049
Registrant Phone Number ………+86.041128805621
Registrant Fax ………………+86.041128805621
Registrant Email …………….kaokga@126.com
Administrative ID ……………V-X-58522-14215
Administrative Name ………….ZHANG WENQI
Administrative Organization …..ZHANG WENQI
Administrative Address ……….JIAOTONGLU16
Administrative City…………..DL
Administrative Province/State …LN
Administrative Country Code …..CN
Administrative Postal Code ……116049
Administrative Phone Number …..+86.041128805621
Administrative Fax …………..+86.041128805621
Administrative Email …………kaokga@126.com
Billing ID ………………….V-X-58522-14215
Billing Name ………………..ZHANG WENQI
Billing Organization …………ZHANG WENQI
Billing Address ……………..JIAOTONGLU16
Billing City…………………DL
Billing Province/State ……….LN
Billing Country Code …………CN
Billing Postal Code ………….116049
Billing Phone Number …………+86.041128805621
Billing Fax …………………+86.041128805621
Billing Email ……………….kaokga@126.com
Technical ID ………………..V-X-58522-14215
Technical Name ………………ZHANG WENQI
Technical Organization………..ZHANG WENQI
Technical Address ……………JIAOTONGLU16
Technical City……………….DL
Technical Province/State………LN
Technical Country Code ……….CN
Technical Postal Code ………..116049
Technical Phone Number ……….+86.041128805621
Technical Fax ……………….+86.041128805621
Technical Email ……………..kaokga@126.com
; Please register your domains at
; http://www.namerich.cn
Network Whois record
Queried whois.apnic.net with “60.12.166.154”…
inetnum: 60.12.0.0 – 60.12.255.255
netname: UNICOM-ZJ
descr: China Unicom Zhejiang province network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: JQ16-AP
remarks: service provider
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP-ZJ
mnt-routes: MAINT-CNCGROUP-RR
status: ALLOCATED PORTABLE
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation’s account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20040629
changed: hm-changed@apnic.net 20060124
changed: hm-changed@apnic.net 20090507
changed: hm-changed@apnic.net 20090508
source: APNIC
route: 60.12.0.0/16
descr: CNC Group CHINA169 Zhejiang Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060118
source: APNIC
person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: abuse@chinaunicom.cn
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: abuse@chinaunicom.cn 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC
person: Jianhuaq Qian
nic-hdl: JQ16-AP
e-mail: chenrenhai@china-netcom.com
address: No 1,Hangzhou University Road,Hangzhou, Zhejiang,China
phone: +86-571-28868063
fax-no: +86-571-28868069
country: CN
changed: wuhong@china-netcom.com 20050421
mnt-by: MAINT-CNCGROUP-ZJ
source: APNIC
DNS records
DNS query for 154.166.12.60.in-addr.arpa returned an error from the server: NameError
name class type data time to live
allthebestatyourfingertips.com IN A 60.12.166.154 162s (00:02:42)
— end —
Canadian Pharmacy Spam Is Among The Most Prevalent
LA Times Consumer columnist David Lazarus
Says the worst thing you can do when you are hit by unwanted spam is to try to “unsubscribe.”
Safety Tips for In-Store and Online Shopping
Holiday Shopping Tips
Everyone Should Know
BBB Safe Online Shopping Tips
Your Better Business Bureau is warning that scammers will again be setting up shop online this year, using low prices to entice shoppers, but ultimately not delivering the goods
Saturn Group – saturn-groupsvc.com/e/
The Purpose of This Post Is To ALERT You That The Job You Are About To APPLY TO or May Have Applied For or is CONSIDERING APPLYING FOR Is Fraudulent. A LEGITIMATE COMPANY IDENTITY HAS BEEN STOLEN OR A BOGUS ONE CREATED
These job postings are an attempt to lure you into cashing counterfeit checks and have you wire funds via Western Union or MoneyGram -Essentially You Become A Money or RePackage Mule
Money Mule Explained
Read All About This at Symantec Corp.
See Bobbear.co.uk – The Encyclopedia of Money Mules
Financial Manager
Location: USA, statewide
Availability: currently available
Employment type: Part-time employment
Number of employees required: 3
CANDIDATE REQUIREMENTS.
* not less than 18 years old
* internet access to reply emails promptly
* availability by phone (1-2 hours a day)
* a bank account to process payments
* good credit history with your bank (new bank account is an option)
* no criminal offense or convictions
* experience in the field of finance is preferred
DUTIES
We are searching for people to process payments coming from our clients. Saturn Group will provide an agent with detailed instructions as regards payment processing operations including sender full name and amount total for each separate case.
When funds enter employee’s bank account, Financial Agent’s duty is to withdraw cash and transfer the funds via International Wire Transfer or Western Union/Money Gram money transfer systems. The main advantage of our services is the shortest possible time within which the seller can receive money for the services/goods sold. If this operation is delayed, our clients are entitled to cancel their contract with us and we suffer financial loss. Therefore, successful applicant must be very responsible and careful!
TRIAL PERIOD POLICY
Successful applicants are offered the position on a probationary period basis (1 month). This is the period when a new employee will be trained and receive online support while working and being paid. A personal supervisor can recommend termination during/after the trial period depending on agent’s activity. New employee should be responsible and strictly follow supervisor’s recommendations to pass the Probationary Period successfully and be employed by us on a regular basis.
SALARY
During the probationary period we offer USD 2,300 monthly salary plus 8% commission for each payment processing operation. For example, an average $5,000 payment will entail $400 commission (but WU/MG fee is paid from this money, please see for more details below). Furthermore, we offer $50 bonus for each transaction completed by 11 a.m. (local time). With the current number of clients, on average, your overall income will amount to up to USD 4,000 per month. A successful agent may ask for additional tasks and earn more. After the probationary period base salary will be as high as USD 3,000 per month plus 8% commission. Base salary ($2,300) will be transferred at the end of each month to employee’s bank account. Commission (8%) is to be deducted from the processed money.
IMPORTANT DETAILS
* Financial Agent is supposed to process received assets during one business day, i.e. from the moment of money entering his bank account to the moment of re-send to our client in accordance with contract terms. If money enters employee’s account on a day-off or holiday, all payment processing procedures have to be completed during the next working day.
* Financial Agent receives invoices for each transaction every 14 days. This document is a confirmation of transaction validity, and in case of any (if any at all) unforeseen circumstances it will evidence your personal non-participation. All invoices will contain detailed information on money sender and will be both sealed and certified with President’s signature.
*After the Probationary Period completion, invoices will be sent every business day.
* Since business transfers can be processed with delays, Financial Manager should specify each transfer as a private remittance. This provision is also applicable in case of a third party interest in the transfer.
* Our clients appreciate our operational efficiency and are ready to pay extra fee for shorter transaction terms. If we manage to deliver goods to buyer within 10 days, the deal is considered to be fulfilled at the earliest possible date.
* All the fees (WU/MG) are paid from employee’s commission. HOWEVER, our company undertakes to reimburse part of expenses which are incurred in connection with money transfer (WIRE or by Western Union/Money gram system) should money transfer charges exceed 3%. All in all, your net profit will amount to 5-8% of the total amount of each payment processing operation.
* We don’t ask for any investment to start cooperating with our company.
* The company offers incentive bonus program based on work results with regard to several factors, i.e. total sum of money transferred, payment processing time, etc.
OUR BENEFITS
Probationary period imposes restrictions on the employment benefits of our corporation. Financial Manager will be able to receive Saturn Group employment benefits only after probationary period completion. Employment benefits will include:
* stock options
* child-care subsidies
* flex-time
* business casual attire
* free training and professional development programs
*Detailed information concerning the employment benefits will be provided after probationary period successful completion.
xxxxxx
Address lookup
canonical name | saturn-groupsvc.com. |
aliases | |
addresses | 222.35.137.238 |
Domain Whois record
Queried whois.internic.net with “dom saturn-groupsvc.com“…
Domain Name: SATURN-GROUPSVC.COM Registrar: ALANTRON BLTD. Whois Server: whois.alantron.com Referral URL: http://www.alantron.com.tr Name Server: NS1.DUMMYKEATH.CC Name Server: NS1.TOTALLYSMILED.CN Status: clientTransferProhibited Updated Date: 28-jul-2009 Creation Date: 28-jul-2009 Expiration Date: 28-jul-2010 >>> Last update of whois database: Fri, 25 Sep 2009 20:07:59 UTC <<<
Queried whois.alantron.com with “saturn-groupsvc.com“…
@ @ ____________________________TURKCE_________________________________ --- Asagida verilen kisisel bilgiler sadece Turk Yasalarinda --- kabul edilen sinirlar cercevesinde kullanilabilir. --- http://www.tk.gov.tr/Duzenlemeler/Hukuki/yonetmelikler/Kisisel_Bil_Yon_06_02_04.pdf --- Bu bilgilerin ticari kullanimi kesinlikle yasaktir. --- Alan adinin muktesep ve yetkilileri hususunda sadece ICANN UDRP --- http://www.icann.org/udrp/udrp.htm hukumleri gecerlidir. ___________________________________________________________________ ____________________________ENGLISH_______________________________ --- The use of the given personal information is restricted by --- Turkish laws. --- http://www.tk.gov.tr/Duzenlemeler/Hukuki/yonetmelikler/Kisisel_Bil_Yon_06_02_04.pdf --- Commercial use of this information is strictly forbidden. --- ICANN UDRP http://www.icann.org/udrp/udrp.htm rules apply --- for the disputes on the ownership and contacts of the domain. __________________________________________________________________ Arastirilan alan adi: saturn-groupsvc.com Ad / Name Vladimir Zhilinsky Adres ul.Inzhenernaya d.62 kv.206 Pskov Pskovskaya oblast 180019 Tel +7.8112723058 Faks +7.8112723058 E-posta jelly@infotorrent.ru Guncelleme / Updated Ad gizli Ad / Name Vladimir Zhilinsky Adres ul.Inzhenernaya d.62 kv.206 Pskov Pskovskaya oblast 180019 Tel +7.8112723058 Faks +7.8112723058 E-posta jelly@infotorrent.ru Guncelleme / Updated Ad gizli Ad / Name Vladimir Zhilinsky Adres ul.Inzhenernaya d.62 kv.206 Pskov Pskovskaya oblast 180019 Tel +7.8112723058 Faks +7.8112723058 E-posta jelly@infotorrent.ru Guncelleme / Updated Alan Adi Sunucusu1 / DNS1 ns1.totallysmiled.cn Alan Adi Sunucusu1 IP / DNS1 IP Alan Adi Sunucusu2 / DNS2 ns1.dummykeath.cc Alan Adi Sunucusu2 IP / DNS2 IP Son Guncelleme/ Last Updated Kayit Tarihi / Registration Date 2009-07-28 SKT / Exp. Date 2010-07-28 Statu Aktif 2009-09-25
Network Whois record
Queried whois.apnic.net with “222.35.137.238“…
inetnum: 222.32.0.0 - 222.63.255.255 netname: CRTC descr: CHINA RAILWAY TELECOMMUNICATIONS CENTER descr: 22F Yuetan Mansion,Xicheng District,Beijing,P.R.China country: CN admin-c: LQ112-AP tech-c: LM273-AP status: ALLOCATED PORTABLE mnt-by: MAINT-CNNIC-AP changed: hm-changed@apnic.net 20030902 source: APNIC route: 222.32.0.0/11 descr: China TieTong Telecommunications Corporation country: CN origin: AS9394 mnt-by: MAINT-CNNIC-AP changed: ipas@cnnic.net.cn 20090908 source: APNIC person: LV QIANG nic-hdl: LQ112-AP e-mail: crnet_mgr@chinatietong.com address: 22F Yuetan Mansion,Xicheng District,Beijing,P.R.China phone: +86-10-51892111 fax-no: +86-10-51847845 country: CN changed: ipas@cnnic.net.cn 20060911 mnt-by: MAINT-CNNIC-AP source: APNIC person: liu min nic-hdl: LM273-AP e-mail: abuse@chinatietong.com address: 22F Yuetan Mansion,Xicheng District,Beijing,P.R.China phone: +86-10-51848796 fax-no: +86-10-51842426 country: CN changed: ipas@cnnic.net.cn 20041208 mnt-by: MAINT-CNNIC-AP source: APNIC inetnum: 222.32.0.0 - 222.63.255.255 netname: CRTC descr: CHINA RAILWAY TELECOMMUNICATIONS CENTER descr: 22F Yuetan Mansion,Xicheng District,Beijing country: CN admin-c: LQ112-CN tech-c: LM273-CN status: ALLOCATED PORTABLE changed: hm-changed@apnic.net 20030902 mnt-by: MAINT-CNNIC-AP source: CNNIC person: LV QIANG nic-hdl: LQ112-CN e-mail: crnet_mgr@chinatietong.com address: 22F Yuetan Mansion,Xicheng District,Beijing phone: +86-10-51892111 fax-no: +86-10-51847845 country: CN changed: ipas@cnnic.cn 20060419 mnt-by: MAINT-CNNIC-AP source: CNNIC person: liu min nic-hdl: LM273-CN e-mail: crnet_tec@chinatietong.com address: 22F Yuetan Mansion,Xicheng District,Beijing,P.R.China phone: +86-10-51848796 fax-no: +86-10-51842426 country: CN changed: ipas@cnnic.net.cn 20041208 mnt-by: MAINT-CNNIC-AP source: CNNIC
DNS records
DNS query for 238.137.35.222.in-addr.arpa returned an error from the server: NameError
name | class | type | data | time to live | |||||||||||||||
saturn-groupsvc.com | IN | SOA |
|
120s | (00:02:00) | ||||||||||||||
saturn-groupsvc.com | IN | A | 222.35.137.238 | 120s | (00:02:00) | ||||||||||||||
saturn-groupsvc.com | IN | NS | ns1.totallysmiled.cn | 120s | (00:02:00) | ||||||||||||||
saturn-groupsvc.com | IN | NS | ns1.dummykeath.cc | 120s | (00:02:00) | ||||||||||||||
saturn-groupsvc.com | IN | MX |
|
120s | (00:02:00) |
— end —
Money Mule Recruitment
Money Mule Recruitment Is Still Alive
Has Been Around for About 7 Years
Scammers Are Constantly Looking At Every Avenue in other words OPPORTUNITY for NEW RECRUITS
Identity Theft – Help Us Defend Against This
Identity Theft Continues To Be A Growing Problem
The New Face of Cybercrime – Organized Crime 2.0
Cyber Crime Toolkits Explained –
Cyber Crime Toolkits Explained
Tech Support Being Offer – UnBelievable
By Openflows.org
Tech Consultant Jesse Hirsh
Scan CEO Alan Paller On Strategy Against Cyber Crime
Alan Paller On Cyber Defenses
Source: VPR.COM
Cyber Crime Growing Global Threat
Consumer Awareness
Source: VOANEWSS
How Cybercriminals Steal Money
Consumer Awareness
The Case of the Cyber Criminal
The Case of the Cyber Criminal
A techie spy and his cunning crew are out to get your personal information. Stop them cold by proving you’re ready to protect yourself online.
http://www.onguardonline.gov/
A DISPATCHER AND ACCOUNT PAYABLE CLERK IS NEEDED
The Purpose of This Post Is To ALERT You That The Job You Are About To APPLY TO or May Have Applied For or is CONSIDERING APPLYING FOR Is Fraudulent. A LEGITIMATE COMPANY IDENTITY HAS BEEN STOLEN OR A BOGUS ONE CREATED
These job postings are an attempt to lure you into cashing counterfeit checks and have you wire funds via Western Union or MoneyGram -Essentially You Become A Money or RePackage Mule
Money Mule Explained
Read All About This at Symantec Corp.
A dispatcher and account payable clerk is needed.We pay good salary and take good care of our worker.apply now.
- Compensation: salary
- Telecommuting is ok.
- This is a part-time job.
- This is an internship job
- OK to highlight this job opening for persons with disabilities
- Principals only. Recruiters, please don’t contact this job poster.
- Please, no phone calls about this job!
- Please do not contact job poster about other services, products or commercial interests.