Header Analysis
The following IP addresses were extracted from your headers:
| IP Address | Probable Country | Additional Info | |||
| 12.161.202.90 | United States (Neffs)* | Whois | DNSStuff | Urgentmessage.org | |
| 207.115.36.137 | United States (Richardson)* | Whois | DNSStuff | Urgentmessage.org | |
| * The last IP listed is usually the originating IP address | |||||
From Brendan Collier Sun May 31 05:31:41 2009
Return-Path:
Authentication-Results: mta143.sbc.mail.mud.yahoo.com from=dck.com.ar; domainkeys=neutral (no sig); from=dck.com.ar; dkim=neutral (no sig)
Received: from 12.161.202.90 (EHLO nlpi123.prodigy.net) (207.115.36.137)
by mta143.sbc.mail.mud.yahoo.com with SMTP; Sat, 30 May 2009 21:31:35 -0700
Received: from 5s9gclp ([12.161.202.90])
by nlpi123.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n4V4VGXY028689;
Sat, 30 May 2009 23:31:33 -0500
Message-ID: <000701c9e1eb$c0242c10$627e2ad2@dck.com.ar>
Reply-To: “Brendan Collier”
From: “Brendan Collier”
To: ,
Subject: great deals goin on
Date: Sun, 31 May 2009 08:31:41 -0400
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
Content-Length: 127
An Incredible Canadian Pharmacy is available at your_Fingertips!
N0 Doctor_Needed! Click Here -> http://motherany.com
Header Analysis
The following IP addresses were extracted from your headers:
| IP Address | Probable Country | Additional Info | |||
| 66.147.35.66 | United States (Davenport)* | Whois | DNSStuff | Urgentmessage.org | |
| 207.115.20.48 | United States (Richardson)* | Whois | DNSStuff | Urgentmessage.org | |
| * The last IP listed is usually the originating IP address | |||||
From Amparo Savage Fri May 29 11:46:23 2009
Return-Path:
Authentication-Results: mta102.sbc.mail.re3.yahoo.com from=blm.co.uk; domainkeys=neutral (no sig); from=blm.co.uk; dkim=neutral (no sig)
Received: from 66.147.35.66 (EHLO flph261.prodigy.net) (207.115.20.48)
by mta102.sbc.mail.re3.yahoo.com with SMTP; Fri, 29 May 2009 22:35:52 -0700
Received: from tcdb592 (nsc66.147.35-66.newsouth.net [66.147.35.66])
by flph261.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n4U5ZbWA013298;
Fri, 29 May 2009 22:35:52 -0700
Message-ID: <000701c9e08d$c3fa2150$627e2c7a@blm.co.uk>
Reply-To: “Amparo Savage” a.savage_go@blm.co.uk
From: “Amparo Savage” a.savage_go@blm.co.uk
To: ScamFraudAlert
Subject: Canadian Rx Medications to the rescue
Date: Fri, 29 May 2009 11:46:23 -0700
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
Content-Length: 127
An Incredible Canadian Pharmacy is available at your_Fingertips!
N0 Doctor_Needed! Click Here -> http://motherany.com

Canadian Pharmacy – the worst Internet fraud problem today. These criminals steal identities and credit card details from unsuspecting customers, to use later to pay for tens of thousands of domain name registrations. Don’t be fooled.
Similar sites to this are listed in the spam trap report at
http://rss.uribl.com/ns/plumbold_com.html
Use complainterator.com to generate complaints to the registrars, and include a link to this page for evidence.Posted at 05/31/2009-12:43:06 AM by pharmalert, Experienced Reviewer
“Canadian Pharmacy” is a flagrant criminal operation that keeps opening thousands and thousands new sites promoting the same old illegal pharmaceuticals. You seldom see greedier scumbags than these criminals. They don’t care how much damage they cause to innocent people as long as they get all they want. No matter if people get seriously ill after taking their fake drugs, or lose their money after giving over their credit card details. This kind of scammers would be happy to sell their own mother for a quick buck (if they only had one).
It’s always better to stay far away from here and similar sites altogether. There’s no one on the face of earth who would gain by this scam but the criminals behind it, and possibly the poor schmucks who send all the spam for them. They think they are safe, but one day the tide will turn…
See evidence of fraud:
http://www.spamtrackers.eu/wiki/index.php/Canadian_Pharmacy
Read about the affiliate program responsible for spamming this brand:
http://www.spamtrackers.eu/wiki/index.php/GlavmedPosted at 05/30/2009-08:56:12 PM by Nodus, Experienced Reviewer , View profile [ Reputation score: 9 / 9 ]
Address lookup
| canonical name | www.motherany.com. |
| aliases | |
| addresses | 58.17.3.41 60.191.239.181 61.191.63.150 203.93.208.86 |
Domain Whois record
Queried whois.internic.net with “dom motherany.com“…
Domain Name: MOTHERANY.COM Registrar: XIN NET TECHNOLOGY CORPORATION Whois Server: whois.paycenter.com.cn Referral URL: http://www.xinnet.com Name Server: NS1.PLUMBOLD.COM Name Server: NS2.PLUMBOLD.COM Name Server: NS3.MORALFLAIR.COM Name Server: NS4.MORALFLAIR.COM Status: ok Updated Date: 27-may-2009 Creation Date: 25-may-2009 Expiration Date: 25-may-2010 >>> Last update of whois database: Sun, 31 May 2009 18:19:27 UTC <<<
Queried whois.paycenter.com.cn with “motherany.com“…
Domain Name : motherany.com PunnyCode : motherany.com Registrant: Organization : LIUJIARONG Name : LIUJIARONG Address : JIULONGLU256 City : shaoyangshi Province/State : hunansheng Country : china Postal Code : 422064 Administrative Contact: Name : LIUJIARONG Organization : LIUJIARONG Address : JIULONGLU256 City : shaoyangshi Province/State : hunansheng Country : china Postal Code : 422064 Phone Number : 86-0739-75912657 Fax : 86-0739-75912657 Email : LIUJIARONG@263.COM Technical Contact: Name : LIUJIARONG Organization : LIUJIARONG Address : JIULONGLU256 City : shaoyangshi Province/State : hunansheng Country : china Postal Code : 422064 Phone Number : 86-0739-75912657 Fax : 86-0739-75912657 Email : LIUJIARONG@263.COM Billing Contact: Name : LIUJIARONG Organization : LIUJIARONG Address : JIULONGLU256 City : shaoyangshi Province/State : hunansheng Country : china Postal Code : 422064 Phone Number : 86-0739-75912657 Fax : 86-0739-75912657 Email : LIUJIARONG@263.COM
Network Whois record
Queried whois.apnic.net with “58.17.3.41“…
inetnum: 58.17.3.32 - 58.17.3.47 netname: CHAOREN-CAFE country: CN descr: Superman Internet Cafe admin-c: CH444-AP tech-c: CH444-AP status: ASSIGNED NON-PORTABLE changed: wujiawei@china-netcom.com 20070427 mnt-by: MAINT-CNCGROUP-JX source: APNIC route: 58.17.0.0/17 descr: CNC Group CHINA169 Jiangxi Province Network country: CN origin: AS4837 mnt-by: MAINT-CNCGROUP-RR changed: abuse@cnc-noc.net 20060728 source: APNIC route: 58.17.0.0/17 descr: CNCGroup JiangXi province network country: CN origin: AS9929 mnt-by: MAINT-CNCGROUP-RR changed: abuse@cnc-noc.net 20050218 changed: hm-changed@apnic.net 20050331 source: APNIC person: CNCGroup Hostmaster nic-hdl: CH444-AP e-mail: abuse@cnc-noc.net address: No.156,Fu-Xing-Men-Nei Street, address: Beijing,100031,P.R.China phone: +86-10-82993155 fax-no: +86-10-82993144 country: CN changed: abuse@cnc-noc.net 20041220 mnt-by: MAINT-CNCGROUP source: APNIC
DNS records
DNS query for 41.3.17.58.in-addr.arpa returned an error from the server: NameError
| name | class | type | data | time to live | |
| http://www.motherany.com | IN | A | 60.191.239.181 | 3600s | (01:00:00) |
| http://www.motherany.com | IN | A | 61.191.63.150 | 3600s | (01:00:00) |
| http://www.motherany.com | IN | A | 203.93.208.86 | 3600s | (01:00:00) |
| http://www.motherany.com | IN | A | 58.17.3.41 | 3600s | (01:00:00) |
| motherany.com | IN | A | 58.17.3.41 | 3600s | (01:00:00) |
| motherany.com | IN | A | 61.191.63.150 | 3600s | (01:00:00) |
| motherany.com | IN | A | 203.93.208.86 | 3600s | (01:00:00) |
| motherany.com | IN | A | 60.191.239.181 | 3600s | (01:00:00) |
— end —












From Stanley Garza Sat May 23 18:12:49 2009 







