Canadian Pharmacy – pathjoyful.com

Buying Prescription Drugs Online Scam Alert 1
May Be Dangerous
Says Drug Enforcement Administration

DEA Logo - Buying Proscription Drugs

National Association of Boards of Pharmacy (NABP)

Warning

“The Canadian Pharmacy, Canadian/European Pharmacy”, “Canadian Healthcare” and “US Drugstore” are brands of one of the most disgusting illegal online pharmacy group well organized CRIMINAL OPERATION of all times. “GREED” is the driving force behind this operation. Don’t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don’t care that you will endanger your health by taking those dangerous counterfeit drugs.

Behind The Online Pharmacy

Today a shadowy, transnational network of illicit drug manufacturers, traders, doctors, Web site operators, spammers and criminals makes up the online pharmacy world.

Buying Medication Online Can Be Safe

There are many options out there when it comes to buying medication online. We have looked at websites after websites. Some sites feature offshore pharmacies that do not require a prior prescription. Others feature licensed pharmacies that do require a prescription from your doctor.
Before making a purchase that can effect your health, we strongly recommend that you consult your physician & DO NOT self-medicate. Ordering medication online can be a safe, money-saving experience. When done through licensed online pharmacies that require a prescription, you can be assured that the medication you get is exactly what you need to treat your ailments.

Also See ThreatChaos


Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
207.115.20.181 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
110.172.0.198 Japan* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

From Annette Macdonald Sat Jun 6 22:07:48 2009
Return-Path:
Authentication-Results: mta129.sbc.mail.re3.yahoo.com from=holts.co.uk; domainkeys=neutral (no sig); from=holts.co.uk; dkim=neutral (no sig)
Received: from 207.115.20.181 (EHLO flpi179.prodigy.net) (207.115.20.181)
by mta129.sbc.mail.re3.yahoo.com with SMTP; Sat, 06 Jun 2009 22:07:48 -0700
Received: from vhnpx42 (0.198.net4.hinocatv.ne.jp [110.172.0.198])
by flpi179.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n5757h3C021495;
Sat, 6 Jun 2009 22:07:46 -0700
Message-ID: <000701c9e72d$e6bd25b0$4a37416a@holts.co.uk>
Reply-To: “Annette Macdonald”    a_macdonald_hi@holts.co.uk
From: “Annette Macdonald”   a_macdonald_hi@holts.co.uk
To: ScamFraudAlert
Subject: Lose weight fast Here!
Date: Sun, 07 Jun 2009 00:07:48 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
Content-Length: 128

An Incredible Canadian_Pharmacy is available at your_Fingertips!
NO_Doctor_Needed! Click There -> http://pathjoyful.com

Address lookup

canonical name pathjoyful.com.
aliases
addresses 58.17.3.41
60.191.239.181
203.93.208.86

Domain Whois record

Queried whois.internic.net with “dom pathjoyful.com“…

Domain Name: PATHJOYFUL.COM
Registrar: XIN NET TECHNOLOGY CORPORATION
Whois Server: whois.paycenter.com.cn
Referral URL: http://www.xinnet.com
Name Server: NS1.FELTTWENTY.COM
Name Server: NS2.FELTTWENTY.COM
Name Server: SP151.DELETEDNS.COM
Name Server: SP152.DELETEDNS.COM
Name Server: SP153.DELETEDNS.COM
Name Server: SP154.DELETEDNS.COM
Status: ok
Updated Date: 04-jun-2009
Creation Date: 03-jun-2009
Expiration Date: 03-jun-2010

Last update of whois database: Sun, 07 Jun 2009 22:53:18 UTC

Queried whois.paycenter.com.cn with “pathjoyful.com“…

Domain Name : pathjoyful.com
PunnyCode : pathjoyful.com
Registrant:
Organization : TIANCHUNLIN
Name : TIANCHUNLING
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039

Administrative Contact:
Name : TIANCHUNLING
Organization : TIANCHUNLIN
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039
Phone Number : 86-0373-61255412
Fax : 86-0373-61255412
Email : TIANCHUNLIN@139.COM

Technical Contact:
Name : TIANCHUNLING
Organization : TIANCHUNLIN
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039
Phone Number : 86-0373-61255412
Fax : 86-0373-61255412
Email : TIANCHUNLIN@139.COM

Billing Contact:
Name : TIANCHUNLING
Organization : TIANCHUNLIN
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039
Phone Number : 86-0373-61255412
Fax : 86-0373-61255412
Email : TIANCHUNLIN@139.COM

Network Whois record

Queried whois.apnic.net with “58.17.3.41“…

inetnum: 58.17.3.32 – 58.17.3.47
netname: CHAOREN-CAFE
country: CN
descr: Superman Internet Cafe
admin-c: CH444-AP
tech-c: CH444-AP
status: ASSIGNED NON-PORTABLE
changed: wujiawei@china-netcom.com 20070427
mnt-by: MAINT-CNCGROUP-JX
source: APNIC

route: 58.17.0.0/17
descr: CNC Group CHINA169 Jiangxi Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060728
source: APNIC

route: 58.17.0.0/17
descr: CNCGroup JiangXi province network
country: CN
origin: AS9929
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20050218
changed: hm-changed@apnic.net 20050331
source: APNIC

person: CNCGroup Hostmaster
nic-hdl: CH444-AP
e-mail: abuse@cnc-noc.net
address: No.156,Fu-Xing-Men-Nei Street,
address: Beijing,100031,P.R.China
phone: +86-10-82993155
fax-no: +86-10-82993144
country: CN
changed: abuse@cnc-noc.net 20041220
mnt-by: MAINT-CNCGROUP
source: APNIC

DNS records

DNS query for 41.3.17.58.in-addr.arpa returned an error from the server: NameError

name class type data time to live
pathjoyful.com IN A 203.93.208.86 3600s (01:00:00)
pathjoyful.com IN A 60.191.239.181 3600s (01:00:00)
pathjoyful.com IN A 58.17.3.41 3600s (01:00:00)