Canadian Pharmacy Spam – spendzap.com

Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
72.165.59.77 United States (Denver)* Whois Google DNSStuff Urgentmessage.org
207.115.20.125 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

From Elsie Sheridan Wed Jun 17 09:42:42 2009
Return-Path: sheridan_ns@chuv.hospvd.ch
Authentication-Results: mta122.sbc.mail.re2.yahoo.com from=chuv.hospvd.ch; domainkeys=neutral (no sig); from=chuv.hospvd.ch; dkim=neutral (no sig)
Received: from 72.165.59.77 (EHLO flpd115.prodigy.net) (207.115.20.125)
by mta122.sbc.mail.re2.yahoo.com with SMTP; Wed, 17 Jun 2009 09:42:33 -0700
Received: from 09lgny3 (72-165-59-77.dia.static.qwest.net [72.165.59.77])
by flpd115.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n5HGgJ8Q013396;
Wed, 17 Jun 2009 09:42:31 -0700
Message-ID: <000701c9ef6a$a263c870$431333e2@chuv.hospvd.ch
Reply-To: “Elsie Sheridan” sheridan_ns@chuv.hospvd.ch
From: “Elsie Sheridan” sheridan_ns@chuv.hospvd.ch
To:ScamFraidAlert
Subject: The widest collection of finest medications online
Date: Wed, 17 Jun 2009 11:42:42 -0500

An Incredible Canadian Pharmacy is available at your Fingertips!
No Doctor Needed! Click Here! -> http://spendzap.com

Address lookup

canonical name spendzap.com.
aliases
addresses 203.93.208.86
58.17.3.41
60.191.221.123
60.191.239.166
61.191.191.241

Domain Whois record

Queried whois.internic.net with “dom spendzap.com“…

   Domain Name: SPENDZAP.COM
   Registrar: CHINA SPRINGBOARD INC.
   Whois Server: whois.namerich.cn
   Referral URL: http://www.namerich.cn
   Name Server: NS1.VITALMOVER.IN
   Name Server: NS2.VITALMOVER.IN
   Name Server: NS3.CREATETAKE.COM
   Name Server: NS4.CREATETAKE.COM
   Name Server: NS5.MOTIONSEEKER.PL
   Name Server: NS6.MOTIONSEEKER.PL
   Status: ok
   Updated Date: 15-jun-2009
   Creation Date: 15-jun-2009
   Expiration Date: 15-jun-2010

Last update of whois database: Thu, 18 Jun 2009 08:05:22 UTC <<<

Queried whois.namerich.cn with “spendzap.com“…

 DomainName : spendzap.com
RSP: China Springboard Inc.
URL: http://www.namerich.cn      

Name Server......................NS5.MOTIONSEEKER.PL
Name Server......................NS6.MOTIONSEEKER.PL
Name Server......................NS3.CREATETAKE.COM
Name Server......................NS2.VITALMOVER.IN
Name Server......................NS4.CREATETAKE.COM
Name Server......................NS1.VITALMOVER.IN
Status...........................ok
Creation  Date ..................2009-06-15
Expiration Date .................2010-06-15
Last Update  Date ...............2009-06-15

Registrant ID ...................V-X-57513-12920
Registrant Name .................ZHAO GUANG
Registrant Organization .........ZHAO GUANG
Registrant Address ..............HUANHUXILU413
Registrant City..................SJZ
Registrant Province/State .......HB
Registrant Country Code .........CN
Registrant Postal Code ..........050037
Registrant Phone Number .........+86.031158541214
Registrant Fax ..................+86.031158541214
Registrant Email ................nmaiucope@163.com

Administrative ID ...............V-X-57513-12920
Administrative Name .............ZHAO GUANG
Administrative Organization .....ZHAO GUANG
Administrative Address ..........HUANHUXILU413
Administrative City..............SJZ
Administrative Province/State ...HB
Administrative Country Code .....CN
Administrative Postal Code ......050037
Administrative Phone Number .....+86.031158541214
Administrative Fax ..............+86.031158541214
Administrative Email ............nmaiucope@163.com

Billing ID ......................V-X-57513-12920
Billing Name ....................ZHAO GUANG
Billing Organization ............ZHAO GUANG
Billing Address .................HUANHUXILU413
Billing City.....................SJZ
Billing Province/State ..........HB
Billing Country Code ............CN
Billing Postal Code .............050037
Billing Phone Number ............+86.031158541214
Billing Fax .....................+86.031158541214
Billing Email ...................nmaiucope@163.com

Technical ID ....................V-X-57513-12920
Technical Name ..................ZHAO GUANG
Technical Organization...........ZHAO GUANG
Technical Address ...............HUANHUXILU413
Technical City...................SJZ
Technical Province/State.........HB
Technical Country Code ..........CN
Technical Postal Code ...........050037
Technical Phone Number ..........+86.031158541214
Technical Fax ...................+86.031158541214
Technical Email .................nmaiucope@163.com

; Please register your domains at
; http://www.namerich.cn

Network Whois record

Queried whois.apnic.net with “203.93.208.86“…

inetnum:      203.93.0.0 - 203.93.255.255
netname:      UNICOM-CN
descr:        China Unicom IP network
descr:        China Unicom
country:      CN
admin-c:      CH1302-AP
tech-c:       CH1302-AP
mnt-by:       APNIC-HM
mnt-lower:    MAINT-CNCGROUP
mnt-routes:   MAINT-CNCGROUP-RR
status:       ALLOCATED PORTABLE
changed:      hm-changed@apnic.net 20040116
changed:      hm-changed@apnic.net 20060124
changed:      hm-changed@apnic.net 20090507
changed:      hm-changed@apnic.net 20090508
source:       APNIC

person:       ChinaUnicom Hostmaster
nic-hdl:      CH1302-AP
e-mail:       abuse@chinaunicom.cn
address:      No.21,Jin-Rong Street
address:      Beijing,100140
address:      P.R.China
phone:        +86-10-82993155
fax-no:       +86-10-82993144
country:      CN
changed:      abuse@chinaunicom.cn 20090408
mnt-by:       MAINT-CNCGROUP
source:       APNIC

DNS records

DNS query for 86.208.93.203.in-addr.arpa returned an error from the server: NameError

name class type data time to live
spendzap.com IN A 203.93.208.86 3600s (01:00:00)
spendzap.com IN A 58.17.3.41 3600s (01:00:00)
spendzap.com IN A 60.191.239.166 3600s (01:00:00)
spendzap.com IN A 60.191.221.123 3600s (01:00:00)
spendzap.com IN A 61.191.191.241 3600s (01:00:00)

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.