Canadian Pharmacy Spam – grewsix.com

Buying Precription Drugs Online May Be Dangerous
– Consumer Alert –
Drug Enforcement Administration Says

warning1

National Association of Boards of Pharmacy (NABP)

Warning

“The Canadian Pharmacy, Canadian/European Pharmacy”, “Canadian Healthcare” and “US Drugstore” are brands of one of the most disgusting illegal online pharmacy group well organized CRIMINAL OPERATION of all times. “GREED” is the driving force behind this operation. Don’t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don’t care that you endanger you health by taking those dangerous counterfeit drugs.

Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
129.10.63.40 United States (Boston)* Whois Google DNSStuff Urgentmessage.org
207.115.36.121 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

From Terry G. Parks Fri Jun 26 10:09:27 2009
Return-Path:
Authentication-Results: mta107.sbc.mail.re3.yahoo.com from=vdc.lv; domainkeys=neutral (no sig); from=vdc.lv; dkim=neutral (no sig)
Received: from 129.10.63.40 (EHLO nlpi107.prodigy.net) (207.115.36.121)
by mta107.sbc.mail.re3.yahoo.com with SMTP; Fri, 26 Jun 2009 10:09:22 -0700
Received: from 329a0d2 ([129.10.63.40])
by nlpi107.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n5QH9Euq004296;
Fri, 26 Jun 2009 12:09:21 -0500
Message-ID:  <000701c9f680$dcd89cc0$4a37416a@vdc.lv>
Reply-To: “Terry G. Parks”  <tg_parkszh@vdc.lv>
From: “Terry G. Parks”
To:
Subject: eye opening
Date: Fri, 26 Jun 2009 12:09:27 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
Content-Length: 135

An Incredible Canadian Pharmacy is available at your Fingertips!
N0~Doctor~Needed! Browse our site Today! -> http://grewsix.com

Address lookup

An Incredible Canadian Pharmacy is available at your Fingertips!
NO `Doctor `Needed! Browse our site Today! -> http://camebear.com

canonical name grewsix.com. aliases
addresses 218.75.144.6
60.191.221.117
60.191.239.153
61.191.191.241
119.39.238.2
203.93.208.86

Domain Whois record

Queried whois.internic.net with “dom grewsix.com“…

   Domain Name: GREWSIX.COM
   Registrar: CHINA SPRINGBOARD INC.
   Whois Server: whois.namerich.cn
   Referral URL: http://www.namerich.cn
   Name Server: NS1.RUNMOTHER.IN
   Name Server: NS2.RUNMOTHER.IN
   Name Server: NS3.LISTENFACE.RU
   Name Server: NS4.LISTENFACE.RU
   Name Server: NS5.WESUCH.PL
   Name Server: NS6.WESUCH.PL
   Status: ok
   Updated Date: 22-jun-2009
   Creation Date: 22-jun-2009
   Expiration Date: 22-jun-2010

>>> Last update of whois database: Sun, 28 Jun 2009 15:51:35 UTC <<<

Queried whois.namerich.cn with “grewsix.com“…

; This data is provided by China Springboard Inc.
; for information purposes, and to assist persons obtaining information
; about or related to domain name registration records.
; China Springboard Inc. does not guarantee its accuracy.
; By submitting a WHOIS query, you agree that you will use this data
; only for lawful purposes and that, under no circumstances, you will
; use this data to
; 1) allow, enable, or otherwise support the transmission of mass
; unsolicited, commercial advertising or solicitations via E-mail
; (spam); or
; 2) enable high volume, automated, electronic processes that apply
; to this WHOIS server.
; These terms may be changed without prior notice.
; By submitting this query, you agree to abide by this policy.

 DomainName : grewsix.com

RSP: China Springboard Inc.
URL: http://www.namerich.cn      

Name Server......................NS4.LISTENFACE.RU
Name Server......................NS2.RUNMOTHER.IN
Name Server......................NS6.WESUCH.PL
Name Server......................NS1.RUNMOTHER.IN
Name Server......................NS5.WESUCH.PL
Name Server......................NS3.LISTENFACE.RU
Status...........................ok
Creation  Date ..................2009-06-22
Expiration Date .................2010-06-22
Last Update  Date ...............2009-06-22

Registrant ID ...................V-X-57955-13465
Registrant Name .................ZHAO LET
Registrant Organization .........ZHAO LEI
Registrant Address ..............JIEFANGLU19
Registrant City..................DL
Registrant Province/State .......LN
Registrant Country Code .........CN
Registrant Postal Code ..........116019
Registrant Phone Number .........+86.04112880527
Registrant Fax ..................+86.04112880527
Registrant Email ................mklao9he@126.com

Administrative ID ...............V-X-57955-13465
Administrative Name .............ZHAO LET
Administrative Organization .....ZHAO LEI
Administrative Address ..........JIEFANGLU19
Administrative City..............DL
Administrative Province/State ...LN
Administrative Country Code .....CN
Administrative Postal Code ......116019
Administrative Phone Number .....+86.04112880527
Administrative Fax ..............+86.04112880527
Administrative Email ............mklao9he@126.com

Billing ID ......................V-X-57955-13465
Billing Name ....................ZHAO LET
Billing Organization ............ZHAO LEI
Billing Address .................JIEFANGLU19
Billing City.....................DL
Billing Province/State ..........LN
Billing Country Code ............CN
Billing Postal Code .............116019
Billing Phone Number ............+86.04112880527
Billing Fax .....................+86.04112880527
Billing Email ...................mklao9he@126.com

Technical ID ....................V-X-57955-13465
Technical Name ..................ZHAO LET
Technical Organization...........ZHAO LEI
Technical Address ...............JIEFANGLU19
Technical City...................DL
Technical Province/State.........LN
Technical Country Code ..........CN
Technical Postal Code ...........116019
Technical Phone Number ..........+86.04112880527
Technical Fax ...................+86.04112880527
Technical Email .................mklao9he@126.com

; Please register your domains at
; http://www.namerich.cn

Network Whois record

Queried whois.apnic.net with “218.75.144.6“…

inetnum:      218.75.128.0 - 218.75.159.255
netname:      CHINANET-HN-CD
country:      CN
descr:        CHINANET-HN changde node network
descr:        hunan Telecom
admin-c:      CHC8-AP
tech-c:       CH636-AP
status:       ALLOCATED NON-PORTABLE
changed:      ipaddress@hntelecom.net.cn 20050823
mnt-by:       MAINT-CHINANET-HN
mnt-lower:    MAINT-CHINANET-HN-CD
source:       APNIC

role:         CHINANET HuNan ChangDe
address:      The middle of Wuling Street,Changde 415000
country:      CN
phone:        +86 736 7229427
fax-no:       +86 736 7267027
e-mail:       abuse.cd@2118.com.cn
trouble:      send spam reports to spam.cd@2118.com.cn
trouble:      and abuse reports to abuse.cd@2118.com.cn
trouble:      Please include detailed information and
trouble:      times in UTC
admin-c:      CM1092-AP
tech-c:       CM1092-AP
nic-hdl:      CHC8-AP
notify:       abuse.cd@2118.com.cn
mnt-by:       MAINT-CHINANET-HN-CD
changed:      ipaddress@hntelecom.net.cn 20050818
source:       APNIC

role:         CHINANET HUNAN
address:      No.1 TuanJie road,ChangSha,Hunan 410005
country:      CN
phone:        +86 731 4792092
fax-no:       +86 731 4792007
e-mail:       abuse.szx@2118.com.cn
trouble:      send spam reports to spam.szx@2118.com.cn
trouble:      and abuse reports to abuse.szx@2118.com.cn
trouble:      Please include detailed information and
trouble:      times in UTC
admin-c:      CH632-AP
tech-c:       CS499-AP
nic-hdl:      CH636-AP
mnt-by:       MAINT-CHINANET-HN
changed:      ipaddress@hntelecom.net.cn 20050816
source:       APNIC

DNS records

DNS query for 6.144.75.218.in-addr.arpa returned an error from the server: NameError

name class type data time to live
grewsix.com IN A 203.93.208.86 10800s (03:00:00)
grewsix.com IN A 60.191.221.117 10800s (03:00:00)
grewsix.com IN A 60.191.239.153 10800s (03:00:00)
grewsix.com IN A 61.191.191.241 10800s (03:00:00)
grewsix.com IN A 218.75.144.6 10800s (03:00:00)
grewsix.com IN A 119.39.238.2 10800s (03:00:00)

xxxxxxxxxx

sharepolite.com
luckyown.com
raincool.com
pathtotal.com
shareproper.com
rightthin.com
zapblack.com
verycuddly.com
offront.com
railactive.com
seekersmiles.com
windowdouble.com
bottomvanish.com
twentyparent.com
sailnotice.com
airproper.com
howheld.com
talkown.com
againnoon.com
minutewood.com
thatcost.com
onthick.com
allthough.com
grewsix.com
heardzest.com
lovingbehind.com
shellyou.com
amtreat.com
wouldground.com
gardenguess.com
wrotemotion.com
legacyshall.com
stateequate.com
beatsshe.com
humanemy.com
camebear.com
rainthree.com
chieftype.com
abovegray.com
deluxeparent.com
centerthen.com
cowzip.com
plumlegend.com
heartlong.com
expectjust.com
causejewel.com
cowwhose.com
simpleinvent.com
streamput.com
pamperthree.com
legendvisit.com
blue-admin.com
via-grashop.com
99-22.com
luckyyour.com
prizefor.com
objectlead.com
awardfelt.com
workenough.com
motiontasty.com
caringwow.com
eagerthin.com
degreeproper.com
recordweight.com
eagerbuild.com
jewelspread.com
shellsmiles.com
caringhigh.com
nosewife.com
serveseemly.com
stoodeight.com
fizzdry.com
99-33.com
80-30.com

One thought on “Canadian Pharmacy Spam – grewsix.com

Leave a reply to Scrub Cancel reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.