Canadian Pharmacy Spam – flowersuffix.com

Buying Precription Drugs Online May Be Dangerous
– Consumer Alert –
Drug Enforcement Administration Says

warning1

National Association of Boards of Pharmacy (NABP)

Warning

“The Canadian Pharmacy, Canadian/European Pharmacy”, “Canadian Healthcare” and “US Drugstore” are brands of one of the most disgusting illegal online pharmacy group well organized CRIMINAL OPERATION of all times. “GREED” is the driving force behind this operation. Don’t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don’t care that you will endanger your health by taking those dangerous counterfeit drugs.

Behind The Online Pharma

Today a shadowy, transnational network of illicit drug manufacturers, traders, doctors, Web site operators, spammers and criminals makes up the online pharma world.

Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
66.168.189.23 United States (Columbus)* Whois Google DNSStuff Urgentmessage.org
207.115.36.163 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

From Stewart Thurman Tue Jul 21 19:18:13 2009
Return-Path:
Authentication-Results: mta124.sbc.mail.re3.yahoo.com from=ebay.ca; domainkeys=neutral (no sig); from=ebay.ca; dkim=neutral (no sig)
Received: from 66.168.189.23 (EHLO nlpi149.prodigy.net) (207.115.36.163)
by mta124.sbc.mail.re3.yahoo.com with SMTP; Tue, 21 Jul 2009 19:21:50 -0700
Received: from wuhlju2 (static.unknown.charter.com [66.168.189.23] (may be forged))
by nlpi149.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n6M2LIQ2019630;
Tue, 21 Jul 2009 21:21:45 -0500
Message-ID: <000701ca0a72$aa470110$d828ea62@ebay.ca>
Reply-To: “Stewart Thurman” <stewartthurman_rl@ebay.ca>
From: “Stewart Thurman”  <stewartthurman_rl@ebay.ca>
To: , ,
Subject: Do you want it to be longer and stronger in bed?
Date: Tue, 21 Jul 2009 21:18:13 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
Content-Length: 142

Address lookup

canonical name flowersuffix.com.
aliases
addresses 203.93.208.86
218.75.144.6
60.191.239.150

Domain Whois record

Queried whois.internic.net with “dom flowersuffix.com“…

   Domain Name: FLOWERSUFFIX.COM
   Registrar: CHINA SPRINGBOARD INC.
   Whois Server: whois.namerich.cn
   Referral URL: http://www.namerich.cn
   Name Server: NS1.SPEAKSMELL.COM
   Name Server: NS2.SPEAKSMELL.COM
   Name Server: NS3.STANDBRIEF.COM
   Name Server: NS4.STANDBRIEF.COM
   Name Server: NS5.B9T.RU
   Name Server: NS6.B9T.RU
   Status: ok
   Updated Date: 20-jul-2009
   Creation Date: 20-jul-2009
   Expiration Date: 20-jul-2010

Last update of whois database: Wed, 22 Jul 2009 12:08:38 UTC <<<

Queried whois.namerich.cn with “flowersuffix.com“…

 DomainName : flowersuffix.com

RSP: China Springboard Inc.
URL: http://www.namerich.cn      

Name Server......................NS1.SPEAKSMELL.COM
Name Server......................NS6.B9T.RU
Name Server......................NS3.STANDBRIEF.COM
Name Server......................NS2.SPEAKSMELL.COM
Name Server......................NS5.B9T.RU
Name Server......................NS4.STANDBRIEF.COM
Status...........................ok
Creation  Date ..................2009-07-20
Expiration Date .................2010-07-20
Last Update  Date ...............2009-07-20

Registrant ID ...................V-X-59716-16698
Registrant Name .................JIANG HUA
Registrant Organization .........JIANG HUA
Registrant Address ..............HUANMEILU82
Registrant City..................CZ
Registrant Province/State .......JS
Registrant Country Code .........CN
Registrant Postal Code ..........300009
Registrant Phone Number .........+86.059176147512
Registrant Fax ..................+86.059176147512
Registrant Email ................afwhndsg@126.com

Administrative ID ...............V-X-59716-16698
Administrative Name .............JIANG HUA
Administrative Organization .....JIANG HUA
Administrative Address ..........HUANMEILU82
Administrative City..............CZ
Administrative Province/State ...JS
Administrative Country Code .....CN
Administrative Postal Code ......300009
Administrative Phone Number .....+86.059176147512
Administrative Fax ..............+86.059176147512
Administrative Email ............afwhndsg@126.com

Billing ID ......................V-X-59716-16698
Billing Name ....................JIANG HUA
Billing Organization ............JIANG HUA
Billing Address .................HUANMEILU82
Billing City.....................CZ
Billing Province/State ..........JS
Billing Country Code ............CN
Billing Postal Code .............300009
Billing Phone Number ............+86.059176147512
Billing Fax .....................+86.059176147512
Billing Email ...................afwhndsg@126.com

Technical ID ....................V-X-59716-16698
Technical Name ..................JIANG HUA
Technical Organization...........JIANG HUA
Technical Address ...............HUANMEILU82
Technical City...................CZ
Technical Province/State.........JS
Technical Country Code ..........CN
Technical Postal Code ...........300009
Technical Phone Number ..........+86.059176147512
Technical Fax ...................+86.059176147512
Technical Email .................afwhndsg@126.com

; Please register your domains at
; http://www.namerich.cn

Network Whois record

Queried whois.apnic.net with “203.93.208.86“…

inetnum:      203.93.0.0 - 203.93.255.255
netname:      UNICOM-CN
descr:        China Unicom IP network
descr:        China Unicom
country:      CN
admin-c:      CH1302-AP
tech-c:       CH1302-AP
mnt-by:       APNIC-HM
mnt-lower:    MAINT-CNCGROUP
mnt-routes:   MAINT-CNCGROUP-RR
status:       ALLOCATED PORTABLE
changed:      hm-changed@apnic.net 20040116
changed:      hm-changed@apnic.net 20060124
changed:      hm-changed@apnic.net 20090507
changed:      hm-changed@apnic.net 20090508
source:       APNIC

person:       ChinaUnicom Hostmaster
nic-hdl:      CH1302-AP
e-mail:       abuse@chinaunicom.cn
address:      No.21,Jin-Rong Street
address:      Beijing,100140
address:      P.R.China
phone:        +86-10-82993155
fax-no:       +86-10-82993144
country:      CN
changed:      abuse@chinaunicom.cn 20090408
mnt-by:       MAINT-CNCGROUP
source:       APNIC

DNS records

DNS query for 86.208.93.203.in-addr.arpa returned an error from the server: NameError

name class type data time to live
flowersuffix.com IN A 218.75.144.6 10800s (03:00:00)
flowersuffix.com IN A 60.191.239.150 10800s (03:00:00)
flowersuffix.com IN A 203.93.208.86 10800s (03:00:00)

— end —

SmartFilter Category: Malicious Sites, Spam URLs
Make Category Suggestions
Namerservers on IP: dns2.wishlate.com
dns3.nightmodest.com
ns0.peakswell.com
ns0.saidcold.com
ns1.112911.org
ns1.adorenew.com
ns1.againseat.com
ns1.alertspring.com
ns1.andfell.com
ns1.ba43.com
ns1.beautybounce.com
ns1.bedplain.com
ns1.bedsing.com
ns1.boughtpose.com
ns1.breadprize.com
ns1.busyorder.com
ns1.cameegg.com
ns1.chartflat.in
ns1.cu28.com
ns1.cutfigure.com
ns1.decentbusy.com
ns1.deluxecrop.com
ns1.evertasty.com
ns1.exceptexotic.com
ns1.expertlofty.com
ns1.fabledmaxi.com
ns1.famousloyal.com
ns1.farkeep.com
ns1.fewwhole.com
ns1.flattry.com
ns1.flypair.com
ns1.fromview.com
ns1.galoresize.com
ns1.gonemade.com
ns1.growten.com
ns1.hadagree.ru
ns1.hadwalk.com
ns1.ku17.net
ns1.letterwant.com
ns1.listwere.com
ns1.mainhumble.com
ns1.me15.net
ns1.moralgrand.com
ns1.noticezap.com
ns1.nu23.com
ns1.okhalf.com
ns1.ownlate.com
ns1.peakswell.com
ns1.pickcool.in
ns1.pill35.net
ns1.poundanger.com
ns1.putanger.com
ns1.re25.org
ns1.relaxtoward.com
ns1.rockflair.com
ns1.saidcold.com
ns1.sawplump.com
ns1.sendbusy.com
ns1.sidebeauty.com
ns1.skinglad.com
ns1.teethoxygen.com
ns1.thosekept.com
ns1.towardlegend.in
ns1.tubeold.com
ns1.typetruck.com
ns1.via99.org
ns1.watchnorth.com
ns1.wooddoes.in
ns1.yardaware.com
ns1.yearbusy.com
ns2.112911.org
ns2.282715.com
ns2.ablenumber.com
ns2.againseat.com
ns2.aglowpaint.com
ns2.alertspring.com
ns2.andfell.com
ns2.aromafish.com
ns2.beautybounce.com
ns2.bedplain.com
ns2.bedsing.com
ns2.beforebegin.com
ns2.bitsshape.com
ns2.bluesign.in
ns2.boughtdeluxe.com
ns2.boughtpose.com
ns2.breezyget.com
ns2.bu15.net
ns2.chartflat.in
ns2.clockbright.com
ns2.clothetrack.com
ns2.coateach.com
ns2.coatfather.com
ns2.cu28.com
ns2.cutfigure.com
ns2.cutheart.com
ns2.deluxecrop.com
ns2.desiresweet.com
ns2.directlisten.com
ns2.doctorstill.com

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.