Canadian Pharmacy Spam – http://getrxmedicationshere.com

Buying Precription Drugs Online May Be Dangerous
– Consumer Alert –
Drug Enforcement Administration Says

warning1

National Association of Boards of Pharmacy (NABP)

Warning


“The Canadian Pharmacy, Canadian/European Pharmacy”, “Canadian Healthcare” and “US Drugstore” are brands of one of the most disgusting illegal online pharmacy group well organized CRIMINAL OPERATION of all times. “GREED” is the driving force behind this operation. Don’t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don’t care that you will endanger your health by taking those dangerous counterfeit drugs.

Behind The Online Pharmacy

Today a shadowy, transnational network of illicit drug manufacturers, traders, doctors, Web site operators, spammers and criminals makes up the online pharmacy world.

Buying Medication Online Can Be Safe

There are many options out there when it comes to buying medication online. We have looked at websites after websites. Some sites feature offshore pharmacies that do not require a prior prescription. Others feature licensed pharmacies that do require a prescription from your doctor.
Before making a purchase that can effect your health, we strongly recommend that you consult your physician & DO NOT self-medicate. Ordering medication online can be a safe, money-saving experience. When done through licensed online pharmacies that require a prescription, you can be assured that the medication you get is exactly what you need to treat your ailments.

All_of your favorite Rx~Medications are available at your_Fingertips!
Browse_Our Selection Today –> http://getrxmedicationshere.com

Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
68.142.207.170 United States (Sunnyvale)* Whois Google DNSStuff Urgentmessage.org
207.115.20.185 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:
From Conrad Bonner Sat Sep 5 10:59:37 2009
X-Apparently- Sat, 05 Sep 2009 10:58:16 -0700
Return-Path:
X-YahooFilteredBulk: 109.87.19.108
X-YMailISG: H.phxEAWLDtB_eE2RNGcrV7bll_Bl_DUObhczWx9uct6I5p3PQMWm4WLoEaPqrp80fVAB8_099N8nselcFG2Y86RwWtYMCtUvyL8tuAj0FH5MkgLAxwDk19fBlqhCwVA5EiAkhbBgDqEh_xVIFI.E12Rw4QdmdG9.kmLz1iyiAGfAl_TFzugyJuLU6g8pX5PmJINB9K_0hTmREpxFCk5JRp5rRid7cs7FPN.ZGz_6uh3dDsQwMuw24MluI0gpkPG7QIJWjJT43_E2NQmkpwoS90yOkKk40W5uUX.pj.0R6Ab1_YIVdd6WbWfpgtsiRfMUE4j6.mD84PJxvjE4hz7hte5_IpTLoiVZyEsMeMhQvvb01Cxh8E3nvl1fQ–
X-Originating-IP: [109.87.19.108]
Authentication-Results: mta121.sbc.mail.re3.yahoo.com from=software-solutions.co.nz;
domainkeys=neutral (no sig); from=software-solutions.co.nz; dkim=neutral (no sig)
Received: from 109.87.19.108 (EHLO flpi183.prodigy.net) (207.115.20.185)
by mta121.sbc.mail.re3.yahoo.com with SMTP; Sat, 05 Sep 2009 10:58:14 -0700
X-Header-NoReverseIP: IP.name.lookup.failed[109.87.19.108]
X-Originating-IP: [109.87.19.108]
Received: from w6agsd3 ([109.87.19.108])
by flpi183.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n85Hutix024595;
Sat, 5 Sep 2009 10:58:08 -0700
Message-ID: <000701ca2e52$a20da680$627e0f72@software-solutions.co.nz>
Reply-To: “Conrad Bonner” <conradbonnerxj@software-solutions.co.nz>
From: “Conrad Bonner”
To:
Subject: PharmacyOnNet sells Phentermin, Ambien …
Date: Sat, 05 Sep 2009 10:59:37 -0700
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Office Outlook, Build 11.0.5510
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1807
Content-Length: 139

Address lookup

canonical name getrxmedicationshere.com.
aliases
addresses 60.12.166.135

Domain Whois record

Queried whois.internic.net with “dom getrxmedicationshere.com“…

   Domain Name: GETRXMEDICATIONSHERE.COM
   Registrar: GUANGZHOU MING YANG INFORMATION TECHNOLOGY CO., LTD
   Whois Server: whois.hupo.com
   Referral URL: http://www.hupo.com
   Name Server: NS1.ACTCTICNS.COM
   Name Server: NS2.ACTCTICNS.COM
   Name Server: NS3.BRIILOVENS.COM
   Name Server: NS4.BRIILOVENS.COM
   Name Server: NS5.84GNK.COM
   Name Server: NS6.84GNK.COM
   Status: clientDeleteProhibited
   Status: clientTransferProhibited
   Updated Date: 02-sep-2009
   Creation Date: 22-aug-2009
   Expiration Date: 22-aug-2010

>>> Last update of whois database: Sat, 05 Sep 2009 19:46:04 UTC <<<

Queried whois.hupo.com with “getrxmedicationshere.com“…

Domain Name: getrxmedicationshere.com

Registrant Contact:
  CAI JIASHAN
  CAI JIASHAN
  Email:chouren_n@yeah.net
  Tel:+86.051283254915
  Fax:+86.051283254915
  HUAXINLU24
  KunShan, JiangSu, CN 215309

Administrative Contact:
  CAI JIASHAN
  CAI JIASHAN
  Email:chouren_n@yeah.net
  Tel:+86.051283254915
  Fax:+86.051283254915
  HUAXINLU24
  KunShan, JiangSu, CN 215309

Technical Contact:
  CAI JIASHAN
  CAI JIASHAN
  Email:chouren_n@yeah.net
  Tel:+86.051283254915
  Fax:+86.051283254915
  HUAXINLU24
  KunShan, JiangSu, CN 215309

Billing Contact:
  CAI JIASHAN
  CAI JIASHAN
  Email:chouren_n@yeah.net
  Tel:+86.051283254915
  Fax:+86.051283254915
  HUAXINLU24
  KunShan, JiangSu, CN 215309

Domain Status:clientTransferProhibited,clientDeleteProhibited

Domain servers in listed order:
  ns1.actcticns.com
  ns2.actcticns.com
  ns3.briilovens.com
  ns4.briilovens.com
  ns5.84gnk.com
  ns6.84gnk.com

Registration Date:2009-08-22 14:51:42
Expireation Date:2010-08-22 14:51:42

Network Whois record

Queried whois.apnic.net with “60.12.166.135“…

inetnum:      60.12.0.0 - 60.12.255.255
netname:      UNICOM-ZJ
descr:        China Unicom Zhejiang province network
descr:        China Unicom
country:      CN
admin-c:      CH1302-AP
tech-c:       JQ16-AP
remarks:      service provider
mnt-by:       APNIC-HM
mnt-lower:    MAINT-CNCGROUP-ZJ
mnt-routes:   MAINT-CNCGROUP-RR
status:       ALLOCATED PORTABLE
remarks:      -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks:      This object can only be updated by APNIC hostmasters.
remarks:      To update this object, please contact APNIC
remarks:      hostmasters and include your organisation's account
remarks:      name in the subject line.
remarks:      -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed:      hm-changed@apnic.net 20040629
changed:      hm-changed@apnic.net 20060124
changed:      hm-changed@apnic.net 20090507
changed:      hm-changed@apnic.net 20090508
source:       APNIC

route:        60.12.0.0/16
descr:        CNC Group CHINA169 Zhejiang Province Network
country:      CN
origin:       AS4837
mnt-by:       MAINT-CNCGROUP-RR
changed:      abuse@cnc-noc.net 20060118
source:       APNIC

person:       ChinaUnicom Hostmaster
nic-hdl:      CH1302-AP
e-mail:       abuse@chinaunicom.cn
address:      No.21,Jin-Rong Street
address:      Beijing,100140
address:      P.R.China
phone:        +86-10-66259940
fax-no:       +86-10-66259764
country:      CN
changed:      abuse@chinaunicom.cn 20090408
mnt-by:       MAINT-CNCGROUP
source:       APNIC

person:       Jianhuaq Qian
nic-hdl:      JQ16-AP
e-mail:       chenrenhai@china-netcom.com
address:      No 1,Hangzhou University Road,Hangzhou, Zhejiang,China
phone:        +86-571-28868063
fax-no:       +86-571-28868069
country:      CN
changed:      wuhong@china-netcom.com 20050421
mnt-by:       MAINT-CNCGROUP-ZJ
source:       APNIC

DNS records

DNS query for 135.166.12.60.in-addr.arpa returned an error from the server: NameError

name class type data time to live
getrxmedicationshere.com IN SOA
server: ns.getrxmedicationshere.com
email: admin.getrxmedicationshere.com
serial: 2006123101
refresh: 300
retry: 300
expire: 86400
minimum ttl: 300
300s (00:05:00)
getrxmedicationshere.com IN A 60.12.166.135 300s (00:05:00)

— end —

Address lookup

lookup failed 109.87.19.108
Could not find a domain name corresponding to this IP address.

Domain Whois record

Don’t have a domain name for which to get a record

Network Whois record

Queried whois.ripe.net with “-B 109.87.19.108“…

% Information related to '109.87.16.0 - 109.87.31.255'

inetnum:        109.87.16.0 - 109.87.31.255
netname:        TRIOLAN
descr:          TRIOLAN, Simferopol
country:        UA
admin-c:        KID3-RIPE
admin-c:        MICH-RIPE
tech-c:         MICH-RIPE
status:         ASSIGNED PA
remarks:        INFRA-AW
mnt-by:         BOMASC-MNT
changed:        boma@bi.com.ua 20090902
source:         RIPE

person:         Konstantin I Doljenko
address:        pr-t Frunze, 26
address:        310007, Kharkov
address:        Ukraine
phone:          +380 572 179727
fax-no:         +380 572 191510
e-mail:         boma@bi.com.ua
nic-hdl:        KID3-RIPE
mnt-by:         BOMASC-MNT
changed:        boma@bi.com.ua 20040218
source:         RIPE

person:         Mihail A.Vovk
address:        Ukraine, Kyiv
phone:          +380667206611
e-mail:         mich@michael.com.ua
nic-hdl:        MICH-RIPE
mnt-by:         MICH-MNT
notify:         mich@michael.com.ua
changed:        mich@michael.com.ua 20060105
source:         RIPE

% Information related to '109.86.0.0/15AS13188'

route:          109.86.0.0/15
descr:          TRIOLAN
descr:          Triple Play Services
descr:          Ukraine
origin:         AS13188
mnt-by:         BOMASC-MNT
changed:        boma@bi.com.ua 20090820
source:         RIPE

% Information related to '109.87.16.0/20AS13188'

route:          109.87.16.0/20
descr:          TRIOLAN, Simferopol
descr:          Triple Play Services
descr:          Ukraine
origin:         AS13188
mnt-by:         BOMASC-MNT
changed:        boma@bi.com.ua 20090902
source:         RIPE

DNS records

DNS query for 108.19.87.109.in-addr.arpa returned an error from the server: NameError

No records to display

Traceroute

Tracing route to 109.87.19.108 [109.87.19.108]