Canadian Pharmacy Spam – allthebestatyourfingertips.com

Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
68.142.207.168 United States (Sunnyvale)* Whois Google DNSStuff Urgentmessage.org
216.100.91.6 United States (Orange)* Whois Google DNSStuff Urgentmessage.org
207.115.20.18 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

O0rder all your Favorite_Medications 0nline!
Browse Our Selection Today! -> http://allthebestatyourfingertips.com

From Ronda Morris Fri Sep 25 03:12:24 2009
X-Apparently- Fri, 25 Sep 2009 10:12:31 -0700
Return-Path: <rondamorris_yd@resmed.com.au>
X-YahooFilteredBulk: 216.100.91.6
X-YMailISG: ZVkpBtYWLDus6bK24BEw6wDy_AzUhvchxxHMuHz21VQUqtGfsANfuLs.2DrfYv8SQ_.OW0gp2CS2_DQktjA5dCJib.x99JuqYcpWnJdFhd6qmHUcY66BcQhLyycD2L7VfG_5KYUTHkjblhzFg3bIuYGfCDe9N0PsK18E7ZWY9OWUj36o.eLTkiGEmG7KDBtMJVaJDc4gIu_61lL1_ruYoay2WWX4aDE8enWF0Pr6Kis68CfceTNFahxRmJZVPTVd2.WVj9NsyQj3yNiaEaz4t8whmFSMGNqJ92rNfIom9qKMCQmzKLkEZn.g4Al_91376LnsQAfZTaYhIBWG2E3G
X-Originating-IP: [216.100.91.6]
Authentication-Results: mta111.sbc.mail.gq1.yahoo.com from=resmed.com.au; domainkeys=neutral (no sig); from=resmed.com.au; dkim=neutral (no sig)
Received: from 216.100.91.6 (EHLO flph260.prodigy.net) (207.115.20.18)
by mta111.sbc.mail.gq1.yahoo.com with SMTP; Fri, 25 Sep 2009 10:12:31 -0700
X-Header-NoReverseIP: IP.name.lookup.failed[216.100.91.6]
X-Originating-IP: [216.100.91.6]
Received: from jwu8wm2 ([216.100.91.6])
by flph260.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n8PHAsnV003600;
Fri, 25 Sep 2009 10:12:27 -0700
Message-ID: <000701ca3dc8$ad9272d0$627e09ca@resmed.com.au>
Reply-To: “Ronda Morris” <rondamorris_yd@resmed.com.au>
From: “Ronda Morris” <rondamorris_yd@resmed.com.au>
To: ,
Subject: Get RxMed without a Doctor online!
Date: Fri, 25 Sep 2009 03:12:24 -0700 championrxsource.com
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
X-Priority: 3
X-MSMail-Priority: Normal
X-Mailer: Microsoft Office Outlook, Build 11.0.5510
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2800.1807
Content-Length: 118

Address lookup

canonical name allthebestatyourfingertips.com.
aliases
addresses 60.12.166.154
Domain Whois record

Queried whois.internic.net with “dom allthebestatyourfingertips.com”…

Domain Name: ALLTHEBESTATYOURFINGERTIPS.COM
Registrar: CHINA SPRINGBOARD INC.
Whois Server: whois.namerich.cn
Referral URL: http://www.namerich.cn
Name Server: NS1.UBR34NS.COM
Name Server: NS2.UBR34NS.COM
Name Server: NS3.BIDOKODJU.COM
Name Server: NS4.BIDOKODJU.COM
Name Server: NS5.HOSTLIFE45.COM
Name Server: NS6.HOSTLIFE45.COM
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 22-sep-2009
Creation Date: 16-sep-2009
Expiration Date: 16-sep-2010

>>> Last update of whois database: Fri, 25 Sep 2009 21:54:58 UTC <<<
Queried whois.namerich.cn with “allthebestatyourfingertips.com”…

; This data is provided by China Springboard Inc.
; for information purposes, and to assist persons obtaining information
; about or related to domain name registration records.
; China Springboard Inc. does not guarantee its accuracy.
; By submitting a WHOIS query, you agree that you will use this data
; only for lawful purposes and that, under no circumstances, you will
; use this data to
; 1) allow, enable, or otherwise support the transmission of mass
; unsolicited, commercial advertising or solicitations via E-mail
; (spam); or
; 2) enable high volume, automated, electronic processes that apply
; to this WHOIS server.
; These terms may be changed without prior notice.
; By submitting this query, you agree to abide by this policy.

DomainName : allthebestatyourfingertips.com

RSP: China Springboard Inc.
URL: http://www.namerich.cn

Name Server………………….NS5.HOSTLIFE45.COM
Name Server………………….NS1.UBR34NS.COM
Name Server………………….NS2.UBR34NS.COM
Name Server………………….NS4.BIDOKODJU.COM
Name Server………………….NS6.HOSTLIFE45.COM
Name Server………………….NS3.BIDOKODJU.COM
Status………………………clientTransferProhibited
Status………………………clientDeleteProhibited
Creation Date ………………2009-09-16
Expiration Date ……………..2010-09-16
Last Update Date ……………2009-09-23

Registrant ID ……………….V-X-58522-14215
Registrant Name ……………..ZHANG WENQI
Registrant Organization ………ZHANG WENQI
Registrant Address …………..JIAOTONGLU16
Registrant City………………DL
Registrant Province/State …….LN
Registrant Country Code ………CN
Registrant Postal Code ……….116049
Registrant Phone Number ………+86.041128805621
Registrant Fax ………………+86.041128805621
Registrant Email …………….kaokga@126.com

Administrative ID ……………V-X-58522-14215
Administrative Name ………….ZHANG WENQI
Administrative Organization …..ZHANG WENQI
Administrative Address ……….JIAOTONGLU16
Administrative City…………..DL
Administrative Province/State …LN
Administrative Country Code …..CN
Administrative Postal Code ……116049
Administrative Phone Number …..+86.041128805621
Administrative Fax …………..+86.041128805621
Administrative Email …………kaokga@126.com

Billing ID ………………….V-X-58522-14215
Billing Name ………………..ZHANG WENQI
Billing Organization …………ZHANG WENQI
Billing Address ……………..JIAOTONGLU16
Billing City…………………DL
Billing Province/State ……….LN
Billing Country Code …………CN
Billing Postal Code ………….116049
Billing Phone Number …………+86.041128805621
Billing Fax …………………+86.041128805621
Billing Email ……………….kaokga@126.com

Technical ID ………………..V-X-58522-14215
Technical Name ………………ZHANG WENQI
Technical Organization………..ZHANG WENQI
Technical Address ……………JIAOTONGLU16
Technical City……………….DL
Technical Province/State………LN
Technical Country Code ……….CN
Technical Postal Code ………..116049
Technical Phone Number ……….+86.041128805621
Technical Fax ……………….+86.041128805621
Technical Email ……………..kaokga@126.com

; Please register your domains at
; http://www.namerich.cn
Network Whois record

Queried whois.apnic.net with “60.12.166.154”…

inetnum: 60.12.0.0 – 60.12.255.255
netname: UNICOM-ZJ
descr: China Unicom Zhejiang province network
descr: China Unicom
country: CN
admin-c: CH1302-AP
tech-c: JQ16-AP
remarks: service provider
mnt-by: APNIC-HM
mnt-lower: MAINT-CNCGROUP-ZJ
mnt-routes: MAINT-CNCGROUP-RR
status: ALLOCATED PORTABLE
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
remarks: This object can only be updated by APNIC hostmasters.
remarks: To update this object, please contact APNIC
remarks: hostmasters and include your organisation’s account
remarks: name in the subject line.
remarks: -+-+-+-+-+-+-+-+-+-+-+-++-+-+-+-+-+-+-+-+-+-+-+-+-+-+
changed: hm-changed@apnic.net 20040629
changed: hm-changed@apnic.net 20060124
changed: hm-changed@apnic.net 20090507
changed: hm-changed@apnic.net 20090508
source: APNIC

route: 60.12.0.0/16
descr: CNC Group CHINA169 Zhejiang Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060118
source: APNIC

person: ChinaUnicom Hostmaster
nic-hdl: CH1302-AP
e-mail: abuse@chinaunicom.cn
address: No.21,Jin-Rong Street
address: Beijing,100140
address: P.R.China
phone: +86-10-66259940
fax-no: +86-10-66259764
country: CN
changed: abuse@chinaunicom.cn 20090408
mnt-by: MAINT-CNCGROUP
source: APNIC

person: Jianhuaq Qian
nic-hdl: JQ16-AP
e-mail: chenrenhai@china-netcom.com
address: No 1,Hangzhou University Road,Hangzhou, Zhejiang,China
phone: +86-571-28868063
fax-no: +86-571-28868069
country: CN
changed: wuhong@china-netcom.com 20050421
mnt-by: MAINT-CNCGROUP-ZJ
source: APNIC
DNS records

DNS query for 154.166.12.60.in-addr.arpa returned an error from the server: NameError

name class type data time to live
allthebestatyourfingertips.com IN A 60.12.166.154 162s (00:02:42)
— end —