Canadian Pharmacy – pathjoyful.com

Buying Prescription Drugs Online Scam Alert 1
May Be Dangerous
Says Drug Enforcement Administration

DEA Logo - Buying Proscription Drugs

National Association of Boards of Pharmacy (NABP)

Warning

“The Canadian Pharmacy, Canadian/European Pharmacy”, “Canadian Healthcare” and “US Drugstore” are brands of one of the most disgusting illegal online pharmacy group well organized CRIMINAL OPERATION of all times. “GREED” is the driving force behind this operation. Don’t let them fool you. They will never send you any genuine drugs. If they ever send anything at all, it may consist of literally anything from sugar to wall plaster, and they certainly don’t care that you will endanger your health by taking those dangerous counterfeit drugs.

Behind The Online Pharmacy

Today a shadowy, transnational network of illicit drug manufacturers, traders, doctors, Web site operators, spammers and criminals makes up the online pharmacy world.

Buying Medication Online Can Be Safe

There are many options out there when it comes to buying medication online. We have looked at websites after websites. Some sites feature offshore pharmacies that do not require a prior prescription. Others feature licensed pharmacies that do require a prescription from your doctor.
Before making a purchase that can effect your health, we strongly recommend that you consult your physician & DO NOT self-medicate. Ordering medication online can be a safe, money-saving experience. When done through licensed online pharmacies that require a prescription, you can be assured that the medication you get is exactly what you need to treat your ailments.

Also See ThreatChaos


Header Analysis

The following IP addresses were extracted from your headers:

IP Address Probable Country Additional Info
207.115.20.181 United States (Richardson)* Whois Google DNSStuff Urgentmessage.org
110.172.0.198 Japan* Whois Google DNSStuff Urgentmessage.org
* The last IP listed is usually the originating IP address

Here is the text you submitted, with the IP addresses highlighted:

From Annette Macdonald Sat Jun 6 22:07:48 2009
Return-Path:
Authentication-Results: mta129.sbc.mail.re3.yahoo.com from=holts.co.uk; domainkeys=neutral (no sig); from=holts.co.uk; dkim=neutral (no sig)
Received: from 207.115.20.181 (EHLO flpi179.prodigy.net) (207.115.20.181)
by mta129.sbc.mail.re3.yahoo.com with SMTP; Sat, 06 Jun 2009 22:07:48 -0700
Received: from vhnpx42 (0.198.net4.hinocatv.ne.jp [110.172.0.198])
by flpi179.prodigy.net (8.13.8 inb ipv6 jeff0203/8.13.8) with SMTP id n5757h3C021495;
Sat, 6 Jun 2009 22:07:46 -0700
Message-ID: <000701c9e72d$e6bd25b0$4a37416a@holts.co.uk>
Reply-To: “Annette Macdonald”    a_macdonald_hi@holts.co.uk
From: “Annette Macdonald”   a_macdonald_hi@holts.co.uk
To: ScamFraudAlert
Subject: Lose weight fast Here!
Date: Sun, 07 Jun 2009 00:07:48 -0500
MIME-Version: 1.0
Content-Type: text/plain;
format=flowed;
charset=”windows-1250″
reply-type=original
Content-Transfer-Encoding: 7bit
Content-Length: 128

An Incredible Canadian_Pharmacy is available at your_Fingertips!
NO_Doctor_Needed! Click There -> http://pathjoyful.com

Address lookup

canonical name pathjoyful.com.
aliases
addresses 58.17.3.41
60.191.239.181
203.93.208.86

Domain Whois record

Queried whois.internic.net with “dom pathjoyful.com“…

Domain Name: PATHJOYFUL.COM
Registrar: XIN NET TECHNOLOGY CORPORATION
Whois Server: whois.paycenter.com.cn
Referral URL: http://www.xinnet.com
Name Server: NS1.FELTTWENTY.COM
Name Server: NS2.FELTTWENTY.COM
Name Server: SP151.DELETEDNS.COM
Name Server: SP152.DELETEDNS.COM
Name Server: SP153.DELETEDNS.COM
Name Server: SP154.DELETEDNS.COM
Status: ok
Updated Date: 04-jun-2009
Creation Date: 03-jun-2009
Expiration Date: 03-jun-2010

Last update of whois database: Sun, 07 Jun 2009 22:53:18 UTC

Queried whois.paycenter.com.cn with “pathjoyful.com“…

Domain Name : pathjoyful.com
PunnyCode : pathjoyful.com
Registrant:
Organization : TIANCHUNLIN
Name : TIANCHUNLING
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039

Administrative Contact:
Name : TIANCHUNLING
Organization : TIANCHUNLIN
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039
Phone Number : 86-0373-61255412
Fax : 86-0373-61255412
Email : TIANCHUNLIN@139.COM

Technical Contact:
Name : TIANCHUNLING
Organization : TIANCHUNLIN
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039
Phone Number : 86-0373-61255412
Fax : 86-0373-61255412
Email : TIANCHUNLIN@139.COM

Billing Contact:
Name : TIANCHUNLING
Organization : TIANCHUNLIN
Address : daxuenanlu29
City : xinxiangshi
Province/State : henansheng
Country : china
Postal Code : 453039
Phone Number : 86-0373-61255412
Fax : 86-0373-61255412
Email : TIANCHUNLIN@139.COM

Network Whois record

Queried whois.apnic.net with “58.17.3.41“…

inetnum: 58.17.3.32 – 58.17.3.47
netname: CHAOREN-CAFE
country: CN
descr: Superman Internet Cafe
admin-c: CH444-AP
tech-c: CH444-AP
status: ASSIGNED NON-PORTABLE
changed: wujiawei@china-netcom.com 20070427
mnt-by: MAINT-CNCGROUP-JX
source: APNIC

route: 58.17.0.0/17
descr: CNC Group CHINA169 Jiangxi Province Network
country: CN
origin: AS4837
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20060728
source: APNIC

route: 58.17.0.0/17
descr: CNCGroup JiangXi province network
country: CN
origin: AS9929
mnt-by: MAINT-CNCGROUP-RR
changed: abuse@cnc-noc.net 20050218
changed: hm-changed@apnic.net 20050331
source: APNIC

person: CNCGroup Hostmaster
nic-hdl: CH444-AP
e-mail: abuse@cnc-noc.net
address: No.156,Fu-Xing-Men-Nei Street,
address: Beijing,100031,P.R.China
phone: +86-10-82993155
fax-no: +86-10-82993144
country: CN
changed: abuse@cnc-noc.net 20041220
mnt-by: MAINT-CNCGROUP
source: APNIC

DNS records

DNS query for 41.3.17.58.in-addr.arpa returned an error from the server: NameError

name class type data time to live
pathjoyful.com IN A 203.93.208.86 3600s (01:00:00)
pathjoyful.com IN A 60.191.239.181 3600s (01:00:00)
pathjoyful.com IN A 58.17.3.41 3600s (01:00:00)

SpamFilter IPs – TrustedSource.org (NameServers)

 

SmartFilter Category: Spam URLs
Make Category Suggestions
Namerservers on IP: dns1.carryfit.com
dns1.drivefabled.com
dns1.grewmile.com
dns1.relaxrange.com
dns1.towardhardy.com
dns1.trendysit.com
dns1.varystart.com
dns1.wentcrisp.com
dns1.winnertrue.com
dns2.angerboat.com
dns2.carryfit.com
dns2.createwere.com
dns2.dadfour.com
dns2.dreamylot.com
dns2.drivefabled.com
dns2.hasfeet.com
dns2.headraise.com
dns2.pridenature.com
dns2.shallcoat.com
dns2.tangyprime.com
dns2.towardhardy.com
dns2.trendysit.com
dns2.varystart.com
dns3.drivefabled.com
dns3.headraise.com
dns3.noticematch.com
dns3.nounstudy.com
dns3.relaxrange.com
dns3.shallcoat.com
dns3.tangyprime.com
dns3.towardhardy.com
dns3.varystart.com
dns4.coursethey.com
dns4.createwere.com
dns4.dadfour.com
dns4.dreamylot.com
dns4.greatyule.com
dns4.headraise.com
dns4.joyfulthin.com
dns4.relaxrange.com
dns4.shallcoat.com
dns4.sliporgan.com
dns4.towardhardy.com
dns4.trendysit.com
dns4.varystart.com
dns4.winnertrue.com
host2.soonplay.com
host4.soonplay.com
ns1.activeinch.com
ns1.boatabove.com
ns1.breezycorner.com
ns1.cookmulti.com
ns1.croppast.com
ns1.dimplechair.com
ns1.dimplechaste.com
ns1.donewater.com
ns1.earlytwenty.com
ns1.feetreal.com
ns1.ideazeal.com
ns1.listenflower.com
ns1.plainable.com
ns1.posewill.com
ns1.powerhardy.com
ns1.silverwe.com
ns1.strongwisdom.com
ns1.toophrase.com
ns1.wheredone.com
ns2.activeinch.com
ns2.callold.com
ns2.cookmulti.com
ns2.croppast.com
ns2.cuddlyhumble.com
ns2.dimplechair.com
ns2.dimplechaste.com
ns2.earlytwenty.com
ns2.listenflower.com
ns2.lucidsoon.com
ns2.mightexcept.com
ns2.posewill.com
ns2.resttrust.com
ns2.ropemeant.com
ns2.toophrase.com
ns2.wheredone.com
ns3.activeinch.com
ns3.atbread.com
ns3.bandwater.com
ns3.briefdesire.com
ns3.burnround.com
ns3.callold.com
ns3.cookmulti.com
ns3.cuddlyhumble.com
ns3.dimplechair.com
ns3.dimplechaste.com
ns3.earlytwenty.com
ns3.fizzdecent.com
ns3.listenflower.com
ns3.lucidsoon.com
ns3.posewill.com
ns3.quietyet.com
ns3.radiothan.com

Canadian Health & Care Mall – pharmacyyy.com

Buying Precription Drugs Online May Be Dangerous
– Consumer Alert –
Drug Enforcement Administration Says

warning1

National Association of Boards of Pharmacy (NABP)

Pharmacyyy

Address lookup

canonical name pharmacyyy.com
aliases
addresses 24.232.33.129
Domain Whois record

Queried whois.internic.net with “dom pharmacyyy.com”…

Domain Name: PHARMACYYY.COM
Registrar: XIAMEN ENAME NETWORK TECHNOLOGY CORPORATION LIMITED DBA ENAME CORP
Whois Server: whois.ename.com
Referral URL: http://www.ename.com
Name Server: NS1.GREATAGEHEALTH.COM
Name Server: NS2.PHARMSSTOREJOBS.NET
Status: clientDeleteProhibited
Status: clientTransferProhibited
Updated Date: 12-may-2009
Creation Date: 20-sep-2008
Expiration Date: 20-sep-2009

>>> Last update of whois database: Tue, 19 May 2009 07:42:56 UTC <<<
Queried whois.ename.com with “pharmacyyy.com”…

Domain Name : pharmacyyy.com
Registrant Contact Information :
王淼
王淼
zyiekjdd@yahoo.com.cn
成都抚琴西路12号, 610000
tel: +86 89898799
fax: +86 89898799

Administrative Contact Information :
王淼
王淼
zyiekjdd@yahoo.com.cn
成都抚琴西路12号, 610000
tel: +86 89898799
fax: +86 89898799

Technical Contact Information :
王淼
王淼
zyiekjdd@yahoo.com.cn
成都抚琴西路12号, 610000
tel: +86 89898799
fax: +86 89898799

Billing Contact Information :
王淼
王淼
zyiekjdd@yahoo.com.cn
成都抚琴西路12号, 610000
tel: +86 89898799
fax: +86 89898799

Status :
clientDeleteProhibited
clientTransferProhibited

Domain Name Server :
ns1.greatagehealth.com
ns2.pharmsstorejobs.net

Registration Date :2008-9-21
Expiration Date : 2009-9-21

For more information, please go to http://whois.ename.com.

Network Whois record

Queried whois.lacnic.net with “24.232.33.129”…

inetnum: 24.232.33.128/25
status: reallocated
owner: Cablevision S.A.
ownerid: AR-CASA24-LACNIC
address: Bonpland 1745
address: Buenos Aires, Capital Federal 1414
country: AR
owner-c: PL319-ARIN
created: 19990929
changed: 19990929
inetnum-up: 24.232/16
source: ARIN-HISTORIC

nic-hdl: PL319-ARIN
person: Patricio Latini
e-mail: platini@FIBERTEL.COM.AR
address: Fibertel TCI
address: Bonpland 1745
address: Buenos Aires, Capital Federal 1414
country: AR
phone: 54-11-4778-6567
source: ARIN-HISTORIC

% whois.lacnic.net accepts only direct match queries.
% Types of queries are: POCs, ownerid, CIDR blocks, IP
% and AS numbers.

DNS records

name class type data time to live
pharmacyyy.com IN SOA
server: ns1.pharmacyyy.com
email: admin.pharmacyyy.com
serial: 2005000000
refresh: 600
retry: 900
expire: 1209600
minimum ttl: 43200
600s (00:10:00)
pharmacyyy.com IN NS ns1.pharmacyyy.com 600s (00:10:00)
pharmacyyy.com IN NS ns3.pharmacyyy.com 600s (00:10:00)
pharmacyyy.com IN NS ns2.pharmacyyy.com 600s (00:10:00)
pharmacyyy.com IN MX
preference: 10
exchange: mail.pharmacyyy.com
600s (00:10:00)
pharmacyyy.com IN A 24.232.33.129 600s (00:10:00)
129.33.232.24.in-addr.arpa IN PTR ol129-33.fibertel.com.ar 3600s (01:00:00)

 

Associated Harvesters
62.163.32.108 | H
62.195.253.27 | H
82.49.177.232 | HS
89.35.131.56 | H

 

 

 

 

Sample Spam URLs & Keywords Posted From 66.45.252.82
Domain: http://www.pillhh.com
URL: http://www.pillhh.com/
Keywords: xenical online
Domain: http://www.pillhh.com
URL: http://www.pillhh.com/
Keywords: http://www.pillhh.com/
Domain: http://www.pillgg.com
URL: http://www.pillgg.com/
Keywords: hydrocodone ibs
Domain: http://www.pillgg.com
URL: http://www.pillgg.com/
Keywords: http://www.pillgg.com/
Domain: http://www.ffdoctor.com
URL: http://www.ffdoctor.com/
Keywords: order xanax online
Domain: http://www.ffdoctor.com
URL: http://www.ffdoctor.com/
Keywords: http://www.ffdoctor.com/
Domain: http://www.pharmacyyy.com
URL: http://www.pharmacyyy.com/
Keywords: order xanax online
Domain: http://www.pharmacyyy.com
URL: http://www.pharmacyyy.com/
Keywords: http://www.pharmacyyy.com/
Domain: http://www.rrpill.com
URL: http://www.rrpill.com/
Keywords: buy vicodin
Domain: http://www.rrpill.com
URL: http://www.rrpill.com/
Keywords: http://www.rrpill.com/
Domain: http://www.doctoruu.com
URL: http://www.doctoruu.com/
Keywords: buy soma
Domain: http://www.doctoruu.com
URL: http://www.doctoruu.com/
Keywords: http://www.doctoruu.com/
Domain: http://www.bepharmacy.com
URL: http://www.bepharmacy.com/
Keywords: tramadol on line
Domain: http://www.bepharmacy.com
URL: http://www.bepharmacy.com/
Keywords: http://www.bepharmacy.com/
Domain: http://www.doctorbe.com
URL: http://www.doctorbe.com/
Keywords: hydrocodone overnight
66.45.252.82’s User Agent Strings
Lynx 8.99
Example Messages Sent From 66.45.252.82
From: Info Team <service@listerhill.com>
Subject: Dear Customer, 
From: Microsoft.com <security@microsoft.com>
Subject: Microsoft Windows – Security Fix 
From: nationalagency11@netscape.net <nationalagency15@ne
Subject: You are a Lottery winner. 
From: nedlotto <sjjgs@walla.com>
Subject: YOUR EMAIL HAS WON A LOTERY   

http://www.projecthoneypot.org/ip_66.45.252.82