CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

SIRT(TM)

Spam Incident Reporting and Termination(TM) Squad

A global spam termination operation launched by CastleCops, the volunteer SIRT Squad is comprised of folks who report spam, investigate spam, and actively work on spam takedown and termination. SIRT is funded by CastleCops. Become a SIRT Squad terminator by reporting spam today!

[ How-To / FAQ ]

SIRT -> Confirmed Spam | Terminated Spam


evidence status: confirmed spam

HTTP Response
11 Jul, 2008
10:32:53
HTTP/1.1 200 OK
ID172792 (termination link)
TitleCanadian Health&Care Mall
Entry
SIRT Squad
Reporter
AlphaCentauri
Timestamp11 May, 2008 @ 04:42:32
Topic ID221572 - Read/respond to SIRT commentary.
Handler Note:
11 May, 2008
05:24:54
AlphaCentauri: ixflintere.com is one of the sites for the spam operation, "Canadian Health&Care Mall." This site and its spam are violating US law:
* It offers medications which may not be dispensed without a prescription, sometimes including Provigil and sometimes Valium, which are federal contolled substances, without requiring any prescription.
* Its site advertises generic versions of drugs like Viagra which are still under patent protection. Therefore, any generics are by definition counterfeit.
* Its site includes "certificates" claiming endorsement from Verisign, The "Canadian Pharmaceutical Association," The American Food and Drug Administration, and the "American Consumers Organization." All of these claims are outright falsehoods and violations of these agencies' trademarks in those cases in which such an organization actually exists. See also the BBB alert at http://www.bbbmwo.ca/commonreport.html?bid=1134034 regarding sister site My Canadian Pharmacy.
* Viewing satellite photos of the addresses it gives for the locations of its offices in Ontario and Louisiana show residential areas with no evidence of the existence of large buildings like those pictured on the "contact us" page of their website. The location of the warehouse in New Delhi, India is not precise enough for Google Maps to locate it and may be a nonexistent address. See http://spamtrackers.eu/wiki/index.php?title=Canadian_Health%26Care_Mall .
* The site displays a forged pharmacy license claiming to be issued by the state of Minnesota, USA. See http://spamtrackers.eu/wiki/index.php?title=Canadian_Health%26Care_Mall for a response from the Executive Director of the Minnesota Board of Pharmacy confirming that this is a forgery.
* It presents photos of people it claims are the physicians and pharmacists running their operation. At least some of these photos have been identified as stock photos from gettyimages.com. See http://spamtrackers.eu/wiki/index.php?title=Canadian_Health%26Care_Mall#Fake_Doctors
* There is doubt whether they actually sell anything; the website may only be collecting credit card numbers.
* It violates US law by offering drugs for sale to US residents that they may not legally import from pharmacies outside the US, and it offers them for sale without prescription. See http://www.fda.gov/oc/buyonline/faqs.html
* It offers for sale to US residents drugs that have not been approved by the FDA for sale in the US, like rimonabant.
* Its site offers for sale antiepileptic medications like Neurontin, Depakote, Lamictal, Trileptal, Keppra, and Topamax. Given the documented fact that even when spamvertised pharmacies deliver medications, they are subpotent or completely inactive about half the time, well-controlled epileptics taking these pills could have seizures while driving, causing an accident that could kill or seriously injure themselves or others, or at very least, lead to loss of their drivers' licenses.
* Its site offers for sale anticancer agents like casodex and nolvadex. Again, even when spamvertised pharmacies deliver medications, they are subpotent or completely inactive about half the time. The first indication people taking these medications would have that they are taking inactive drug would be recurrence of their cancers.
* Its site offers for sale antibiotics like Levaquin, Amoxicillin, Augmentin, Cipro, Zithromax, and Suprax. As Canadian Health&Care Mall does not even claim to offer overnight delivery, the only reason to order these drugs without prescription from a pharmacy that takes weeks to deliver (if it ever delivers at all), is to keep it at home "just in case." As most people are unaware that viral illnesses do not respond to antibiotics, are not aware of which organisms are most likely to cause which infections nor which antibiotics will cover those organisms, and do not have the ability to perform culture and sensitivity testing to confirm empiric treatment, this practice is highly likely to select for drug resistant organisms like CA-MRSA (community acquired methicillin resistant staphylococcus aureus, a particularly aggressive variety of staph that causes recurrent skin boils and has a 50% mortality when it causes pneumonia). As Cipro and Levaquin also have anti-tubercular activity, their use can select for drug resistant tuberculosis. Extended drug resistant mycobacterium tuberculosis (XDR-TB) is extracting nearly 100% mortality in South Africa at present.
* Its site offers for sale Coumadin, a narrow therapeutic index drug that requires very frequent blood testing to determing the correct dose, and continued monitoring to readjust dose due to interactions with food and other medications. The consequence of too much OR too little can be stroke or death.
* Its site offers for sale major antipsychotic medications like Seroquel, Abilify, and Risperdal. In addition to the fact that inactive drug could cause a patient to relapse, leading to consequences like loss of employment, even if these pills contain real medication and the correct quantity of real medication, they are only sold by prescription because patients taking them must be monitored for possible side effects like diabetes.
* Its site offers for sale the fertility medication clomid which carries the risk of multiple pregnancy, visual disturbances, and ovarian tumors, especially if used in excess.
* Their spam messages violate the CAN-SPAM act because they have forged "from" and "reply to" addresses, are sent from hijacked computers without the knowledge or permission of the owners, do not include valid information identifying who has sent the spam or how to opt out, and do not honor opt-out requests on their websites. Addresses are collected by bots spidering the internet for email addresses.
* Sites in this spam family (My Canadian Pharmacy, International "Legal" Rx, Canadian Health&Care Mall, Men+ Health, US Drugs, VIP Pharmacy/"Viagra+Cialis") utilize hijacked Unix servers using the tirqd trojan. See:
http://www.spamtrackers.eu/wiki/index.php?title=My_Canadian_Pharmacy#The_tirqd_Unix_infection
* In each case in which this reporter was able to contact the person named in the whois information in the domain registration of one of these sites, that person denied having any knowledge of his/her personal information being used to register any domains. Some victims had already been aware of fraudulent charges on their credit cards for domain registrations. See documentation at http://spamtrackers.eu/wiki/index.php?title=Fake_yambo_whois . In this case I spoke with the person whose name is used, and she confirmed she did not register the domain name.
* Spamwiki entry: http://spamtrackers.eu/wiki/index.php?title=Canadian_Health%26Care_Mall . SiteAdvisor reviews at http://www.siteadvisor.com/sites/ixflintere.com

ixflintere.com is located at IP address 218.3.160.2
but loads images from port 8080 of 79.135.167.10
http://79.135.167.10:8080/e/ch/images/theme.jpg

The following other previously used hijacked servers continue to have the images for these sites as well:
http://58.241.87.130:8080/e/ch/images/theme.jpg
http://84.253.77.6:8080/e/ch/images/theme.jpg
http://194.67.66.10:8080/e/ch/images/theme.jpg
Handler Note:
11 May, 2008
06:02:28
AlphaCentauri: Consumed following related reports:

[172794] http://ixflintere.com/e/ch/?action=xanax&t=testimonials
[172795] http://ixflintere.com/e/ch/?action=xanax&t=description
[172796] http://ixflintere.com/e/ch/?action=xanax
[172797] http://ixflintere.com/e/ch/?action=valium&t=testimonials
[172798] http://ixflintere.com/e/ch/?action=valium&t=description
[172799] http://ixflintere.com/e/ch/?action=valium
[172800] http://ixflintere.com/e/ch/?action=testimonials
[172801] http://ixflintere.com/e/ch/?action=secure
[172802] http://ixflintere.com/e/ch/?action=provigil&count=1&t=testimonials
[172803] http://ixflintere.com/e/ch/?action=provigil&count=1&t=description
[172804] http://ixflintere.com/e/ch/?action=provigil
[172805] http://ixflintere.com/e/ch/?action=misoprostol&count=1&t=testimonials
[172806] http://ixflintere.com/e/ch/?action=misoprostol&count=1&t=description
[172807] http://ixflintere.com/e/ch/?action=misoprostol
[172808] http://ixflintere.com/e/ch/?action=meridia&t=testimonials
[172809] http://ixflintere.com/e/ch/?action=meridia&t=description
[172810] http://ixflintere.com/e/ch/?action=meridia
[172811] http://ixflintere.com/e/ch/?action=license
[172812] http://ixflintere.com/e/ch/?action=index
[172813] http://ixflintere.com/e/ch/?action=howtoorder
[172814] http://ixflintere.com/e/ch/?action=genericviagra&count=1&t=testimonials
[172815] http://ixflintere.com/e/ch/?action=genericviagra&count=1&t=description
[172816] http://ixflintere.com/e/ch/?action=genericviagra
[172817] http://ixflintere.com/e/ch/?action=faq
[172818] http://ixflintere.com/e/ch/?action=delivery
[172819] http://ixflintere.com/e/ch/?action=contact
[172820] http://ixflintere.com/e/ch/?action=clomid&count=1&t=testimonials
[172821] http://ixflintere.com/e/ch/?action=clomid&count=1&t=description
[172822] http://ixflintere.com/e/ch/?action=clomid
[172823] http://ixflintere.com/e/ch/?action=awveri
[172824] http://ixflintere.com/e/ch/?action=awfda
[172825] http://ixflintere.com/e/ch/?action=awcpa
[172826] http://ixflintere.com/e/ch/?action=awaq
[172827] http://ixflintere.com/e/ch/?action=antispam
[172828] http://ixflintere.com/e/ch/?action=ambien&t=testimonials
[172829] http://ixflintere.com/e/ch/?action=ambien&t=description
[172830] http://ixflintere.com/e/ch/?action=ambien
[172831] http://ixflintere.com/e/ch/?action=allproducts
[172832] http://ixflintere.com/e/ch/?action=affiliate
[172833] http://ixflintere.com/e/ch/?action=acomplia&count=1&t=description
[172834] http://ixflintere.com/e/ch/?action=acomplia
[172835] http://ixflintere.com/e/ch/?action=aboutus
[172838] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=women_s_health
[172839] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=weight_loss
[172840] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=pain_relief
[172841] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=men_s_health
[172842] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=general_health
[172843] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=blood_pressure_cholesterol
[172844] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=anti_herpes
[172845] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=anti_diabetic
[172846] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=anti_depressants
[172847] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=anti_biotics
[172848] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=anti_allergic_asthma
[172849] http://ixflintere.com/e/ch/?action=allproducts&count=1&type=anti_acidity
Handler Note:
11 May, 2008
06:18:03
AlphaCentauri: Sites in this spam family (My Canadian Pharmacy, International "Legal" Rx, Canadian Health&Care Mall, Men+ Health, US Drugs, VIP Pharmacy/"Viagra+Cialis") will often block traffic from IP addresses associated with legal, financial and antispam organizations as well as anyone who has visited more than one of their sites. It may be necessary to use a proxy to view the pages. In addition, nameservers will selectively refuse queries for certain domains not currently being spammed, and it is necessary to use traversal to see that the domains themselves are not suspended.

Nameservers:
Generated by www.DNSstuff.com at 05:00:28 GMT on 11 May 2008.
ns2.werfaintish.com [203.174.60.37]
ns1.noparborescent.com [200.204.142.53]
ns2.samnout.info [203.174.60.37]
ns1.betamarop.com [121.121.121.121]

Spamhaus information on these IP addresses:
http://www.spamhaus.org/sbl/sbl.lasso?query=SBL56016 for 218.3.160.2
http://www.spamhaus.org/sbl/sbl.lasso?query=SBL62483 for 79.135.167.10
http://www.spamhaus.org/sbl/sbl.lasso?query=SBL63639 for 203.174.60.37
Handler Note:
11 May, 2008
06:19:11
AlphaCentauri: View CIDR AS4134 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4134

"4134 | CN | apnic | 2002-08-01 | CHINANET-BACKBONE No.31,Jin-rong Street"

Handler Note:
11 May, 2008
06:19:12
AlphaCentauri: Extended information for AS4134:
State/Province:
Country: cn
Responsible Domain: chinanet.cn.net
Abuse Email: cncert@cert.org.cn
Handler Note:
11 May, 2008
06:21:06
AlphaCentauri: View CIDR AS9121 Report: http://www.cidr-report.org/cgi-bin/as-report?as=9121

"9121 | TR | ripencc | 1998-12-29 | TTNET TTnet Autonomous System"

Handler Note:
11 May, 2008
06:21:08
AlphaCentauri: Extended information for AS9121:
State/Province:
Country: tr
Responsible Domain: telekom.gov.tr
Abuse Email: abuse@ttnet.net.tr
Handler Note:
11 May, 2008
06:23:50
AlphaCentauri: View CIDR AS4837 Report: http://www.cidr-report.org/cgi-bin/as-report?as=4837

"4837 | CN | apnic | 2001-09-17 | CHINA169-BACKBONE CNCGROUP China169 Backbone"

Handler Note:
11 May, 2008
06:23:50
AlphaCentauri: Extended information for AS4837:
State/Province:
Country: cn
Responsible Domain: cnc-noc.net
Abuse Email: abuse@cnc-noc.net
Handler Note:
11 May, 2008
06:25:14
AlphaCentauri: View CIDR AS8629 Report: http://www.cidr-report.org/cgi-bin/as-report?as=8629

"8629 | RU | ripencc | 1998-01-22 | MCNTT-AS MCNTT Autonomous System"

Handler Note:
11 May, 2008
06:25:15
AlphaCentauri: Extended information for AS8629:
State/Province:
Country: ru
Responsible Domain: ntt.ru
Abuse Email: postmaster@ntt.ru
Handler Note:
11 May, 2008
06:31:00
AlphaCentauri: View CIDR AS2683 Report: http://www.cidr-report.org/cgi-bin/as-report?as=2683

"2683 | EU | ripencc | 1993-09-01 | RADIO-MSU RADIO-MSU"

Handler Note:
11 May, 2008
06:31:00
AlphaCentauri: Extended information for AS2683:
State/Province:
Country:
Responsible Domain: radio-msu.net
Abuse Email: abuse@radio-msu.net
Handler Note:
11 May, 2008
06:35:29
AlphaCentauri: View CIDR AS9381 Report: http://www.cidr-report.org/cgi-bin/as-report?as=9381

"9381 | HK | apnic | 1998-08-17 | NEWTT-IP-AP Wharf T&T Ltd."

Handler Note:
11 May, 2008
06:35:29
AlphaCentauri: Extended information for AS9381:
State/Province:
Country: hk
Responsible Domain: wharftt.com
Abuse Email: abuse@wharftt.com
Handler Note:
11 May, 2008
06:36:53
AlphaCentauri: View CIDR AS27699 Report: http://www.cidr-report.org/cgi-bin/as-report?as=27699

"27699 | BR | lacnic | 2003-06-24 | TELECOMUNICACOES DE SAO PAULO S/A - TELESP"

Handler Note:
11 May, 2008
06:36:54
AlphaCentauri: Extended information for AS27699:
State/Province:
Country: br
Responsible Domain: telesp.com.br
Abuse Email: abuse@telesp.net.br
Handler Note:
11 May, 2008
06:39:35
AlphaCentauri: View CIDR AS9534 Report: http://www.cidr-report.org/cgi-bin/as-report?as=9534

"9534 | MY | apnic | 1999-05-17 | MAXIS-AS1-AP Binariang Berhad"

Handler Note:
11 May, 2008
06:39:36
AlphaCentauri: Extended information for AS9534:
State/Province:
Country: my
Responsible Domain: maxis.net.my
Abuse Email: tony@maxis.net.my
Handler Note:
11 May, 2008
06:44:57
AlphaCentauri: ISPs: Please assist your customers in identifying and disinfecting

servers at the following addresses:

chinanet.cn.net
218.3.160.2

cnc-noc.net
58.241.87.130

maxis.net.my
121.121.121.121

ntt.ru
84.253.77.6

radio-msu.net
194.67.66.10

telekom.gov.tr
79.135.167.10

telesp.com.br
200.204.142.53

wharftt.com
203.174.60.37


Registrars: please suspend the following domains and nameservers. Please

investigate the payment history as it was almost certainly fraudulent as

well. Please forward evidence of fraudulent activity to law enforcement.

See domain suspension instructions at
http://www.spamtrackers.eu/wiki/index.php?title=Registrar_Advice
Hong Kong mirror:
香港 镜象地点
http://spamtrackers.hk/wiki/index.php/Suspending_an_EPP_domain
http://spamtrackers.hk/wiki/index.php/Suspending_a_non-EPP_domain

(Removal of nameservers is here:
http://spamtrackers.hk/wiki/index.php/Suspending_an_EPP_name_server_doma

in
http://spamtrackers.hk/wiki/index.php/Suspending_a_non-EPP_name_server_d

omain )

As the domains for the Yambo family of spamvertised websites (My

Canadian Pharmacy, International Legal Rx Medications, Men+ Health, US

Drug, VIP Pharmacy ("Viagra + Cialis"), and Canadian Health&Care Mall

are uniformly registered with information obtained by identity theft and

paid with fraudulent credit/debit card information, please suspend any

other sites in this family that you become aware of.

moniker.com
ixflintere.com

dns.com.cn
noparborescent.com
ns1.noparborescent.com [200.204.142.53]

xinnet.com
werfaintish.com
ns2.werfaintish.com [203.174.60.37]

ENOM
samnout.info
ns2.samnout.info [203.174.60.37]
Handler Note:
11 May, 2008
06:48:07
AlphaCentauri: Generated and sent email spam alert to respective parties.
Fetched URLs
Slaves172794, 172795, 172796, 172797, 172798, 172799, 172800, 172801, 172802, 172803, 172804, 172805, 172806, 172807, 172808, 172809, 172810, 172811, 172812, 172813, 172814, 172815, 172816, 172817, 172818, 172819, 172820, 172821, 172822, 172823, 172824, 172825, 172826, 172827, 172828, 172829, 172830, 172831, 172832, 172833, 172834, 172835, 172838, 172839, 172840, 172841, 172842, 172843, 172844, 172845, 172846, 172847, 172848, 172849,

Report for at 11 May, 2008 @ 04:43:54


fetched page


at 11 May, 2008 @ 04:44:12
MD5 Fingerprint: 182aab447e454c310ca2e9c402e92644
SHA1 Fingerprint: 33f784a5c1844a5221049c5f91db32ce4318a2bf
Version 1.0
spacer spacer