
05-22-08, 09:43 PM
|
 | Administrator | | | |
Pharmacy Express (referred to in this document as PE) is a very large and sophisticated spamming operation believed to be operated by the Russian criminal spammer Leo Kuvayev, Alex Polyakov, Vincent Chan and several of his colleagues and affiliates. These sites have been spamvertised relentlessly to several million email addresses since at least 2004, possibly even longer. Mr. Kuvayev is wanted for several international charges which he has never answered for, including money laundering, child porn and of course illegal spamming. This spam operation has numerous ties to several large-scale Windows viruses and Trojan infections dating back numerous years. The botnets alleged to be behind this operation handle everything from domain registration to zombie infection to probably website hosting and "order" processing. Nobody has ever claimed to have received anything upon ordering, so this series of websites is actually considered a credit card fraud operation very similar to Alex Polyakov's My Canadian Pharmacy.
As is the case with My Canadian Pharmacy, numerous pharmacy oversight organizations have fielded several thousand complaints per year regarding this illegal operation. They and numerous law enforcement agencies continue to investigate as much as possible regarding the spamming, website setup, DNS setup and (alleged) order processing of this spam gang. This investigation is ongoing.
Pharmacy Express sites stopped being spam during the middle portion of 2007, but resurfaced with a completely new design in Feb. 2008. Current Discussion
The newer version of Pharmacy Express sites started to be spammed in late-February of 2008 and as mentioned above they feature a totally different design.
2008 spam runs relied on Yahoo search redirects to penetrate spam whitelists.
Spamming in 2007 for domains like lodrx.com, tedrx.com and similar, targeted Google's Gmail customers. Most were trapped by Gmail's spam detection and diverted to the spam folder.
You may follow a discussion on Pharmacy Express at the Fight Back forum. Read More - SpamTrackers.eu
WhoIs Lookup performed by Karen's WhoIs http://www.karenware.com/
Domain Name: www.SEVERALSO.COM
Registrar: XIN NET TECHNOLOGY CORPORATION
Whois Server: whois.paycenter.com.cn
Referral URL: http://www.xinnet.com
Name Server: NS1.COW77.COM
Name Server: NS2.COW77.COM
Name Server: NS3.COW77.COM
Name Server: NS4.COW77.COM
Status: ok
Updated Date: 19-may-2008
Creation Date: 14-may-2008
Expiration Date: 14-may-2009
Last update of whois database: Thu, 22 May 2008 19:56:21 UTC
Domain Name:severalso.com
Registrant:
He Yong
NO.138,Baiyan street,Chongqiong City
404041
Administrative Contact:
HeYong
He Yong
NO.138,Baiyan street,Chongqiong City
shenzen Guangdong 404041
CN
tel: 755 3265698
fax: 755 3265698 cg186@126.com
Technical Contact:
HeYong
He Yong
NO.138,Baiyan street,Chongqiong City
shenzen Guangdong 404041
CN
tel: 3265698
fax: 3265698 cg186@126.com
Billing Contact:
HeYong
He Yong
NO.138,Baiyan street,Chongqiong City
shenzen Guangdong 404041
CN
tel: 3265698
fax: 3265698 cg186@126.com
Registration Date: 2008-05-14
Update Date: 2008-05-20
Expiration Date: 2009-05-14
Primary DNS: ns1.cow77.com 61.160.212.10
Secondary DNS: ns2.cow77.com 221.122.64.14
Last edited by Scrub; 06-08-08 at 11:41 AM.
|