Blog for hpHosts, and whatever else I feel like writing about ....

Sunday 18 March 2012

Canadian pharmacy: Lets play tagged!

As if the reputation of Tagged for spamming people, wasn't bad enough, the boys involved in fake pharmacies have decided to make it even worse, by mis-using the Tagged name, presumably in an attempt to bypass spam filters (woops!).

From: Tagged <Tagged@taggedmail.com>
To: raymonda_laermans@yahoo.co.uk
Sent: Saturday, 17 March 2012, 22:11
Subject: Senga D sent you a message...


<http://sks.yyu.edu.tr/dimensioning.html> My Profile <http://sks.yyu.edu.tr/dimensioning.html> |Messages <http://sks.yyu.edu.tr/dimensioning.html> |Friends <http://sks.yyu.edu.tr/dimensioning.html> |Meet Me <http://sks.yyu.edu.tr/dimensioning.html> |Browse <http://sks.yyu.edu.tr/dimensioning.html> |Search <http://sks.yyu.edu.tr/dimensioning.html>
<http://sks.yyu.edu.tr/dimensioning.html> Senga D, 29 You have a new message!
Senga D says: Hi. Do you remember me ?
View message! <http://sks.yyu.edu.tr/dimensioning.html>

Manage my account and email settings <http://sks.yyu.edu.tr/dimensioning.html> on Tagged Inc., 110 Pacific Mall Box #117, San Francisco, CA. 94111
All Tagged emails will be sent from our official @tagged.com or @taggedmail.com domains to your registered email address. We will never contact you from any other email addresses.


From Tagged Sat Mar 17 21:11:00 2012
X-Apparently-To: [REMOVED] via 87.248.103.88; Sat, 17 Mar 2012 18:28:50 +0000
Return-Path: <billtownsend@talkmatch.com>
X-YahooFilteredBulk: 67.225.143.155
Received-SPF: fail (domain of talkmatch.com does not designate 67.225.143.155 as permitted sender)
X-YMailISG: ZqA8NFgWLDuXaeTEMafLSAqynCwVdfranwA.jeTP3Atwb.F2
3hlABc8WXiYcr9sZCQqUgabP6fGehBSMin8beNWGH_43Igx6zbp1Sq0x2zSG
BBab56U2ZswLQmEXk4qwsKsTOG2vNjpCI.TCwCg0xugmy9n49fxw7gyHd7KS
PfLcxH_Pr9JSpu58zrmmJwUjQxDwGYj7VlTnhoseK.sPnmZ7b_O9j9GZp8Wo
_Kapk5ZQu7xcFgrIIvHY7aeBOSB1Bzu9vQTk.OU3vhjREOTpi4Jb6ZpkDcIF
g64z7FfU7yQgUkxVZzQD46qOcH336b7oAPCZb9QhsSfAAvLmyPDQMjNS50Hh
d5gdYyKryoTYnTo8BKO47tVS0b.nMnn7pwUVlrHIGFM0Y9SgsymUXgzS4u_d
cZIrHE6Luaxt1oFxRaPhfYYqTKPYjvCMoBUSxFk_JpQzAhZ_y28IHT55q6AE
SCnsVjmU_d7.iKvdDp6Dbnx6e4oZLnZbECU4NlrHynmGzeqGEqtnwahD38x6
HkqakM2qLDklQFVr6mFtbfXVYfg7.PYY5lFO163O59_I_6SzZPRwW_BCFc.O
AFd9_5bu7fyaTcIm1pTP5zHm0Lcg3wYB2KH.6uUprdNYiJLzaholknfwbqdJ
8SL_yv2efVSkodO.mO3ZEijwR7WSwDlIFIpYI1e2wXCs3Zap9MUnmoSGhAab
5NwZvAMxAA4zkbs8OsOkiUWHTckslU1tKnpZVlB82.yCTfX2we61AeQw6u9Q
vuL56K1qxOaDjYEcvEdGH5bhfOz_A86s3i3s2vRfX.zevTmAHSAwigyDnXrn
&nbs p;mP19BFWl.Ze5zsFTwsqFSKVqvOQtx_yr7GHhD4bLsalm7stfTPKFF_Th5bl8
u8opt2J3VvI5B.DW8PdW9UufWWwa62Q7zDy9NsXB_jFxoF3XfjrcroJ8QbZP
vBFRm65rDRqOItYagjcysx5gyTtNayN01RYm_y_OuTTALEYALuAzvHmi_orG
Qv5uHioNA0CQuScUCsP_PWJw.nqw1oozWVg.M1QNJmxOfgEGPkpACfEu8iYZ
5dw98B.Uphjl4nXFND_urlgXGjUJtq8JnvdHLdX26f0e
X-Originating-IP: [67.225.143.155]
Authentication-Results: mta1022.mail.ird.yahoo.com from=taggedmail.com; domainkeys=neutral (no sig); from=taggedmail.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (HELO colo4.kaakateeya.com) (67.225.143.155)
by mta1022.mail.ird.yahoo.com with SMTP; Sat, 17 Mar 2012 18:28:50 +0000
Date: Sat, 17 Mar 2012 14:11:00 -0700 (PDT)
From: Tagged<Tagged@taggedmail.com>
To: [REMOVED]
Subject: Senga D sent you a message...
MIME-Version: 1.0
List-Unsubscribe: <http://www.tagged.com/no_more.html?unsem=[REMOVED]
Sender: TaggedTagged@taggedmail.com
Content-Type: text/html; charset="utf-8"
X-Log-Id: 8073775313
Content-Transfer-Encoding: 7bit
Message-ID: <5.23.851.7265.0FCF410F036E793.3@sf-mta-643.taggedmail.com>
Content-Length: 3998


You'd have thought they'd have realised, if you want to bypass a spam filter, the last thing you do is impersonate a company known for spamming - they're already likely to be on everyones favourite blacklist/spam filter.

So what of the link? Well, the link in this case, points to;

URL: sks.yyu.edu.tr/dimensioning.html
IP: 193.255.143.50
IP PTR: yapi.yyu.edu.tr
ASN: 8517 193.255.0.0/16 ULAKNET ULAKNET-ASN

Which uses window.location, to redirect you to;

Host: palliativecarebooks.com
IP: 208.79.81.198
IP PTR: xyw3.x.rootbsd.net
ASN: 13637 13647 208.79.80.0/22 Tranquil Hosting, Inc.



Once you've decided what you want, the checkout then takes you to;

Host: onlinerxbilling.com
IP: 74.86.44.57
IP PTR: 74.86.44.57-static.reverse.softlayer.com
ASN: 36351 74.86.0.0/16 SOFTLAYER - SoftLayer Technologies Inc.



With the SSL cert provided by RapidSSL as of January 4th;



In case you're wondering, 208.79.81.198 also houses;

galaxycialistab.mobi
palliativecarebooks.com
xyw3.x.rootbsd.net
onlinemedicinemedic.ru
ns1.onlinemedicinemedic.ru
ns2.onlinemedicinemedic.ru
mail.onlinemedicinemedic.ru
bho2000.oilrk.ru
budda510.oilrk.ru
bill5150.oilrk.ru
blau5150.oilrk.ru
alfi0.oilrk.ru
bip2001.oilrk.ru
bmarcus001.oilrk.ru
carle01.oilrk.ru
apark01.oilrk.ru
bbeck11.oilrk.ru
amacgregor11.oilrk.ru
dolphi2721.oilrk.ru
dhhc21.oilrk.ru
deuce21.oilrk.ru
djali21.oilrk.ru
dboone1.oilrk.ru
chrismoore1.oilrk.ru
brettg1.oilrk.ru
asaiah1.oilrk.ru
aci1.oilrk.ru
jesmel1.oilrk.ru
dbowen1.oilrk.ru
calvinmiller1.oilrk.ru
chrishowes1.oilrk.ru
clrocks1.oilrk.ru
ns1.oilrk.ru
dcmgmt1.oilrk.ru
aconnolly1.oilrk.ru
bkane012.oilrk.ru
badcad42.oilrk.ru
blackwatch42.oilrk.ru
dwk72.oilrk.ru
ns2.oilrk.ru
dunn13.oilrk.ru
don13.oilrk.ru
c1023.oilrk.ru
davida4353.oilrk.ru
carla5263.oilrk.ru
bhs65.oilrk.ru
bam206.oilrk.ru
depage007.oilrk.ru
barrybragg007.oilrk.ru
bjoerne7.oilrk.ru
dcusack009.oilrk.ru
cherb49.oilrk.ru
bigred359.oilrk.ru
detroitlionsfan1989.oilrk.ru
andymac99.oilrk.ru
benner99.oilrk.ru
abuda.oilrk.ru
alenmila.oilrk.ru
capazasa.oilrk.ru
ckobsa.oilrk.ru
dotsb.oilrk.ru
bennietb.oilrk.ru
aghazariandd.oilrk.ru
xcsdd.oilrk.ru
balloud.oilrk.ru
fvubyd.oilrk.ru
rsmeade.oilrk.ru
archmage.oilrk.ru
bhf-garage.oilrk.ru
abbake.oilrk.ru
benofmooresville.oilrk.ru
anniesunshine.oilrk.ru
allstretchlimousine.oilrk.ru
avolpe.oilrk.ru
blairhouse.oilrk.ru
dougpete.oilrk.ru
driaf.oilrk.ru
chaydogg.oilrk.ru
cmberg.oilrk.ru
alexenberg.oilrk.ru
bertholdkrug.oilrk.ru
cibertech.oilrk.ru
driosh.oilrk.ru
adamjsmith.oilrk.ru
alupnorth.oilrk.ru
davesdj.oilrk.ru
darrinj.oilrk.ru
balok.oilrk.ru
bartlettelectrical.oilrk.ru
ahal.oilrk.ru
agusital.oilrk.ru
docparcel.oilrk.ru
dbaseball.oilrk.ru
btram.oilrk.ru
daydoom.oilrk.ru
bsilverm.oilrk.ru
chsm.oilrk.ru
billidrum.oilrk.ru
bobrieckelman.oilrk.ru
mrhappyheadn.oilrk.ru
asilken.oilrk.ru
bfranzen.oilrk.ru
chrissgriffin.oilrk.ru
cerdmann.oilrk.ru
debusmann.oilrk.ru
bertswanson.oilrk.ru
dennis.robinson.oilrk.ru
dodioflo.oilrk.ru
ddgroto.oilrk.ru
bimber.oilrk.ru
cheezyrider.oilrk.ru
ben_inker.oilrk.ru
jackfulmer.oilrk.ru
chplummer.oilrk.ru
bradayer.oilrk.ru
bsdias.oilrk.ru
bholmes.oilrk.ru
dvdjones.oilrk.ru
chaynes.oilrk.ru
btiefs.oilrk.ru
asulkis.oilrk.ru
anns.oilrk.ru
ceturns.oilrk.ru
atsanders.oilrk.ru
aftermidnight.oilrk.ru
mrsbanksgunit.oilrk.ru
bart.oilrk.ru
anttolbert.oilrk.ru
airblast.oilrk.ru
ashertt.oilrk.ru
bvgut.oilrk.ru
b.simoneau.oilrk.ru
cboudreau.oilrk.ru
blkarrow.oilrk.ru
broux.oilrk.ru
brandy.oilrk.ru
adrianbradley.oilrk.ru
brianmcnasty.oilrk.ru
www10s3mr6.gnmkl.ru
wwwces35c7.gnmkl.ru
www040mjc4b.gnmkl.ru
wwwy3uiywue.gnmkl.ru
wwwndqf.gnmkl.ru
wwwmflt.gnmkl.ru
www26eqnu.gnmkl.ru
tabletrxnutrition.ru
ns1.tabletrxnutrition.ru
ns2.tabletrxnutrition.ru
fitnesspharmacytabs.ru
ns1.fitnesspharmacytabs.ru
ns2.fitnesspharmacytabs.ru
mail.fitnesspharmacytabs.ru
www.fitnesspharmacytabs.ru
onlinemedspills.ru
ns1.onlinemedspills.ru
ns2.onlinemedspills.ru
medtechspillstablets.ru
ns1.medtechspillstablets.ru
ns2.medtechspillstablets.ru
medicinetorepillsrx.ru
ns1.medicinetorepillsrx.ru
ns2.medicinetorepillsrx.ru
drugcutpillsrx.ru
ns1.drugcutpillsrx.ru
ns2.drugcutpillsrx.ru
drugstoremedspharmacy.ru
ns1.drugstoremedspharmacy.ru
ns2.drugstoremedspharmacy.ru
drugstoredrugspharmacy.ru
ns1.drugstoredrugspharmacy.ru
ns2.drugstoredrugspharmacy.ru
bestpillspharmacy.ru
ns1.bestpillspharmacy.ru
ns2.bestpillspharmacy.ru


References

Microsoft, Google, Facebook, Tagged et al - they never learn
http://hphosts.blogspot.co.uk/2010/04/microsoft-google-facebook-tagged-et-al.html

Tagged.com pays $750,000 over deceptive emails
http://www.theregister.co.uk/2009/11/10/new_york_ag_fines_tagged/

Tagged spam - with a difference
http://hphosts.blogspot.co.uk/2009/10/tagged-spam-with-difference.html

Dear Tagged .... weren't you already being sued for this?
http://hphosts.blogspot.co.uk/2009/07/dear-tagged-werent-you-already-being.html

Tagged.com being sued - and about bloody time too!
http://hphosts.blogspot.co.uk/2009/07/taggedcom-being-sued-and-about-bloody.html

No comments: