Blog for hpHosts, and whatever else I feel like writing about ....

Monday 11 June 2012

Fake meds spoofing IMDB

Looks like it's the turn of the IMDB to be spoofed. Same gang responsible, not surprisingly.



Return-Path: <ticket@dutchman.dk>
Delivered-To: [REMOVED]
X-Spam-Flag: YES
X-Spam-Score: 14.747
X-Spam-Level: **************
X-Spam-Status: Yes, score=14.747 tagged_above=-9999 required=1.3
tests=[BAYES_50=0.8, DATE_IN_FUTURE_12_24=3.199,
DKIM_ADSP_NXDOMAIN=0.9, HTML_MESSAGE=0.001, HTTPS_HTTP_MISMATCH=1.989,
MIME_HEADER_CTYPE_ONLY=0.717, MIME_HTML_ONLY=0.723,
RAZOR2_CHECK=0.922, RCVD_IN_BL_SPAMCOP_NET=1.347,
RCVD_IN_BRBL_LASTEXT=1.449, RCVD_IN_PSBL=2.7] autolearn=spam
Received: from ns1-110.psychodev.net (ns1-110.psychodev.net [122.155.10.125])
by [REMOVED] (Postfix) with SMTP id D97EC39846D
for <[REMOVED]>; Mon, 11 Jun 2012 15:59:38 +0100 (BST)
Subject: [SPAM] Your password is too short
Content-Type: text/html; charset="utf-8"
To: [REMOVED]
From: IMDb User Protection <do-not-reply-here@change-imdb.com>
Message-Id: <20120611215942.C11DBDCEA0A@imdb-pro-online-0376.iad6.amazon.com>
Date: Mon, 11 Jun 2012 21:59:42 -0700 (PDT)


In this case, the link leads to;

loekieschroder.nl/up/load/

Which redirects to;

Host: herbalchemistsshop.com
IP: 91.238.180.92
IP PTR: Resolution failed
ASN: 197071 91.238.180.0/23 INTERWERK INTERWERK - Rotorfly Europa GmbH & Co. KG

Domain Name: HERBALCHEMISTSSHOP.COM

Registrant:
Ilmari Karlsson
Ilmari Karlsson (jovanovic@08mail.com)
Siikajoentie 85
Revonlahti
Revonlahti,92350
FI
Tel. +358.0408663029

Creation Date: 08-Jun-2012
Expiration Date: 08-Jun-2013

Domain servers in listed order:
ns1.herbalchemistsshop.com
ns2.herbalchemistsshop.com

Administrative Contact:
Ilmari Karlsson
Ilmari Karlsson (jovanovic@08mail.com)
Siikajoentie 85
Revonlahti
Revonlahti,92350
FI
Tel. +358.0408663029

Technical Contact:
Ilmari Karlsson
Ilmari Karlsson (jovanovic@08mail.com)
Siikajoentie 85
Revonlahti
Revonlahti,92350
FI
Tel. +358.0408663029

Billing Contact:
Ilmari Karlsson
Ilmari Karlsson (jovanovic@08mail.com)
Siikajoentie 85
Revonlahti
Revonlahti,92350
FI
Tel. +358.0408663029


Other domains seen on this IP (you can also keep up with them via the hpHosts website)

abacirnyo.net
acefsynqe.com
ailanthoidolherbal.com
ailanthoidolwelness.com
aircanadarx.com
ajohn.dietrxpills.ru
ajryfdewett.com
allcialisrx.com
allied.couponkidrugstore.com
amwafudicbia.com
amwafudicbia.net
androidcanadatablet.mobi
androidmedical.com
androidrugstoretablet.com
androidtratablet.com
anticaretab.com
appstabletsrx.com
aronpharmacylevitra.com
arontrapharmacy.com
arontrapill.mobi
arontraprescription.com
arontratablet.com
arontraviagra.com
assayslnesshealthcare.com
athaxpyqs.com
awakeninglevitra.com
awsanimmag.com
badgeshealthcare.com
badgestabmedicine.com
baetevzuo.com
bataviagracialis.com
bdauzzyus.com
bdelwiac.com
bdocleyle.com
beliciamelisande.com
bestmedicinepharma.ru
betterhealthpills.com
bildunterschriftpills.com
biologicalpill.mobi
biolpharm.com
biolpharmacy.com
blockbusterstore.net
blonfipa.com
boisviagra.com
boquihcu.net
bosnialispharm.eu
bplispill.com
bplispills.com
breiclorn.com
brokusvexva.com
brylzaox.com
buygenericsmeds.com
buygenericspills.com
buygenericswelness.com
buyviagracialis.com
bygjeqworw.com
bzawivuck.com
bziwsinowebr.com
cadnuzque.com
caifkytce.com
canadapillgroup.com
canadaprescriptiongroup.com
canadatabtablet.mobi
canadatrevali.com
canadianelnesscanada.com
canadiantabcanada.com
carehealthmeds.com
carehealthrxtablets.net
caremarkviagra.com
caremedicalpharmacy.com
carepharmedical.com
carepharmkildee.com
carepillsgroup.com
caretabgalaxy.com
careviagra.com
careviagrahealth.mobi
careviagras.com
carewelbizness.com
carewelloch.com
carmelitakelly.com
carotenoidsherbal.be
cecbitpa.com
celebrex200mg.org
cellwelness.mobi
cialispillerie.com
cialispillsbp.com
cialistabletgroup.com
cialistkvue.com
cialisttypeab.com
cialisviagracounterpunch.com
cialiswelbizness.com
cialiswelpakistan.com
cialiswichi.com
cnadkuxnif.com
cnajzepsok.com
cnajzepsok.net
comptablevitra.com
contabcialis.com
contabgenerics.com
contabmedicare.com
contabsale.com
counterpunchgenerics.com
counterpunchviagra.com
counterpunchviagramedicine.com
counterpunchwelness.com
couponkidrugstore.com
cvityasmiy.com
dakbenranul.com
daksuzwuw.com
debtpharm.com
dedwiccew.com
derunherta.com
dexfaifmev.com
dfdohf.ru
dfhjds.ru
dfjkd.ru
dfnsmf.ru
dfsmnf.ru
dhfjsf.ru
dietabletgroup.com
dietmedscalories.com
dietpharmacyeat.com
dietpharmacyweight.com
dietpharmgroup.com
dietpilldrugstore.com
dietpillgenerics.com
dietpillgroup.com
dietpillmed.com
dietpillmedicare.com
dietpillsdrugstore.com
dietpillsgenerics.com
dietpillsgroup.com
dietpillsherbal.com
dietprescriptionfat.com
dietprescriptiongroup.com
dietsperm.com
dietwelfat.com
dietwichi.com
dietwiski.com
digitalmediaset.com
djfhf.ru
doypdaficea.com
drugenericswiki.com
drughealthcareprescription.com
drugmedpill.com
drugpillcialis.com
drugpillsgenerics.com
drugpillsherbal.com
drugscvspharmacy.com
drugsmedsmedical.com
drugsprescriptionlevitra.com
drugstoreandroid.com
drugstorebirth.com
drugstoredoctor.com
drugstoredrugstorehealth.ru
drugstorehealthmedscare.net
drugstorehealthmedsinsurance.net
drugstorehomerxmeds.net
drugstorehospital.net
drugstorepause.com
drugstorepharmacydrug.com
drugstorepharmacyretailers.com
drugstorepharmacywalgreens.com
drugstorepilldrug.com
drugstorepillsandroid.net
drugstorerxbronzer.com
drugstorerxhealthinsurance.net
drugstorestrauss.com
drugstoretabinc.com
drugstoretabletgroup.com
drugstoretabletsmed.com
drugstoretabletsnook.net
drugstoreviagragroup.com
drugstorewelloch.com
drugstorewelness.com
drugstorewelnessgroup.com
drugstorewichi.com
drugtorehealthcare.com
drugtorehealthtabletsmedicare.net
drugtorepharmacytabletsomma.net
drugtoretabletshealth.net
drykveffum.com
dukyoxcymo.com
dunnvillepill.com
dvocmiojha.com
dymevaga.bestmedicinepharma.ru
dynuldauc.com
dzepojkarny.com
dzovhodryts.com
dzovhodryts.net
eaheuwdufpi.net
eatdietmeds.com
eatingmeds.com
eatpharmdiet.com
eatpill.mobi
ebjoknubih.com
eckingerrx.com
ecstasyherbal.com
ejcibweof.com
ejpythoufah.com
elsevkatja.com
eovurvainso.com
epanfaftue.com
epwyphafqe.com
esfixmovizqe.com
eskunpoa.com
ettoicbynn.net
evkasryb.com
fndmsf.ru
fnsmfs.ru
goscandata.com
gugyhpymka.com
hibaqyro.bestmedicinepharma.ru
igjfmd.ru
jatijogu.bestmedicinepharma.ru
jhfsfd.ru
jvhjaq.ru
kjckv.ru
kjvkxd.ru
mail.dfjkd.ru
mail.dietrxpills.ru
mail.fkvjgx.ru
miravalmed.eu
mypharmcialis.com
mywelnesslevitra.com
newcialispharmacy.com
newhealthmeds.com
newpillshealth.com
newrxmedical.com
nokitore.bestmedicinepharma.ru
ns1.baetevzuo.com
ns2.baetevzuo.com
pharmmednew.com
rubed.ru
tylubita.bestmedicinepharma.ru
xamonixe.bestmedicinepharma.ru
zeu.drugstorerxmedsfast.ru
zuxudasi.bestmedicinepharma.ru


And I've no doubt there's more I'm not yet aware of.

Email text;

This is an automatic message from the Internet Movie Database (IMDb) registration system.
Our system detected your password is too weak. Short passwords are easy to guess.

Please follow this link :

https://secure.imdb.com/password_detect/imdb/73922755903363027203

If you use this password at any other sites, you'll need to change those passwords as well.

Regards,
IMDb User Protection help
http://imdb.com/register/


The link of course, doesn't lead to secure.imdb.com, which if you're sensible and have HTML email turned off, will be immediately obvious to you. Instead, it leads to the loekieschroder.nl domain, and then to the fake meds domain.

Still trying to determine which botnet is responsible for these.

References

Fake meds spam spoofing Microsoft
http://hphosts.blogspot.co.uk/2012/06/fake-meds-spam-spoofing-microsoft.html

Alert: Fake meds spam impersonating Digg
http://hphosts.blogspot.co.uk/2012/06/alert-fake-meds-spam-impersonating-digg.html

No comments: