Last visit was: Sat Jul 05, 2014 6:06 pm
It is currently Sat Jul 05, 2014 6:06 pm

Archive: EvaPharmacy - Enough is enough


All times are UTC - 5 hours [ DST ]


 [ 150 posts ]  Go to page 1, 2, 3, 4, 5 ... 10  Next
Author Message
 PostPosted: Sun Nov 25, 2012 6:32 pm   
Spammers' Nightmare
User avatar

Joined: Thu Apr 12, 2007 6:55 pm
Posts: 2549
EDIT: These postings are archived from the "Enough is Enough" topic, because they are over 12 months old /EDIT

-----------------------------------------------------------------------------------------------------------------------------------------------------------------


Do you believe the servers are abandoned, and or possibly on shared hosting?

If the IP of a spammed link goes to a shared hosting company, maybe contacting that company can get the machine shutdown or at least fixed.


EDIT: I guess if I had read your other posts, my response would have been answered.


Top
 Profile  
 PostPosted: Mon Nov 26, 2012 3:00 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
trobbins wrote:
Do you believe the servers are abandoned, and or possibly on shared hosting?

It's any kind of server that has a very weak root password, and there are thousands of them. The majority of them are not even used as web servers at all, but are either phone / pbx boxes, firewalls, or some other utility-level unix server that was not intended to host websites of any sort.

trobbins wrote:
If the IP of a spammed link goes to a shared hosting company, maybe contacting that company can get the machine shutdown or at least fixed.

The thing is: that has not been my experience. Shared or not: getting anyone to pay attention to this has been time consuming and largely ineffective. So far. This is why I posted my message: what do we have to do to get these hosting companies to recognize the criminal nature of this activity on their own servers?

There are dozens (40+) of Chinanet servers which have all been abused in this way, and nobody from Chinanet ever responds to any report of this activity. This is only one example of probably hundreds since 2006.

trobbins wrote:
EDIT: I guess if I had read your other posts, my response would have been answered.


It's fine. I'm treating this whole thing as a net-new "Tell me what we know so far" discussion. It's been dormant for a while because we focused on other things.

Any questions, no matter how dumb, are welcome. I have a lot of research I can provide.

SiL


Top
 Profile  
 PostPosted: Mon Nov 26, 2012 8:16 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Thu Mar 01, 2007 3:01 am
Posts: 5915
I'm in. :)


Top
 Profile  
 PostPosted: Wed Nov 28, 2012 5:38 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Okay so I took a second to try to compile where my own actions have led.

Bear with me, this is a little lengthier than usual.

I have been trying to report as many new hijacked IP addresses as I can each time I see new spam for these morons.

a) Report rogue redirections to website operators and hosting companies who have been exploited.
b) For each IP providing hosting and dns services for any of the Eva Pharmacy brands to the hosting companies.

I have a very basic tool called the Phishing Reporterator™ which makes that task a little easier.

You can get it, for now, here:

http://ge.tt/8yd6FXS/v/0?c

Red: that download section of spamtrackers refuses to accept any file type. I really don't like that interface. If you can make this live there it would be great.

That takes care of the easier stuff - alerting site owners and their hosting company that they've been compromised.

The bigger deal is: organizing so we can send a single, clear, easy to understand warning about the server compromise.

I have a boilerplate message I've been sending that's pretty detailed:

Quote:
to: [site owner], [hosting company abuse email]

Your web server has been hacked by EvaPharmacy [ip.add.re.ss]

Hello

The subject says it all.

I've been investigating a Russian rogue online pharmacy group known as EvaPharmacy since 2005.

EvaPharmacy host all of their illicit rogue pharmacy websites on other people's servers, like yours, by performing scans and attempting to find servers with very weak Root passwords. A server you control - at IP address ip.add.re.ss - is now under their control. I know this because your IP address shows up when I perform a "dig" command on a recently spammed domain of theirs.

%dig roguedomain.com

; <<>> DiG 9.8.3-P1 <<>> roguedomain.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 9530
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2

;; QUESTION SECTION:
;roguedomain.com. IN A

;; ANSWER SECTION:
roguedomain.com. 600 IN A ip.add.re.ss

;; AUTHORITY SECTION:
roguedomain.com. 600 IN NS ns1.roguedomain.com.
roguedomain.com. 600 IN NS ns2.roguedomain.com.

;; ADDITIONAL SECTION:
ns1.roguedomain.com. 172800 IN A other.ip.add.ress
ns2.roguedomain.com. 172800 IN A other.ip.add.ress

How can you tell your server has been taken over?

Using SSH, run the following command:

ps w | grep tirqd

If infected, you will be shown at least one running instance of the binary program "tirqd", which is EvaPharmacy's web-mirroring and DNS software.

You may also notice that one or all of the following commands are now missing from your server, as they usually remove them when they take your server over:

passwd
restart
reboot
shutdown

Your server is now being used to host at least one domain for a rogue pharmacy website. The one I was sent (via spam) today was "roguedomain [dot] com".

This server needs to be taken offline and repaired, and obviously the root password needs to be changed, but as mentioned you may not be able to do that.

This is obviously a criminal act. I thought you should be aware.

Sincerely

[Signature]

This has resulted in (often) no response at all from any of the contactees, however I do see that action is taken usually within a day.

This is to get started.

SiL


Top
 Profile  
 PostPosted: Fri Nov 30, 2012 4:31 am   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
It is now also available from http://www.spamtrackers.eu/downloads

There is some sample report information and more background at
http://www.spamtrackers.eu/wiki/index.php/Hijacked_host

Also, old but good, the specific advice at
http://pharmalert.zoomshare.com


Top
 Profile WWW  
 PostPosted: Sun Dec 02, 2012 7:05 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
:silthumb:

SiL


Top
 Profile  
 PostPosted: Wed Dec 05, 2012 5:09 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
Let's review how we can mine the Internet for Eva pharmacy web sites.

Starting from just one existing live site, let's use it as an example of the process: baldwinviagracialis.com
It is one of the Eva pharmacy brands, Toronto Drug Store, covered in the Spamtrackers wiki entry
Load it and examine the source.
The <title> line has "What we offer is best choice of First-Hand Meds in Canada - from ED drugs to antibiotics!"

Look up that title line in a Google search, and you will find others that use it. A WHOIS lookup will also reveal the name of the registrar that accepts payment for the service of registering the domain name, and whether they have suspended it for illegal activity

    ipadlistablet.com - BIZCN.COM, INC.
    baldwinviagracialis.com - HTTP.NET INTERNET GMBH
    canadianviagracanada.com - HTTP.NET INTERNET GMBH
    levitrawelnessteel.com - HTTP.NET INTERNET GMBH
    newpharmacyherbal.com - HTTP.NET INTERNET GMBH
    freedtrapharm.com - NAMESILO, LLC
    healthcarerxhealth.com - NAMESILO, LLC
    herbalpillvitamin.com - NAMESILO, LLC

Since all of these share the same title, it is evident they they are all Toronto Drug Store sites.
I have listed the registrars. These tend to be the last bastion for these criminals. Most registrars act responsibly, and suspend the domains for breaking their terms of service (using the service for unlawful purposes).


Top
 Profile WWW  
 PostPosted: Wed Dec 05, 2012 5:43 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
To find other Eva pharmacy sites, it is possible to use a "guilt-by-association" method. Already we have used the association of the title line to identify other Toronto Drug Store sites using Google.
But if we look at the hosting IP address for these, we can then find other web sites hosted on the same IP address by using some nifty Internet tools.

    largepharmacy.net has address 91.204.162.83 Suspended - ClientHold
    samsungtabdrugstore.com has address 82.102.163.200 Suspended - ClientHold
    antibioticsdrugstore.com has address 199.19.94.147 Suspended - ClientHold
    torontodrugstore.net has address 205.204.87.45
    pillhealthcare.eu has address 209.236.67.220 Suspended - ClientHold
    toronto-drug-store.org has address 178.162.251.16

Once again, take the first one. 91.204.162.83
Using a passive DNS server look up what other names have resolved to that IP
    boschmedpill.com My Canadian Pharmacy NAMESILO, LLC
    boschmedsdrugstore.com My Canadian Pharmacy NAMESILO, LLC
    highestsale.com Canadian Health&Care Mall PSI-USA, INC. DBA DOMAIN ROBOT
    homecaremeds.com Canadian Health&Care Mall PSI-USA, INC. DBA DOMAIN ROBOT
I have appended the registrar responsible.

Another useful tool is call robtex.com. Here, a look-up on that IP address reveals many more
    androidgenericstablet.com
    cmsmedicarepills.com

These will prove to be other brands from Eva pharmacy, such as Canadian Health&Care Mall, My Canadian Pharmacy.

Here I have taken only one of the IP addresses; more pharmacy fraud sites will be found using the others.
More data mining can be performed by selecting the name servers and finding what other web sites are resolved using them.
So it can easily be seen from this simple example that just one spammed domain name from Eva Pharmacy can turn up a swag of additional suspects.


Top
 Profile WWW  
 PostPosted: Wed Dec 05, 2012 6:02 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
Brand Identification.
By loading each of the ones on the list, we can find out what Eva Pharmacy fraud family they are

    tablethealthapp.com Canadian Family Pharmacy
    amilchiquita.com Canadian Health&Care Mall
    mapsrxhealth.com Canadian Neighbor Pharmacy
    levitraopioid.com My Canadian Pharmacy
    medicinepillreckitt.com RxMedications
    baldwinviagracialis.com Toronto Drugstore
    salepillshighest.com US Drugs


Top
 Profile WWW  
 PostPosted: Thu Dec 06, 2012 3:39 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Some specific hijacked host owners I can't reach no matter what:

a) Anything from Chinanet. Nobody answers. Nobody takes action. I've seen three servers get taken offline but that's out of several dozen in the past year, and it's unknown if it had anything to do with my EvaPharmacy reports.
b) 93.99.136.42 [Pavel Suk V - data s.r.o. Fugnerova 4 Vysoke Myto Czech Republic]
c) 218.206.241.178 [China Mobile Communications Corporation - henan]

China Mobile has at least 14 servers since March 2012 that have all been hijacked and overtaken by EvaPharmacy.

If anyone has any different experience trying to reach these people I'd appreciate hearing about it.

SiL


Top
 Profile  
 PostPosted: Thu Dec 06, 2012 4:25 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
For a) and c)

When you want cooperation from China for such a request, it is a good idea to raise it at the CN CERT [English] level

http://www.cert.org.cn/publish/english/121/index.html
Quote:
CNCERT/CC

National Computer network Emergency Response technical Team/Coordination Center of China
Website:http://www.cert.org.cn/
Email:cncert@cert.org.cn
Tel:+8610 82991000
Fax:+8610 82990375
PGP Key:http://www.cert.org.cn/cncert.asc


After supplying convincing evidence of criminal abuse, the terminology is usually a request to "null route or blackhole" the IP address


Top
 Profile WWW  
 PostPosted: Thu Dec 06, 2012 4:37 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
For b)

I presume you have addressed a similar "null route or black-hole" request to Sloane Park Property Trust in Prague

Sloane Park Property Trust, a.s. has been in the telco marketplace since 2000 and it is the 3rd biggest provider of internet connectivity in the Czech Republic now.

abuse-mailbox: abuse@sloane.cz
remarks: trouble: hostmaster@sloane.cz

And from their WHOIS contact
e-mail: Otec@sloane.cz


Top
 Profile WWW  
 PostPosted: Fri Dec 07, 2012 1:49 pm   
Site Admin
User avatar

Joined: Tue May 09, 2006 9:18 am
Posts: 5022
Red Dwarf wrote:
For a) and c)

<snip>

After supplying convincing evidence of criminal abuse, the terminology is usually a request to "null route or blackhole" the IP address

That actually is not what I want them to do. Yes, take the server offline, but then: investigate this and any other servers for weak root passwords and either reinstall the server software or perform patches and updates.

Usually the criminals at EvaPharmacy who take these servers over render them unrecoverable. Awfully nice of them.

SiL


Top
 Profile  
 PostPosted: Fri Dec 07, 2012 3:29 pm   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
spamislame wrote:
Red Dwarf wrote:
For b)

I presume you have addressed a similar "null route or black-hole" request to Sloane Park Property Trust in Prague

No. How would I have found that out?! How do I tell them I found the relationship between Pavel Suk and their company?

SiL

Starting with a whois look-up on the IP address 93.99.136.42
Quote:
inetnum: 93.99.132.0 - 93.99.137.255
netname: VM-NET
descr: V - data s.r.o., Vysoke Myto
country: CZ
admin-c: PS9259-RIPE
tech-c: PS9259-RIPE
status: ASSIGNED PA
mnt-by: SLOANE-MNT
mnt-lower: SLOANE-MNT

source: RIPE # Filtered

person: Pavel Suk
address: V - data s.r.o.
address: Fugnerova 4
address: Vysoke Myto
address: Czech Republic
phone: +420 465 421 760


% Information related to '93.99.128.0/17AS29113'

route: 93.99.128.0/17
descr: Sloane Park Property Trust, a.s.
origin: AS29113


We see the DNS entry is maintained by Sloane.

A Google search on Sloane Park Property Trust leads us to pages like
http://investing.businessweek.com/resea ... =109371522

This contains their own company domain name and web presence:
Quote:
Detailed Description
Slunecni namesti 2588/14
Prague 5
Prague, 158 00
Czech Republic

Founded in 1998
Phone: 420 2 4241 5111
Fax: 420 2 4241 5555
www.sloane.cz


A Whois look-up on sloane.cz gives us
Quote:
contact: OTEC
name: LubomA-r Otec
address: LuÅ_nA¡ 2/716
address: Praha 6 - Vokovice
address: 16000
address: CZ
e-mail: Otec@sloane.cz
registrar: REG-IGNUM
created: 29.06.2004 16:15:00


The different phone numbers and address for Pavel Suk (Vysoke Myto, not Prague) reveal that he may not be part of the whole address range owner, which is described as
Quote:
SLOANE PARK Property Trust, a.s. provides wholesale telecommunications services to operators in the Czech Republic and internationally. The company operates optical fiber cables that use DWDM, CWDM, GE, and SDH technologies to provide services, such as IP connectivity;
etc


Top
 Profile WWW  
 PostPosted: Sun Dec 23, 2012 6:36 am   
You are kiillllling-a my bizinisss!
User avatar

Joined: Tue Jun 27, 2006 2:01 am
Posts: 9227
Here is a list of Eva brands by domain name and registrar, ready for a complaint campaign

DOMAIN NAME - PHARMACY BRAND - REGISTRAR
* fidnaevqui.comMy Canadian PharmacyACTIVE REGISTRAR, INC.
* herbalcannabinoids.atSuspendedAT-DOM
* medsmedicinedisease.comCanadian Family PharmacyCLOUD GROUP LIMITED
* evsqnfny.comCanadian Health&Care MallCLOUD GROUP LIMITED
* sabonatabmed.comCanadian Health&Care MallCLOUD GROUP LIMITED
* thegenericspills.comCanadian Health&Care MallCLOUD GROUP LIMITED
* healthcarecarerx.comMy Canadian PharmacyCLOUD GROUP LIMITED
* isvlhnvo.comMy Canadian PharmacyCLOUD GROUP LIMITED
* outlooksale.comMy Canadian PharmacyCLOUD GROUP LIMITED
* hyrnuzham.comCanadian Health&Care MallENOM, INC.
* jozejhyqn.comCanadian Health&Care MallINTERNET.BS CORP.
* labwydehyj.comCanadian Health&Care MallMAILCLUB SAS
* rxcatholic.comCanadian Health&Care MallNAMESILO, LLC
* remedycutrxpills.ruCanadian Health&Care MallNAUNET-REG-RIPN
* rxdrugstoremedicines.ruCanadian Health&Care MallNAUNET-REG-RIPN
* nutritiondrugstorepharmacy.ruCanadian Neighbor PharmacyNAUNET-REG-RIPN
* rxpharmacycaremeds.ruCanadian Neighbor PharmacyNAUNET-REG-RIPN
* rxpharmacytabletspharmacy.ruCanadian Neighbor PharmacyNAUNET-REG-RIPN
* rxpharmacytechmeds.ruCanadian Neighbor PharmacyNAUNET-REG-RIPN
* rxpharmacytreatments.ruCanadian Neighbor PharmacyNAUNET-REG-RIPN
* pillsdrugstoredrugs.ruMy Canadian PharmacyNAUNET-REG-RIPN
* pillsdrugstorepills.ruMy Canadian PharmacyNAUNET-REG-RIPN
* garciniaherbal.comCanadian Health&Care MallNETLYNX, INC.
* medmedsepub.comCanadian Health&Care MallNETLYNX, INC.
* healthcaremedprescription.comMy Canadian PharmacyNETLYNX, INC.
* healthcarelnessmedical.netCanadian Health&Care MallPSI-USA, INC. DBA DOMAIN ROBOT
* herbalwelgarcinia.netCanadian Health&Care MallPSI-USA, INC. DBA DOMAIN ROBOT
* ipadiet.netCanadian Health&Care MallPSI-USA, INC. DBA DOMAIN ROBOT
* pharmacycialismeningitis.netCanadian Health&Care MallPSI-USA, INC. DBA DOMAIN ROBOT
* ewggesaj.netMy Canadian PharmacyPSI-USA, INC. DBA DOMAIN ROBOT
* kbcbhgdw.comMy Canadian PharmacyPSI-USA, INC. DBA DOMAIN ROBOT
* kidneyprescriptiondiet.comMy Canadian PharmacyPSI-USA, INC. DBA DOMAIN ROBOT
* outlooklnessasale.comMy Canadian PharmacyPSI-USA, INC. DBA DOMAIN ROBOT
* drugenericsmeds.comToronto DrugstorePSI-USA, INC. DBA DOMAIN ROBOT
* cliffpharmacy.comCanadian Health&Care MallPSI-USA, INC. DBA DOMAIN ROBOT
* romneyrx.netCanadian Health&Care MallPSI-USA, INC. DBA DOMAIN ROBOT
* benghazilispharm.comCanadian Health&Care MallREGISTRYGATE GMBH
* retailersmeds.comCanadian Health&Care MallREGISTRYGATE GMBH
* medicinerxpharmacy.ruCanadian Health&Care MallREGRU-REG-RIPN
* rxwellbeing.ruCanadian Health&Care MallREGRU-REG-RIPN
* tabletdropsrx.ruCanadian Health&Care MallREGRU-REG-RIPN
* pilltabletsfitness.ruCanadian Neighbor PharmacyREGRU-REG-RIPN
* reliablerxpillstablets.ruCanadian Neighbor PharmacyREGRU-REG-RIPN
* healthpills.ruMy Canadian PharmacyREGRU-REG-RIPN
* medicinecutrxpills.ruMy Canadian PharmacyREGRU-REG-RIPN
* pharmacydrugstablets.ruMy Canadian PharmacyREGRU-REG-RIPN
* pillmedshealth.ruMy Canadian PharmacyREGRU-REG-RIPN
* pillspharmacyrx.ruMy Canadian PharmacyREGRU-REG-RIPN
* patientswelnesshealthcare.comCanadian Health&Care MallTRUNKOZ TECHNOLOGIES PVT LTD.
* mydrugstorerx.comMy Canadian PharmacyTRUNKOZ TECHNOLOGIES PVT LTD.




ClientHold Updated Dec 26


Top
 Profile WWW  
 [ 150 posts ]  Go to page 1, 2, 3, 4, 5 ... 10  Next

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: Wayback machine and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  


Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
Style originally created by Volize © 2003 • Redesigned SkyLine by MartectX © 2008