Author Topic: PharmSpam Domains  (Read 3320 times)

0 Members and 1 Guest are viewing this topic.

August 25, 2009, 08:57:47 pm
Read 3320 times


  • Sr. Member

  • Offline
  • ****

  • 179
Once host is infected it starts sending out pharmspam, the host checks in here:

Gets email address list along with spam subject/body:

Subject:###  long sex! ###
MIME-Version: 1.0
Importance: High
Content-Type: text/plain; charset="ISO-8859-1"
Content-Transfer-Encoding: 7bit
Drug Online Your discount
Looks like : Small blue diamond-shaped pills

Various domains used in spam body. All prepended with canadian (seems like more good ol pharmspam). All resolve to (APNIC).

The above IP's/domains aren't in the list yet so thought I would share.