About: Pharmacy Express   Sponge Permalink

An Entity of Type : owl:Thing, within Data Space : dbkwik.org associated with source dataset(s)

Since end November 2010, there have been millions of spams containing links to the Pharmacy Express fraud pharmacy. The criminal nature of the fraud and proof of its false pretenses are clearly documented here. This operation uses the "redirector" approach. The spammed link has a long, padded format, with extra words in it. Common words that are always present as a "fingerprint" are pfizer and viagra. For example * http://will.ulyh.pfizer.pillsdrx.ru * http://pfizer.viagra.sbynmori.humidiclc.ru Anti-spam measures can involve

AttributesValues
rdfs:label
  • Pharmacy Express
rdfs:comment
  • Since end November 2010, there have been millions of spams containing links to the Pharmacy Express fraud pharmacy. The criminal nature of the fraud and proof of its false pretenses are clearly documented here. This operation uses the "redirector" approach. The spammed link has a long, padded format, with extra words in it. Common words that are always present as a "fingerprint" are pfizer and viagra. For example * <a href="http://will.ulyh.pfizer.pillsdrx.ru">http://will.ulyh.pfizer.pillsdrx.ru</a> * <a href="http://pfizer.viagra.sbynmori.humidiclc.ru">http://pfizer.viagra.sbynmori.humidiclc.ru</a> Anti-spam measures can involve
dcterms:subject
abstract
  • Since end November 2010, there have been millions of spams containing links to the Pharmacy Express fraud pharmacy. The criminal nature of the fraud and proof of its false pretenses are clearly documented here. This operation uses the "redirector" approach. The spammed link has a long, padded format, with extra words in it. Common words that are always present as a "fingerprint" are pfizer and viagra. For example * <a href="http://will.ulyh.pfizer.pillsdrx.ru">http://will.ulyh.pfizer.pillsdrx.ru</a> * <a href="http://pfizer.viagra.sbynmori.humidiclc.ru">http://pfizer.viagra.sbynmori.humidiclc.ru</a> These links in turn redirect to a "target" domain, to avoid the spammed links getting blacklisted as is common today. The spammer strategy is to hide the actual location of the pharmacy fraud web sites. Since anti-spam operations will also report the hosting IP address on which illegal web sites are running, this operation takes measures to "bullet-proof" the IPs as well. The target web sites run on a "fast-flux" or rapidly changinge range of host locations. These are a botnet of machines that have been compromised and are running a "reverse proxy" program. The reverse proxy program is a small front-end program that tunnels all request for web pages to hidden back-end servers, providing another level of bullet-proofing. Anti-spam measures can involve 1. * reporting and getting the spammed redirectors suspended (there are over 2500, and they add more daily) 2. * reporting and getting the target site suspended ( there are hundreds, and they change daily) 3. * reporting and having the hosting IPs cleaned (botnet counts are in the millions) 4. * locating, arresting and prosecuting the perpetrators of the Pharmacy Express fraud Looking at that that list, the last one is the only effective solution.
Alternative Linked Data Views: ODE     Raw Data in: CXML | CSV | RDF ( N-Triples N3/Turtle JSON XML ) | OData ( Atom JSON ) | Microdata ( JSON HTML) | JSON-LD    About   
This material is Open Knowledge   W3C Semantic Web Technology [RDF Data] Valid XHTML + RDFa
OpenLink Virtuoso version 07.20.3217, on Linux (x86_64-pc-linux-gnu), Standard Edition
Data on this page belongs to its respective rights holders.
Virtuoso Faceted Browser Copyright © 2009-2012 OpenLink Software