I hate scammers; especially if they are to do with peoples health. Just like in this case with the fake Canadian pharmacy. This is a very old and famous scam, in which I remember reading at one point a botnet was sending out millions of spam emails a day to generate traffic to their websites. This could have a huge impact on vulnerable people who order medication for health reasons, and for druggos too I suppose. I do not know whether or not you get the products or not, and I do not know whether the products are legit.
My initial target was this website which I found on Google one day:
Ok obviously this is a scam lets be honest here. Its a php file in a dir called doc and the root of the site is a completely different website in iteself anyway.
Did I mention this site runs Joomla and is vulnerable to hell.
Not to mention this page is dodgy as hell:
Those two images were located here:
Which I got Imgur to remove for me to help kill the traffic reaching the end sites.
The images link to the following website:
Which obviously has a .ru russian domain name and is hosted in le Russia:
|IP range||18.104.22.168-22.214.171.124 CIDR|
|Country||Russian Federation (RU)|
|City||Moscow (Central Administrative Okrug)|
|Time zone||Asia/Krasnoyarsk, GMT+0700|
|Local time||02:30:46 (KRAT) / 2016.05.14|
This website looks even more dodgy:
From here I will not investigate the site any further up until I have gathered enough information and intelligence from the targets to pass over to the authorities.
I actually found another hacked site within their network:
Did I mention this site runs WordPress and is vulnerable to hell. Do you see the pattern here? If you are using WordPress, Drupal or Joomla, KEEP IT UPDATED!!! AND DONT USE DODGY PLUGINS! cannot stress this enough.
Anyway funnily enough I found the hackers FilesMan backdoor here:
Although it is password protected (aw, maybe later).
Here are a few others I found:
Google dork: https://www.google.co.uk/search?sclient=psy-ab&hl=en&biw=1920&bih=971&site=webhp&q=%22alternative+and+coupon+codes%22&oq=%22alternative+and+coupon+codes%22&gs_l=hp.3…185672.185672.5.1857126.96.36.199.0.0.0.0.0..0.0….0…1c.1.64.psy-ab..1.0.0.j_3locg6Lsk&pbx=1&bav=on.2,or.&bvm=bv.122129774,d.bGs&ech=1&psi=qA47V6u6I-qC6AT34ZiwBA.1463488168987.13&ei=3A47V4HyG6mVgAaU3aToBg&emsg=NCSR&noj=1
But alas, we have a much bigger operation on our hands. The following are only some of the fake Canadian pharmacys I have found:
More to follow soon.