The other day, we contacted the domain registrar of the notorious pharmacy spam site at www.toppharmacy.com. Now, it’s gone. But a pharmacy spam ring is still sending junk messages to advertise this dead website.
So who’s behind this pharmacy spam? Well, we don’t have the answer. But we now have strong reasons to believe that this pharmacy spam is actually run by the same spam group running the illegal software store called Software Download. We have put some of their domains to death. They have found their temporary new home at laga-soft.com.
Comparing two different spam messages, we have found similarities.
The source codes reveal that one message arrived at 12:44:08 in April 9 while the other spam message arrived at 12:50:43 on the same day.
Furthermore, one of the source code shows that the character set used is KOI8-R, an 8-bit character encoding for Russian and the Cyrillic alphabet. They often say that many Russian criminal groups are behind running phishing websites and sending spam messages.




