The other day there was a disturbing report  that found that nearly 90 percent of all pharmacy ads appearing on Bing’s sponsored search engine results were illegal pharmacies … Yikes! … well most of us already know that “Sponsored Results” are not to be trusted …

I certainly don’t think Bing is the only one at fault here … since the FBI states – “More than 80,000 “portal” websites currently sell ad space for these medications and link to one of more than 1,400 “anchor” websites that allow customers to place orders through illegal pharmacies“.

The full report is here … (.pdf) and in that report “klikadvertising” is mentioned … these culprits are also involved in many of the Fraudware Antispyware scams currently on the Internet. Anyway LegitScript also released their Top 10 so I thought I’d check them out and possibly add those to the HOSTS file. Now I have no intension of adding all these illegal pharmacy sites as there are just too many, and nothing malicious happens when you visit these sites.

The best way I feel to protect users is to add their payment sites to the HOSTS file … at least that way it would protect users from making ill-advised purchases … or worse … just imagine what’s in those counterfeit drugs! I started visiting these sites and found my own disturbing trend which was not mentioned in any of the articles … (see below)

The above site is listed as one of the Top 10 (above) … when you click the “Next step” …

 As you can see you are redirected to “” via a certain certificate … I’m not even going to comment.

 Visiting another of the above mentioned Top 10 which is described as “The website claims to sell drugs from Canada, but the authors submitted an order, and received counterfeit Cialis, without a prescription from India.” If you read the full report LegitScript put a lot of time and effort into their finding. Going so far as to actually purchase products and have them tested …

 Another certificate from the same source as above and a Truste icon … ouch!

Again we see a redirect from “” to “”

[Subject], OU=Comodo EV SGC SSL, O=RX Corp, STREET=3155 Hickory Hill Rd, L=Memphis, S=TN, PostalCode=38115, C=US, OID.”V1.0, Clause 5.(b)”, OID., OID., SERIALNUMBER=0582044

  CN=COMODO EV SGC CA, O=COMODO CA Limited, L=Salford, S=Greater Manchester, C=GB

[Serial Number]

Now to be fair I also found a Verisign certificate for “” … so please don’t nag me about I’m picking on one vendor …

[Subject], OU=Terms of use at (c)05, OU=buySAFE IT, O=buySAFE Inc, L=Arlington, S=Virginia, C=US

[Issuer] Ref. LIABILITY LTD.(c)97 VeriSign, OU=VeriSign International Server CA – Class 3, OU=”VeriSign, Inc.”, O=VeriSign Trust Network

[Serial Number]

You can view a very short video LegitScript posted on YouTube for … there are several others as well … I also found another site that contains “illegal pharmacies identified by the FDA, HealthPricer and other official bodies”

First on their list was “” which redirects to “” which redirects to … “”

[Subject], OU=Comodo InstantSSL, O=Pharmos Limited, STREET=Leningradsky prospekt 143-26, L=MOSCOW, S=MSK, PostalCode=149501, C=RU

  CN=UTN-USERFirst-Hardware, OU=, O=The USERTRUST Network, L=Salt Lake City, S=UT, C=US

[Serial Number]

Seems is hosted on the same IP block as several other scam sites … most using “” as their “check out” payment service.

# [Moskvacom][AS2118][ –] (Google Diagnostic report for AS2118) #[ScamFraudAlert.Pharmacy] #[Spamdexing] #[ScamFraudAlert.Pharmacy]

Many of the other sites HealthPricer listed no longer exist …

Hopefully these certificate issuers and Truste will take a better look into the activities of the sites that were mentioned … after all illegal activities are illegal!

