Welcome to Geeklog Saturday, May 18 2013 @ 09:47 PM EDT
Well, we've had spam for porn, pills, and poker - but contact lenses?
Last week, someone actually registered with several Geeklog sites only to post comment spam for contact lenses. I actually thought that was somewhat amusing, but it seems there's more of this coming.
We are now seeing referer spam for a site advertising contact lenses:
| Spamvertized site: | contact-lenses-x7 DOT com |
| Domain registered with: | Names4ever.com |
| Site hosted at: | 72.9.234.170, Global Net Access LLC, Atlanta |
| Referer spam came from: | 63.247.74.90, Global Net Access LLC, Atlanta |
It doesn't look like the two incidents are directly related, though. Last week's spam was for:
| Spamvertized site: | lens DOT excellentoffers DOT info |
| Domain registered with: | DirectNIC |
| Site hosted at: | 216.195.42.217, APS Telecom |
I don't have the IP address of that spammer any more, but it belonged to an ISP in Hong Kong.
The excellentoffers site is apparently registered to some Alex Antuacesko in Romania, while contact-lenses-x7 is registered to some Marlon Santos in Seattle, WA. Both addresses may be fake, of course, but at least the Seattle address looks legit.
Anyway, it can't hurt to add both domain names to your Personal Blacklist. And throw in a few key phrases like "contact lens" (so that it also matches "contact lenses"), too, while you're at it.
The following comments are owned by whomever posted them. This site is not responsible for what they say.
63.247.74.90
---
tokyoahead.com
bye, Dirk
The same person is apparently still doing referer spam, only now it's for flower-delivery-2day DOT com.
The domain is hosted on the same server as the contact-lenses-x7 site above and the person is still spamming from the same IP address (even though I send complaints to his hoster/ISP).
So I'd say you can safely block 63.247.74.90 - nothing good will be coming from there:
bye, Dirk
... and now it's cash-advance-z3 DOT com. Same server, same IP address the referer spam is coming from - the same guy, obviously.
As I said, block that IP ...
bye, Dirk