More “GUID Spam”
Darren recently mentioned that he has been receiving a pointless kind of spam in the last couple days he is calling GUID Spam:
I’ve been getting a new species of comment spam. They’re meaningless strings of numbers and letters, often without links. I’ve been calling it GUID (globally unique identifiers) spam because that’s what they most resemble.
I’ve been seeing it too:
Website: 5d0813b34159 (IP: 213.251.189.201 , gw1.ovh.net)
URI : 5d0813b34159.us
Excerpt:
<strong>5d0813b34159…</strong>
5d0813b34159b436b3d8…Website: 68c95c8a9410 (IP: 64.131.83.138 , srv.anony-mous.info)
URI : 68c95c8a9410.us
Excerpt:
<strong>68c95c8a9410…</strong>
68c95c8a9410017afcac…Website: 853bf2b234ad (IP: 64.141.108.29 , 64.141.108.29)
URI : 853bf2b234ad.us
Excerpt:
<strong>853bf2b234ad…</strong>
853bf2b234add2151fa1…Website: 087f722478aa (IP: 67.159.44.134 , TE01.techentrance.com)
URI : 087f722478aa.us
Excerpt:
<strong>087f722478aa…</strong>
087f722478aaf73ffa8f…Website: 655dec378813 (IP: 74.54.136.66 , corsica.websitewelcome.com)
URI : 655dec378813.us
Excerpt:
<strong>655dec378813…</strong>
655dec3788132527049e…
This kind of spam looks like a partial md5 sum of the URL, or it could just be random. Perhaps the spammer is using compromised hosts to drop these tags, and then coming back over time to see when they are removed, or if they stay up forever. That would give him a list of possible sites to spam in the future.
Posted in Spam
Tagged with pointless kind, meaningless strings, md5 sum, mous, couple days, corsica, spammer, excerpt, lt, uri, spam, hosts
Which comes back to blocking generally .INFO domains and websites in the hosting range. modding the htaccess just do fine.