I found a URL somewhere, that had an interesting mechanism for throwing bloggers and forum visitors off.
The spammer is targetting these search engines:
google, yahoo, aol, msn, altavista, web.ask.com, ask.co.uk, dogpile, excite, teoma, earthlink, hotbot.
If you’re accessing the spamvertized page from any other referrer, the script throws up a 404 error page, leading you to believe the page has already been yanked by the webhost.
That’s not true, because if you access it with a referrer from one of those domains, you’ll see the actual intended end page, which is entirely different.
The trail is complex, and goes through a few well known (to me) domains.
It eventually ends up with an affiliate ID to a pay for porn site, probably unrelated to the spammer, except he’s making money off it.
One of the domains has this whois info:
Registrant
Andrey Shchegolikhin
Servibox, buzon N 442, Patrisio Ferrandiz 40
Denia, Alicante 03700
Spain
email: dyakon@mail.ru
phone: 1-800-342-4243
That e-mail address connects it to the spammer I described in this post.
This spammer is using the exact same domains for cutout addresses before reaching the final destinations.
One of the cutout domains has this whois info:
Fethard
Andrey Shchegolikhin (dyakon@mail.ru)
1-800-342-6424
Servibox, buzon N 442,
Patrisio Ferrandiz 40
Denia, - 03700
ES
Another cutout domain has this whois info:
Crutop
Alexander Morozov (webmaster@se-traf.com)
Varvarka, 6
Moscow
null,128037
RU
Tel. +11.2345234655
Another cutout domain also belongs to Alexander
Update
This spammer also did some referrer spamming, and targeted webalizer pages.