Massive spam campaign

I’ve received hundreds of spam comments from one outfit. They’re relatively easy to recognize:

*They send several hundred spam comments to the same blog
*Lots of nonsense domains with subdomains
*Just a few IP addresses used, all on Layeredtech
*The domains usually have dns servers with the same domain name
*The whois info has yahoo e-mail addresses and addresses in African sounding countries.
*They use open proxies for posting

There are some more characteristics that you can find for yourself. Basically, for now, the spam can be blocked, if you look at the logs or the database. But of course, the moment they figure it out, they’ll try and correct those, so let’s keep it quiet for now.

Once you get hit by this spammer, the best bet is to try and block them rather than cleaning your database later. Spam Karma probably zaps them, but if you’re using some other software, beware - do some .htaccess blocking sooner rather than later!

Another interesting factoid: I see several other types of spam comments with the same features. Not sure if we’re talking about the same software or the same spammer doing stuff for various parties or various spam sets.

3 Responses to “Massive spam campaign”

  1. Try Says:

    layeredtech.com is probably the biggest host of spammers in all of the worlkd.

    Just check;
    http://hotpot.se/guest-book-spammers.htm

    The worst thing is that layeredtech.com refuses to do anything aginst the spammers.

    I’ve sent numreous email’s to their abuse department (abuse@layeredtech.com, abuse@support.layeredtech.com, support@layeredtech.com) but they only say that if I continue to report spam from their network they will block me out.

  2. John D Says:

    *groans* Not Layeredtech again *rollseyes*…….. they couldn’t stop a spammer if they were butt ****ing one while both were on the job.

  3. mike of concrete Says:

    Layered Tech aren’t just clueless. They’re malicious. They’ve recently reprogrammed their DNS servers to use a new domain name, ltdomains.com, for RARP searches. This is probably because they’ve been banned by so many people already.

    http://www.belle-aurore.com/mike/weblog.php?id=P298

Leave a Reply