I got a comment to an old post that seemed fairly well on topic, but it had a “commercial” link, so I dug deeper. It’s a manual spam, meaning it was done with a browser, not a script.
He first came in from a Google search October 6, and left after checking out the post
Query syntax:
Name (required) + Website + comments + blogs + office machinery
He came back October 21 after a Google search, and posted
Query syntax:
Name (required) + Website + comments + blogs + fax machines
The text in the spam comment was this one:
One that has no comment spam (now) had 700+ comment spam entries before the plugin.
That sentence is lifted from an existing comment on that page and then used for the spam comment.
And the site was: shredderwarehouse.com
It’s kind of unusual for business sites to have whois protection, but this one does.
It’s on 68.178.184.239, which is ip-68-178-184-239.ip.secureserver.net. It appears that the IP has changed hands very recently. All the sites listed for it are on another IP by now.
It’s been spamvertized at least since August 30th. And it’s been spamvertized together with evision.com.pk, which is owned by someone in Pakistan. The spam I received also came from an IP in Pakistan. They’ve also spammed for flowergirldressforless.com, which wants people to think they’re based in California. There’s a mailbox rental company at that address, so they’re not really at the address listed in the whois. Their phone numbers are local to that area, though.
If I were to guess, I’d say it’s quite possible eVISION is a Black Hat SEO company that’s spamming for themselves as well as customers.