Today I received a letter with a complaint from a regular user of a small forum, which I administer:
Hello, on your forum, I occasionally receive spam in drugs ( private messages ).
It would seem a common thing. Some users have occasionally received some amount of spam in their personal e-mail before this point. But this time, the number of sent messages, judging by the reports, was great, and I turned to decisive measures. And I was surprised a lot: it turns out that I was already “helped” in the fight against spam!
Spam messages were sent from several users who were registered in the interval from March 26, 2009 to March 2, 2010. They did not show activity on the forum, had relatively meaningful nicknames, postal addresses and did not cause any special suspicions.
The fact that spammers, who had been seeing for almost a year, became more active at one moment - not as interesting as the rather dull content of their spam (dating, porn, etc.). It was interesting to have the contents of the private messages of one bot, which registered just a day before the “hour X” I will quote it here in its entirety:
Hello. Today, the forum administrator informed us about the fact of spamming by members of this forum (Spammers: % username% )
We strongly recommend that you go through the online check on our website: _http: //stopspamworld.com/virusscanner/
In case of ignoring the requirements of the organization StopSpam, we reserve the right to file a complaint with your Internet provider about blocking access to the Internet.
Yours sincerely, World Spam Protection Organization StopSpam.
In general, the scheme is simple:
- The part of users that received spam is likely to report this on the forum.
- Another part of users receives a brazen message with threats from the allegedly forum administration and learns that spam is indeed being sent to the forum. Then an inexperienced user in fear clicks on a link to a phishing antivirus scanner, where he gets a good portion of Trojans.
- ...
- profit!
')
And although the scheme is simple, but apparently effective. A search in runet showed that a similar “attack” was recently carried out in many forums. Administrators and moderators, beware.
PS: By the way, on my and some other forums, messages from fake anti-spammers were sent from the account of
Alexey Pleshkov . Look for him and yourself, just in case.