Wikipedia talk:WikiProject Spam

Page contents not supported in other languages.
Source: Wikipedia, the free encyclopedia.

This is an old revision of this page, as edited by MER-C (talk | contribs) at 12:54, 3 August 2012 (→‎seeraa.com: +). The present address (URL) is a permanent link to this revision, which may differ significantly from the current revision.

    When reporting spam, please use the appropriate template(s):
    As a courtesy, please consider informing other editors if their actions are being discussed.
    {{Link summary|example.com}} -- do not use "subst:" with this template - Do not include the "http://www." portion of the URL inside this template
    • {{IP summary}} - to report anonymous editors suspected of spamming:
    {{IP summary|127.0.0.1}} --- do not use "subst:" with this template
    • {{User summary}} - to report registered users suspected of spamming:
    {{User summary|Username}} -- do not use "subst:" with this template

    Also, please include links (

    "diffs"
    ) to sample spam edits.

    Indicators
    Reports completed:
     Done
    no No action
     Stale
    Defer discussion:
     Defer to XLinkBot
     Defer to Local blacklist
     Defer to Global blacklist
     Defer to Abuse filter
    Information:
     Additional information needed
    information Note:

    hoparoundindia.com - can someone look into this?

    Anyone have time to look into this link? I saw that

    talk) 15:48, 23 July 2012 (UTC)[reply
    ]

    --

    talk) 16:51, 24 July 2012 (UTC)[reply
    ]

    Most of the remaining links that I've seen were added as references. Refspam perhaps? Its hard to tell if the site is reliable, Indian geography isn't really my field. If the site is reliable I'd say it isn't doing any harm as a reference. ThemFromSpace 17:07, 25 July 2012 (UTC)[reply]
    Adsense related
    Adsense google_ad_client = pub-2014564446906822 (Track - Report - reverseinternet.com • meta: Track - Report)
    --Hu12 (talk) 19:39, 25 July 2012 (UTC)[reply]

    The site is clearly intended to promote tourism. I don't see any indication that they meet

    talk) 15:30, 26 July 2012 (UTC)[reply
    ]

    These could all be the same person. --
    talk) 15:55, 27 July 2012 (UTC)[reply
    ]
    Also found on fa fwiw. Many on en are from Rkiran t (talk · contribs), who started posting them on 19 March.LeadSongDog come howl! 22:05, 27 July 2012 (UTC)[reply]
    Sorry, but "fa" = Farsi? --
    talk) 13:50, 28 July 2012 (UTC)[reply
    ]
    Googling "hoparoundindia.com" site:wikipedia.org finds [1] and [2] in addition to all the English pages. LeadSongDog come howl! 23:45, 29 July 2012 (UTC)[reply]
    Looks
    talk) 23:45, 30 July 2012 (UTC)[reply
    ]
    One editor added it a source when they had difficulty finding anything better. While he agrees it's promotional in nature, I'm not against keeping it for clear statements of fact about locations or regions, but not for history, religion, etc, and certainly not for listing "local attractions." --
    talk) 15:53, 1 August 2012 (UTC)[reply
    ]

    spam to www.transfermarkt.co.uk

    130.43.40.136 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    transfermarkt.co.uk: Linksearch en (insource) - meta - de - fr - simple - wikt:en - wikt:frSpamcheckMER-C X-wikigs • Reports: Links on en - COIBot - COIBot-Local • Discussions: tracked - advanced - RSN • COIBot-Link, Local, & XWiki Reports - Wikipedia: en - fr - de • Google: searchmeta • Domain: domaintoolsAboutUs.com — Preceding

    talk • contribs
    )

    Funny, because I whitelisted this site on the linkwatchers just before this report was made due to widespread use (OVER 9000 records and thus, no stats). Removed, though I think at least some of these weren't spammed. MER-C 11:16, 28 July 2012 (UTC)[reply]

    airtet.in

    Adsense google_ad_client = pub-7144942111468669 (Track - Report - reverseinternet.com • meta: Track - Report)

    Spammers

     Defer to Local blacklist MER-C 10:01, 27 July 2012 (UTC)[reply]

    Updated. MER-C 02:21, 30 July 2012 (UTC)[reply]

    sinelog.net

    Previous incidents
    Sites spammed

    Google Analytics ID: UA-32745659 - (Track - Report - reverseinternet.com • Meta: Track - Report)

    Google Analytics ID: UA-3395138 - (Track - Report - reverseinternet.com • Meta: Track - Report)

    Spammers
    Registrant

    BIREYSEL FARUK ALACAM

    See also

     Defer to Local blacklist MER-C 11:02, 28 July 2012 (UTC)[reply]

    Continued:
    MER-C 02:23, 30 July 2012 (UTC)[reply]

    2012-london-olympics-news.com and dhruvplanet.com - can someone look into this?

    Related links
    Editors
    Probably should be considered for immediate blacklisting given the problems with the related links --
    talk) 14:16, 28 July 2012 (UTC)[reply
    ]
    Cleanup of 2012-london-olympics-news.com done.
    (As an aside, it looks like there are other bloggers doing the same thing: creating websites to carry news related to the Olympics, then spamming them to Wikipedia.) --
    talk) 03:50, 29 July 2012 (UTC)[reply
    ]
    The site appears to be plagiarizing articles. --
    talk) 21:30, 29 July 2012 (UTC)[reply
    ]
    I've requested that 202.134.156.161 be blocked as the only one continuing to spam the olympic site. Still looking at the other sites... --
    talk) 19:54, 30 July 2012 (UTC)[reply
    ]
    Adsense google_ad_client = pub-9445189103749654 (Track - Report - reverseinternet.com • meta: Track - Report)
    Previous incidents:
     Defer to Local blacklist MER-C 11:33, 31 July 2012 (UTC)[reply]

    Questions about "Chinese Knockoff Spam"

    Continuing earlier research about link spam has led me to intensive archive browsing. It is impossible not to notice the many-many iterations of "Generic Chinese Knockoff Spam" that appear throughout 2010 and 2011 (now inactive?). Given that this time is far past, it inhibits my investigation a bit. Moreover, it seemed the team here usually blacklisted it without much discussion or fanfare. For these reasons, I'd like to ask a few questions of those who were active at that time:

    • Was there a particular modus operandi for their actions?
    • How were "related domains" found? I notice that usually only a few domains were actually spammed, but many more were pro-actively blacklisted on some basis? Something to do with WHOIS registrations?
    • What was actually at the destinations? Were there just a couple of core sites that they endlessly purchased new domains for?
    • How do you think they got all those IPs? Do you think this was a single person or a team? Were they utilizing proxy servers, or something more powerful?
    • Do you have any evidence that these spam links were being used elsewhere? blog/forum spam?
    • Do you think these links were added by a human acting quickly, or were there automation scripts?
    • Has any attacker near this scale/complexity been seen before?

    Thanks for all you help, West.andrew.g (talk) 21:16, 28 July 2012 (UTC)[reply]

    From top to bottom:
    • Profit.
    • Web search for various unique Chinglish phrases.
    • They usually aren't redirects. Chinese knockoff domains are copypasta/reskins.
    • I don't know, but there is definitely more than one person doing it.
    • Google is your friend. Something like "louis vuitton cheap comment" will do. This is an internet wide problem.
    • Most likely human sweatshop spam.
    • No.
      This is organized, as in organized crime
      .
    MER-C 03:03, 29 July 2012 (UTC)[reply]
    In case people are not aware, Andrew is probably not just curious—he is able to monitor link additions and perform complex processing. If there were patterns that might be detected (article categories, timing of link additions, ranges of IPs, and more), his processing may be of assistance (potentially, it could do more background checking than XLinkBot). The copypaste/reskins observation is of interest—it would be difficult, but it might be possible to guess that the target of an added link is a reskin. Another clue might be the whois registrant for the domain, although whois lookups can become expensive. Johnuniq (talk) 03:22, 29 July 2012 (UTC)[reply]
    Johnuniq is correct. I have several corpora of Wikipedia link spam, run a link processing engine, and have worked heavily in anti-vandalism development (see WP:STiki. No offense, but I found MER-C's answers were a bit sarcastic/brief, whereas I was hoping to have a more technical discussion on the topic of Generic Chinese Knockoff Spam (CGKS). If anyone seems to be persistent and technically sophisticated in profiting off of wiki via link spam, it would seem to be those folks. Understanding their attack vectors would seem key to understanding Wikipedia's spam weaknesses. So to go top to bottom again, with a little more detail:
    • Yes, profit is obviously the over-arching MO. However, the actions are just puzzling. Sometimes they blank articles with links. Sometimes they insert 5-10 at a time in the middle of an article. Sometimes they post to talk pages. They obviously aren't trying to blend in and evade the first wave of anti-vandal checks. With this behavior so obvious to patrollers, its difficult to imagine how the links survive long enough to extract any utility. It's also a bit odd that they had to know the accounts/IPs would be blocked, but didn't seem to use accounts to their full capacity (i.e., spamming at speed until blocked). Real spam outfits know how things work and have technical sophistication, these folks just seemed dumb and random at times (which made me wonder about automation).
    • I don't imagine you actually searched Chinglish phrases. I imagine the related domains were sitting on the same server?
    • The destination sites were actually selling products, I assume? With this complexity I imagined they were probably part of a larger affiliate program into the actual goods, but probably using copypaste/reskins themselves - i.e., some central backend was fulfilling any "orders"
    • Looking at the accounts used was a bit perplexing. For their poor understanding of the interface and norms (i.e., spamming talk pages, they still managed to register some accounts. As far as the IPs involved, they seem all over the place. This isn't local IP hopping. They are geographically distributed. This screams proxy servers to me. In the worst case, it could be a botnet (but these attacks simply don't seem large enough for that). Why do you believe it is more than one person? The spam never really happened so quickly that it couldn't be a single person.
    • I understand that GCRS is a widespread Internet problem, but there are certainly many outfits involved in it globally. I was curious about the domains Wikipedia was dealing with in particular. They've paid for 1000s of domain registrations, so if they weren't getting used on wiki, they had to be showing up elsewhere. Strange, then, why they didn't show up on wiki? 50 or so pockets of spam over 1.5 years isn't *that* much for an outfit that seems to have these capabilities.
    • -skip-
    • I understand the organized crime ramifications of spam outfits. What I was asking if anyone/anything had come close to this in your experience *on Wikipedia"? My interest here is confined to wiki/Wikipedia experience.
    Additional questions:
    • Were all/most of these blacklisted? Over at meta? Including the "related but not yet seen on wiki" set? MER-C always seemed to lodge the reports, but it wasn't clear the blacklist treatment of these guys.
    Thanks for your help. More than a casual passer-by, I am trying to develop tools/algorithms that aide the project. I'd be happy to take this up on IRC if that is easier for anyone involved. Thanks, West.andrew.g (talk) 04:04, 29 July 2012 (UTC)[reply]
    P.S. Why when I do an archive search for "Generic Chinese" or any variant thereof I only get 24 results? I have more luck searching for "2.0", "3.0", "4.0", but this only gets me one at a time and doesn't help with the odd ones, i.e., "8.5". Thanks, West.andrew.g (talk) 04:36, 29 July 2012 (UTC)[reply]
    Thanks Andrew, however this page is not a good place for discussion because it is subject to a lot of churning as new reports come in.
    @MER-C: Do you think there is value in continuing this elsewhere? A subpage dedicated to the topic? I don't think IRC is desirable as complex statements there are difficult—a wiki page would help with development of any ideas, and may be useful for future discussions. I suggest moving this section to a subpage, with a link here. Johnuniq (talk) 04:42, 29 July 2012 (UTC)[reply]

    I think that this is very well within the capabilities of LiWa3/XLinkBot. Problem is that XLinkBot only reverts, spammers will re-insert add nausiam, they don't care when accounts get blocked (just move to another IP), they don't even care when their links get blocked (they just copypaste or reskin to a new domain). It is how they make money. I think that it is therefore valuable to have these link blanket-blacklisted. Preemptively, it saves us, and XLinkBot, a lot of work. If the spammers found out Wikipedia is a target (and they obviously did, some of the links were spammed to Wikipedia), then the fact that only so few links were actually added (while the internet at large was targetted) may actually show MER-C's efficiency here: either they did not spam because their domains were already blacklisted, or the sweat-shop workers were told to not make a priority of Wikipedia, as it was too effective too fast.

    Andrew, I'd like to hear more about your detection systems, maybe there are things that can be incorporated into LiWa3 so we can work in real time and ask COIBot to make reports. Indeed, maybe a dedicated subpage is better. --Dirk Beetstra T C 05:09, 29 July 2012 (UTC)[reply]

    Regarding IRC, MER-C and I generally hang around in #wikipedia-spam-t (the main 'command center' for XLinkBot, though it , you may want to join us there. Regarding doing everything on-wiki - I'd like to put

    WP:BEANS into consideration there. --Dirk Beetstra T C 05:12, 29 July 2012 (UTC)[reply
    ]

    However, the actions are just puzzling. Sometimes they blank articles with links. Sometimes they insert 5-10 at a time in the middle of an article. Sometimes they post to talk pages. They obviously aren't trying to blend in and evade the first wave of anti-vandal checks.
    These guys (1) probably don't speak English too well and (2) are targeting the entire interwebz. This isn't "pay $X to get your link into Wikipedia" spam -- these spammers don't specialize and are paid piecewise per comment => quantity over quality. They do not target Wikipedia specifically -- we're just another website to be spammed. Something like this, I guess. (I have read a more detailed article on this subject but the link escapes me). Usernames are often the same across websites. Messages are usually copypasta. Automation (if used) is usually achieved with XRumer. If there are bots, they pass the Turing test (only because the humans are so dumb).
    I don't imagine you actually searched Chinglish phrases.
    Yes, I actually did. Examine the spam reports here closely and you will find the search phrases I used.
    The destination sites were actually selling products, I assume?
    Mostly. There are also
    splogs
    for the knockoff domains.
    Something to do with WHOIS registrations?
    WHOIS data isn't really helpful for knockoffs. Come to think of it, this might be an example of smurfing. Re: copy and paste reskins -- they look the same, and many use the same server-side software. (So do many other sites).
    blacklist treatment of these guys
    Blacklisted on sight, uncontroversially.
    Why do you believe it is more than one person? The spam never really happened so quickly that it couldn't be a single person.
    Remember, it's the entire internet being targeted. What you see here is the tip of the iceberg.
    Do you think there is value in continuing this elsewhere?
    I'll "sticky" this by adding an appropriate timestamp. Things tend to die on subpages.
    I apologise for my brevity, but the OP should have put a little more effort into asking the initial questions. MER-C 09:46, 29 July 2012 (UTC)[reply]
    Sticky. MER-C 09:36, 29 August 2012 (UTC)[reply]
    FWIW, I've compiled all the reports in archives into a single page @ User:West.andrew.g/GCKS

    Help on examiner.com

    I'm trying to fix in article, and I'm running into problems using examiner.com news articles. I get the silly spam bot warning that it's a spam site, when it is most certainly not. Maybe it's not the New York Times, but they are a legitimate news source, and in fact, I'm using it for a book review for a wikipedia article. Useless bot in this case, though I'm sure there's some reason why this is happening. Can someone fix this? Or am I stuck with putting in the source without the http:// ? I'm using www.examiner.com/article/disproving-christianity-a-controversial-new-book link. But other links are also not working. SkepticalRaptor (talk) 02:13, 30 July 2012 (UTC)[reply]

    they are a legitimate news source
    The Washington Examiner
    .
    If you really want to use this article, see MediaWiki talk:Spam-whitelist. MER-C 03:45, 30 July 2012 (UTC)[reply]
    More Wikipedia bureaucracy. Not worth the trouble for a book review. SkepticalRaptor (talk) 23:03, 30 July 2012 (UTC)[reply]

    martinlawfirm.com

    Google Analytics ID: UA-788456 - (Track - Report - reverseinternet.com • Meta: Track - Report)

    Spammers

    MER-C 09:53, 31 July 2012 (UTC)[reply]

    Long term Benoy K Behl Spamming and promotion

    Article
    Accounts

    Mitra2412 (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    59.164.5.53 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    61.17.131.138 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    61.17.131.138 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    219.65.251.31 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    61.17.131.84 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    219.65.251.231 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    --Hu12 (talk) 10:55, 31 July 2012 (UTC)[reply]

    User:Sobur09

    something to say?) 04:26, 1 August 2012 (UTC)[reply
    ]

    affiliatefuture.com

    Spammers

    No redeeming value.  Defer to Local blacklist MER-C 10:23, 1 August 2012 (UTC)[reply]

    diplomacy.edu Spamming

    Google Analytics ID: UA-364439 - (Track - Report - reverseinternet.com • Meta: Track - Report)
    Accounts

    Tanja Nikolic (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Valentino k (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    --Hu12 (talk) 17:41, 1 August 2012 (UTC)[reply]

    Return of Product Development Institute and Stage-Gate International Spamming

    Google Analytics ID: UA-684908 - (Track - Report - reverseinternet.com • Meta: Track - Report)
    Spammed
    Article Spam
    Accounts

    EmirOzdemir10 (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam) (Emir Ozdemir, Product Manager)
    70.25.21.97 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    Sunil Bechar (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam) (Marketing Communications at Stage-Gate Inc)
    69.159.45.85 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    69.157.46.2 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    65.92.52.28 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    [email protected] (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Dkrempa (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam) (Daniel Krempa. Director of Digital Platforms at Stage-Gate Inc)
    Sbechar (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam) (Marketing Communications at Stage-Gate Inc)
    Izabellalis (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam) (Izabella Lis. Product Manager at Stage-Gate International)
    Jenarl (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    130.215.109.204 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    --Hu12 (talk) 22:53, 1 August 2012 (UTC)[reply]

    Virtual Medical Centre Adsense link-farming Spam

    Adsense google_ad_client = pub-2899426054289428 (Track - Report - reverseinternet.com • meta: Track - Report)
    Articles
    Accounts

    Medicalcentre (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Medical info (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Baggy75 (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    116.212.205.246 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    203.59.102.88 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    Musicnotes117 (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    203.59.45.176 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    Fascia.far (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Sambo72 (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    203.59.102.88 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    Long term multi-article, multiple Adsense related domains. replacing existing links with ones own link is never a sign of good faith. --Hu12 (talk) 03:23, 2 August 2012 (UTC)[reply]

    DocuWare Spamming

    Google Analytics ID: UA-5632806 - (Track - Report - reverseinternet.com • Meta: Track - Report)
    Article spam
    w:fr:DocuWare
    w:de:DocuWare
    w:es:DocuWare
    w:it:DocuWare

    de:Benutzer:ECMdoku/DocuWare

    Accounts
    Accounts

    ECMdoku (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)

    es:Special:Contributions/ECMdoku
    it:Special:Contributions/ECMdoku
    fr:Special:Contributions/ECMdoku
    de:Special:Contributions/ECMdoku

    Mary K. Williams (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Klsmith88 (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Docuware s.l. (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)

    es:Special:Contributions/Docuware s.l.

    DDBritta (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    Floyd2Carolina (talk · contribs · deleted contribs · blacklist hits · AbuseLog · what links to user page · count · COIBot · Spamcheck · user page logs · x-wiki · status · Edit filter search · Google · StopForumSpam)
    217.91.107.21 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)
    85.48.252.237 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)

    es:Special:Contributions/85.48.252.237

    88.30.0.28 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot)

    es:Special:Contributions/88.30.0.28

    91.199.155.2 (talk • contribs • deleted contribs • blacklist hits • AbuseLog • what links to user page • COIBot • Spamcheck • count • block log • x-wiki • Edit filter search • WHOIS • RDNS • tracert • robtex.com • StopForumSpam • Google • AboutUs • Project HoneyPot) --Hu12 (talk) 10:56, 2 August 2012 (UTC)[reply]

    imcredel.com

    links
    accounts

    Multiple SPA accounts adding misleading links and hijacking existing "official links" from multiple articles to point to this site. --- Barek (talkcontribs) - 04:14, 3 August 2012 (UTC)[reply]

    latestmoviez.com

    Adsense google_ad_client = pub-0045382496712859 (Track - Report - reverseinternet.com • meta: Track - Report)
    Google Analytics ID: UA-236291 - (Track - Report - reverseinternet.com • Meta: Track - Report)

    Spam pages
    Sites spammed
    • redirects to latestmoviez.com
    • redirects to latestmoviez.com
    • redirects to latestmoviez.com
    Spammers

     Defer to Local blacklist MER-C 12:36, 13 July 2012 (UTC)[reply]

    Updated. MER-C 09:51, 15 July 2012 (UTC)[reply]
    talk) 15:22, 15 July 2012 (UTC)[reply
    ]

    Post-blacklist spamming:

    Spammers

    MER-C 10:02, 20 July 2012 (UTC)[reply]

    Continued:
    MER-C 01:56, 21 July 2012 (UTC)[reply]
    Also, plain text spamming. MER-C 06:21, 22 July 2012 (UTC)[reply]

    Another day, another domain:

    MER-C 01:50, 23 July 2012 (UTC)[reply]

    I note that the latter 2 are redirect domains (which should be on meta without even thinking about it) - I've instructed XLinkBot to do whack-a-mole. --Dirk Beetstra T C 06:49, 23 July 2012 (UTC)[reply]

    MER-C 11:08, 3 August 2012 (UTC)[reply]

    seeraa.com

    Google Analytics ID: UA-18179304 - (Track - Report - reverseinternet.com • Meta: Track - Report)

    Spammers

     Defer to Local blacklist MER-C 12:24, 3 August 2012 (UTC)[reply]