Weird spam malreports. TOR...?
Steinar Bang <sb <at> dod.no>
2013-05-01 10:03:53 GMT
I am seeing some strance malreports to various Tiki groups. Often
multiple reports to the same article (which has been invarably a
malreport), often the exact same user agent with different IP addresses.
The only thing I can think about is that the reporters are using TOR.
However, their motivation baffles me. Both the target of the malreports
and multiple malreports to the same article from different IPs,
are... weird...
Here are some examples:
X-Gmane-Queue: spam 1367258053 gmane.comp.cms.tiki.cvs 78829 184.154.100.18 "Mozilla/5.0 (Windows
NT 6.0) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1"
X-Gmane-Queue: spam 1367259411 gmane.comp.cms.tiki.cvs 78829 50.115.173.184 "Mozilla/5.0 (Windows
NT 5.1; rv:13.0) Gecko/20100101 Firefox/13.0.1"
X-Gmane-Queue: spam 1367259711 gmane.comp.cms.tiki.cvs 78829 50.115.173.184 "Mozilla/5.0 (Windows
NT 6.1; WOW64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.112 Safari/535.1"
X-Gmane-Queue: spam 1367259736 gmane.comp.cms.tiki.cvs 78829 50.115.173.184 "Mozilla/4.0
(compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts; .NET CLR 1.1.4322; PeoplePal 6.2)"
X-Gmane-Queue: spam 1367260161 gmane.comp.cms.tiki.cvs 78829 178.33.30.12 "Mozilla/5.0 (Windows NT
5.1; rv:5.0.1) Gecko/20100101 Firefox/5.0.1"
X-Gmane-Queue: spam 1367260843 gmane.comp.cms.tiki.cvs 78829 173.0.49.201 "Mozilla/5.0 (Windows NT
5.1; rv:5.0.1) Gecko/20100101 Firefox/5.0.1"
X-Gmane-Queue: spam 1367260965 gmane.comp.cms.tiki.cvs 78829 173.0.49.201 "Mozilla/4.0
(compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]"
X-Gmane-Queue: spam 1367261648 gmane.comp.cms.tiki.cvs 78829 173.234.196.155 "Opera/9.80 (Windows
NT 6.2; Win64; x64) Presto/2.12.388 Version/12.15"
X-Gmane-Queue: spam 1367281366 gmane.comp.cms.tiki.cvs 78834 173.213.93.19 "Mozilla/4.0
(compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)"
(Continue reading)