I've been noticing something strange in this website's logs. A high percent of the referer urls point to Russian gambling sites. Could it be that this website appeals to Russian-speaking, online gamblers? That doesn't seem very likely to me. I think this is a scam that works as follows:
I wonder how often this scam gets to step #4? How could the gambling sites get enough revenue to justify the expense of the servers doing the spidering? Or are those servers just hijacked user machines in a botnet?
It's clear from my logs that this traffic is not coming from actual human web surfers:
[2015-10-24 15:43:02.406] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://********.ru/ Opera/9.00 (Windows NT 4.0; U; en) 200 15.092 [2015-10-24 15:43:02.426] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://www.*************.com/ Opera/9.00 (Windows NT 4.0; U; en) 200 13.100 [2015-10-24 15:43:02.543] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://*************.ru/ Opera/9.00 (Windows NT 4.0; U; en) 200 11.389 [2015-10-24 15:43:03.000] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://********.ru/ Opera/9.00 (Windows NT 4.0; U; en) 200 19.081 [2015-10-24 15:43:03.018] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://www.*************.com/ Opera/9.00 (Windows NT 4.0; U; en) 200 15.431 [2015-10-24 15:43:03.597] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://********.ru/ Opera/9.00 (Windows NT 4.0; U; en) 200 12.707 [2015-10-24 15:43:03.741] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://*************.ru/ Opera/9.00 (Windows NT 4.0; U; en) 200 42.790 [2015-10-24 15:43:04.182] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://www.*************.com/ Opera/9.00 (Windows NT 4.0; U; en) 200 14.877 [2015-10-24 15:43:05.332] [DEBUG] dev - ***.***.***.*** GET 1.1 /blog/203/ http://*************.ru/ Opera/9.00 (Windows NT 4.0; U; en) 200 14.524
Stepping outside during a Colorado winter is enough of a gamble for me!
P.S. I am not misspelling the word "referrer". The HTTP referer header was originally misspelled, but it's now an international standard.
Title | Date |
.NET Public-Key (Asymmetric) Cryptography Demo | July 20, 2025 |
Raspberry Pi 3B+ Photo Frame | June 17, 2025 |
EBTCalc (Android) Version 1.53 is now available | May 19, 2024 |
Vault 3 Security Enhancements | October 24, 2023 |
Vault 3 is now available for Apple OSX M2 Mac Computers! | September 18, 2023 |
Vault (for Desktop) Version 0.77 Released | March 26, 2023 |
EBTCalc (Android) Version 1.44 is now available | October 12, 2021 |