Just in time for the end of the year, I found a new referral spam in my Blogger statistics. http: // semalt . com / competitors_review . php? u= (then my blog address) is obvious spam due to it having text suggesting that someone is competing with my website and checking me out.
Using a virtual machine and TOR to be anonymous, I checked out the address. It only gets me to the home page where a requirement to register first stopped me cold. Of course, it wants you to log in using your Facebook, Google Plus, or Microsoft Live accounts. Oh, nothing suspicious about that, is there?
It offers to show you what your Google rankings are, which is interesting given that you can sign up for Google’s own tools for free to do the same. As the page loaded, I noticed that it loaded counter . yadro . ru , a Russian address I only fleetingly glimpsed. Some sites report this as a malware infection while others that it is simply a tracking site like Google analytics. Still a bad guy according to most, so consider it a red flag.
The privacy policy and terms of use pages are generic giving no useful information. There was no way I’d sign up to find out what lied beneath the barebones page other than to look at the source html. In there the meta description of the content bills the site as a “Professional keyword ranking monitoring service with competitor analysis. Fee plans.” Also found in the code was the yadro address, so that is being loaded as a hit counter.
My advice to all who get a variant of this link in their statistics is to avoid clicking on it. Semalt is most likely only there to harvest data to access your email and social accounts with the possible additional goal of selling SEO (search engine optimization) methods.
UPDATE
I’m seeing more hits from this spam showing up in StatCounter now and they are coming from computers in different countries with differing versions of Windows and screen resolutions. This means a bot net of infected computers is most likely being used to push the spam rather than forged addresses.
Please do not click on the link and if you have, run an antivirus program along with something like MalwareBytes or Spybot to make sure you haven’t been infected.