SmexyLizard
Registered Member
- Feb 5, 2015
- 77
- 15
First it was the Russians, now they don't specify a country code.
The website is simple-share-buttons (groot) com. I got 50+ referrals with a 100% bounce rate and 0:00:00 average session duration. Definitely spam. The website redirects to sharebutton (groot) org which looks pretty legit and has code to put share buttons into a site.
I don't seem to see where they're benefiting from referral spam, so I figured their code has to have something malicious in it. I am not a programmer, but I peaked at the code it inserts here: cdn.sharebutton (groot) org/sharejs.
(I originally had the code here, but it wouldn't let me post it)
That code mentions popups and includes references to sharebuttons (org) net and also includes an import to semalt (groot) com/js/sharebutton.js which is much shorter and references the page empty page semalt (groot) com/test/sharebutton/.
Semalt is an SEO company and I don't think they'd go through so many hoops if they were just a Russian redirect to porn site, so I'm pretty sure it's doing something.
Once again, I am not a JavaScript programmer so I can't be sure of any of this is malicious. If someone who knows JavaScript could chime in, that'd be great.
The website is simple-share-buttons (groot) com. I got 50+ referrals with a 100% bounce rate and 0:00:00 average session duration. Definitely spam. The website redirects to sharebutton (groot) org which looks pretty legit and has code to put share buttons into a site.
I don't seem to see where they're benefiting from referral spam, so I figured their code has to have something malicious in it. I am not a programmer, but I peaked at the code it inserts here: cdn.sharebutton (groot) org/sharejs.
(I originally had the code here, but it wouldn't let me post it)
That code mentions popups and includes references to sharebuttons (org) net and also includes an import to semalt (groot) com/js/sharebutton.js which is much shorter and references the page empty page semalt (groot) com/test/sharebutton/.
Semalt is an SEO company and I don't think they'd go through so many hoops if they were just a Russian redirect to porn site, so I'm pretty sure it's doing something.
Once again, I am not a JavaScript programmer so I can't be sure of any of this is malicious. If someone who knows JavaScript could chime in, that'd be great.