Googlepages Spam
From Spamwiki
Contents |
[edit] Description
Googlepages is a free web hosting service provided by Google. It is predominantly used by hobbyist website creators to build fansites, personal sites, photo galleries, etc.
Numerous spammers have started abusing Googlepages websites in an automated fashion, building pages whose sole purpose is to redirect the user to the actual target website. This allows the spammer to get around numerous well-established spam filters, which hesitate to block a GooglePages subdomain, since Google is widely whitelisted on most block lists.
[edit] Spam Example
All best Free Casino Games invite. Check our best Online games http://archieqg63.googlepages.com/index.html Video Poker, Blackjack, Roulette, Baccarat & Craps. "My kind of loyalty was loyalty to one's country, not to its institutions or its office-holders." Mark Twain .
Too short ? we can help http://bartholomewhr372.googlepages.com/index.html adjust kenney aeolus. kennel we'll grove pareto lain.
[edit] Basic Summary
Visiting a spammed Googlepages website will cause the user's browser to automatically redirect to the target url, which has been embedded within some obfuscated or otherwise encrypted javascript. In the casino example above, the page contains the following JavaScript segments in the header of the page:
var a="3C7363726970743E0D0A77696E646F772E746F702E6C6F636174696F6E2E687265663D22687474703A2F2F636173696E6F34756F6E6C696E652E6E6574223B0D0A3C2F7363726970743E";
var b,c=;
var o=a.length;
for(b=0;b<o;b+=2) {
c+=unescape('%'+a.substr(b,2));
}
document.write(c);
This uses a rudimentary character replacement decryption technique.
The resulting URL in this case turns out to be: casino4uonline.net.
[edit] How to Report this Spam
Google provides a web interface for reporting various TOS violations. [1]
For spam, paste the spamvertized URL, as well as the spam email with full headers.

