Where does WordPress spam come from?

After using Akismet for a few years to battle spam, it seemed to me that the spammers were slowly gaining the upper hand. Spam was starting to leak through the cracks and I was looking for an alternate approach to the problem.

Akismet
Akismet – It does a good job of killing of spam. I’m not too sure of the claimed accuracy rate though.

After analyzing how bots (automated comment spammers) were parsing my content I ended up with a solution that didn’t affect legitimate visitors but was still able to discard comments from bots on the fly. Four months later and I’ve seen no spam whatsoever. For my own amusement I decided to log the IP of every spammer until I reached a 100 000 spam posts. The idea behind this was to get an adequate number to run some statistics against.

So without further ado, I give you my spammer toplist broken down by IP’s and blocks.

Top 10 spammers by IP

Spam post count IP /32 Country
1757 218.107.1.204 China
711 175.44.8.69 China
687 112.111.185.0 China
593 93.182.36.85 Russian Federation
527 175.44.57.109 China
466 175.42.93.201 China
439 93.182.36.82 Russian Federation
430 36.250.178.131 China
422 36.250.191.105 China

Top 10 spammers by IP /24

Spam post count IP /24 Country
2430 175.44.8.0 China
2194 175.44.9.0 China
2173 91.200.12.0 Ukraine
2111 112.111.189.0 China
2080 175.44.57.0 China
1785 112.111.190.0 China
1757 218.107.1.0 China
1741 112.111.188.0 China
1736 36.250.172.0 China
1650 175.44.55.0 China

Top 10 spammers by IP /16

Spam post count IP /16 Country
15006 175.44.0.0 China
11653 112.111.0.0 China
9115 36.250.0.0 China
8501 27.153.0.0 China
4315 175.42.0.0 China
3926 110.89.0.0 China
3634 36.248.0.0 China
3381 120.37.0.0 China
3161 27.150.0.0 China
3133 27.159.0.0 China

Top 5 spammers by IP /8

Spam post count IP /8 Country
19328 175.0.0.0
14807 27.0.0.0
12758 36.0.0.0
11724 112.0.0.0
9142 110.0.0.0

It would seem that comment spam unfortunately is mostly “Made in China”. At least now I understand why 8% of my total bandwidth consumption originates from China.

I’ve attached the log containing the 100k-of-spam if anybody’s interested.

Address blocks are fetched from NirSoft.

Thank you for reading!
Feel free to waste more time by subscribing to my RSS feed or check out the human-readable sitemap for more content.

Related posts