Home > Heuristics, Malware, Stats > Blog Comment Spam Honeypot

Blog Comment Spam Honeypot

January 25th, 2010 Pedro Bustamante

One of the most common vectors for distributing malware nowadays is spamming blogs with comments pointing to malicious sites that host exploits, malware, rogue antiviruses or other types of scams.

In order to analyze the huge volume of spam comments that come in through our various Panda Blogs (PandaLabs, Panda Research, Panda Cloud Antivirus Blog, etc.) Iker from PandaLabs has developed a “blog comment spam honeypot” which is basically a modified Akismet plugin for WordPress. The honeypot basically posts everything that Akismet detects as spam into an XML which is then processed and all links are followed to detect malware, exploits, drive-by downloads, etc.

If you have a wordpress blog and would like to install the honeypot to send your trapped spam to PandaLabs for analysis, simply download and install the blog comment spam honeypot.

Thanks to Iker for all his work on spam research.

  1. Peeedroooo
    January 25th, 2010 at 15:09 | #1

    Does it work also with other kind of blog technologies like blogspot, joomla, drupal, etc? Or only with wordpress? If not, are you planning on it?

  2. Pedro Bustamante
    January 25th, 2010 at 15:59 | #2

    @Peeedroooo Not really, but could be easily done. Which blog platform do you use?

  3. Peeedroooo
    January 25th, 2010 at 17:59 | #3

    I use blogspot in order to be able to keep everything in my google account, but I am not sure if the technology you used can be easily transformed into a blogspot widget/plugin.
    But I also have many friend who use Joomla and its blogging capacity and I bet this would be useful for them too.

  4. Peeedroooo
    January 25th, 2010 at 18:01 | #4

    BTW, sorry about the Peeedroooo name, I actually didn’t realize your name was Pedro and it was solely intended to mock the high-pitch shout of Penelope Cruz when she gave the Oscar to Pedro Almodovar, :P .

  5. Pedro Bustamante
    January 26th, 2010 at 11:51 | #5

    No problem about the nick :)
    We will look into the implementation on other platforms for future releases.

  6. Peeedroooo
    January 26th, 2010 at 16:03 | #6

    Thanks a lot Pedro. If I could code I’d do it myself, but poor of me just works with systems and is not goo enough at coding…. :)

Comments are closed.