Hey you,
BE IN THE KNOW!

35,000 ransomware infections per month and you still believe you are protected?

Sign up to receive:

  • alerts
  • news
  • free how-to-remove guides

of the newest online threats - directly to your inbox:


Get Rid of Referral Spam Linking to Teslathemes(.)com Completely

Referral spam has been reported to link via different URLs to a website advertising a WordPress plugin, called Teslathemes(.)com. The original purpose of the plugin Is claimed to provide WordPress themes on a professional level. However, researchers report it to be associated with massive referral spam that may quickly devaluate Google Analytics statistics.

Name Teslathemes(.)com Referral Spam
Type Referral Spam
Short Description The domain new-look(.)for-your(.)website redirects to a third-party website, promoting a WordPress plugin for site themes.
Symptoms The user may witness spam messages in the form of forum replies as well as comments, posts and other content posted from third-parties containing new-look(.)for-your(.)website domain as well as others.
Distribution Method Via Referral Spam Techniques – Ghost Referral and Web Crawlers
Detection Tool Download Malware Removal Tool, to See If Your System Has Been Affected by Teslathemes(.)com Referral Spam
User Experience Join our forum to discuss about Referral Spam redirecting to Teslathemes(.)com.

teslathemes(.)com-referral-spam-sensorstechforum-site

Teslathemes(.)com Referral Spam – How Did I Get It

Referral spam such as the one promoting different URLs to Teslathemes(.)com may be distributed using two main spam techniques:

Ghost Referral Spam

Ghost Referral Spam (also known as ghost referrer) is a very effective spamming technique that is very sophisticated. The specifics around ghost referrer spam are that it takes advantage via the free HTTP connection passing through. That may allow it to target different aspects of the websites and remain concealed for long periods of times just like its name suggests – a ghost.

Web Crawler Spam

Crawlers also known as spiders are the other form of spam URLs that may appear without permission on your site. They are named crawlers because the spamming software “crawls” for websites that suit a pre-set criteria, after which conducts its spam. This type of technique is less aggressive and most spammers back away after being warned several times.

Teslathemes(.)com in Detail

Teslathemes is a website that may be based in the UK with a high trust rating, promoting WordPress themes. Furthermore, the site is being promoted with links such as new-look(.)for-your(.)website that redirect to it. This suggests that the website may or may not use third-party services that spam it or a phishing page of Teslathemes(.)com which may be hazardous for a user, visiting it.

for-your(.)website-referral-spam-domain-sensorstechforum

Regarding the suspicious URL new-look(.)for-your(.)website, there is no known information only that it`s main domain is called for-your(.)website and the page for it is blank. Another information that was eventually discovered was that the mysterious domain may originate from Panama, according to CQcounter.

Security researchers believe that besides Teslathemes, the spam URL may drive traffic to other websites that may or may not conceal two types of dangers from the user:

Either way, referral spam is not known to come in good will in general for both users and website publishers. It may link to suspicious sites as well as legitimate ones, and it may corrupt data in Google Analytics. Security experts strongly advise users to block out all domains that are associated with the referral domain, including it as well.

Block Referral Spam Redirecting to Teslathemes(.)com

To successfully block referral spam such as new-look(.)for-your(.)website that at the time of writing redirects to Teslathemes(.)com users should take extra precautions. We have provided step-by-step instructions for different methods to block out this and other blacklisted spamming domains and ensure that your website is safer.

Before beginning your learning process on how to block out referral spam, it is advisable to check other blacklistes spammer domains to block them as well:

https://github.com/piwik/referrer-spam-blacklist/blob/master/spammers.txt

Here are several methods to block out Teslathemes(.)com Referral Spam

Method 1: Google Analytics

You can always try to block all of the domains associated with this website (.info, .net., .com, etc.).

Step 1: Click on the ‘Admin’ tab on your GA web page.
Step 2: Choose which ‘View’ is to be filtered and then click the ‘Filters’ button.
Step 3: Click on ‘New Filter’.
Step 4: Write a name, such as ‘Spam Referrals’.
Step 5: On Filter Type choose Custom Filter –>Exclude Filter –> Field: Campaign Source–> Filter Pattern. Then on the Pattern, enter the domain names – for-your(.)website or Teslathemes(.)com(optional)
Step 6: Select Views to Apply Filter.
Step 7: Save the filter, by clicking on the ‘Save’ button.
You are done! Congratulations!

Also, make sure you check out these several methods to help you further block out this referrer spam from Google Analytics:

http://sensorstechforum.com/exclude-all-hits-from-known-bots-and-spiders-in-google-analytics/

Method 2: Block it from your server.

In case you have a server that is Apache HTTP Server, you may want to try the following commands to block new-look(.)for-your(.)website and domains in the .htaccess file:

RewriteEngine on

RewriteCond %{HTTP_REFERER} ^http://.* for-your \.website/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^http://.* new-look \.for-your/ \.website/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^http://.* for-your \-for\-website\.website/

RewriteRule ^(.*)$ – [F,L]

In case you are not using Teslathemes and do not wish users to visit it you may also want to insert the following Rewrite command:

RewriteCond %{HTTP_REFERER} ^http://.* teslathemes \.com/ [NC,OR]

Also here is a web link to some spam URLs being blacklisted from other servers:

https://perishablepress.com/blacklist/ultimate-referrer-blacklist.txt

Disclaimer: This type of domain blocking in Apache servers has not yet been tested and it should be done by experienced professionals. Backup is always recommended.

Method 3 – Via WordPress

There is a method outlined by security researchers online that uses WordPress plugins to block referrer spams from sites. There are many plugins that help deal with referrer spam, simply do a google search. We have currently seen one particular plugin reported to work, called WP-Ban, but bear in mind that you may find an equally good or better. WP-Ban has the ability to block users based on their IP address and other information such as the URL, for example.

In case you have been redirected to or personally visited URLs by for-your(.)website it is advisable to user advanced anti-malware scanner to check whether or not your machine has been infected with malware since this service may advertise all sorts of concealed dangers. Security engineers recommend performing more than one system scan for maximum effectiveness.

donload_now_250
Spy Hunter scanner will only detect the threat. If you want the threat to be automatically removed, you need to purchase the full version of the anti-malware tool.Find Out More About SpyHunter Anti-Malware Tool / How to Uninstall SpyHunter

Vencislav Krustev

A network administrator and malware researcher at SensorsTechForum with passion for discovery of new shifts and innovations in cyber security. Strong believer in basic education of every user towards online safety.

More Posts - Website

Share on Facebook Share
Loading...
Share on Twitter Tweet
Loading...
Share on Google Plus Share
Loading...
Share on Linkedin Share
Loading...
Share on Digg Share
Share on Reddit Share
Loading...
Share on Stumbleupon Share
Loading...
Please wait...

Subscribe to our newsletter

Want to be notified when our article is published? Enter your email address and name below to be the first to know.