Get Rid of ShareButton Refferal Spam Traffic Permanently

referral-spam-sharebutton-to-sensorstechforum-how-to-stopRefferal spam being released under multiple domain extensions (.xyz, .com, .info, .net, .to) has been reported to be associate with a web page advertising fake buttons under the unlicensed brand ShareButton. The most often related traffic with the ShareButton domains are believed to be one of the most massively spammed domains on websites and users are advised to block them out completely. The sites are advertised as what appears to be a free website design tool (sharing button widget). Anyone who has detected referral spam coming from any of the ShareButton domains is advised to immediately take actions towards blocking it, using the information in this article.

Threat Summary

Name ShareButton Domains
Type Referral Spam
Short Description The ShareButton page has been seen on many referral spams sites on predominantly targeted medium sized and smaller blogs in traffic.
Symptoms The user may witness the ShareButton spam on various places of the website that is being targeted. If used, the buttons may redirect to phishing sites.
Distribution Method Most often via spammed URL’s. Bundling or unwanted software as well as spammed advertisements also a scenario. Even possible via malware.
Detection Tool See If Your System Has Been Affected by malware


Malware Removal Tool

User Experience Join Our Forum to Discuss ShareButton Domains.

How Is ShareButton Spam Spread

The domains spreading the ShareButton spam are multiple:

  • Share-button(.)com
  • Sharebutton(.)to
  • Sharebuttons(.)xyz
  • Sharebutton(.)net
  • Sharebutton(.)com
  • Get-Your-Social-Buttons(.)Info

These domains may spread the ShareButton plugin via either using affiliates that generate revenue by spreading them or post them in return for a compensation on different places online or automatically.

The automatic distribution strategy may be used in the case of the Sharebutton domains because they are believed to spread via two primary types of spamming software also known as spam bots.

Type 1: Web Crawler Spam

Also known as Spiders, this type of spamming software uses a pre-programmed list of websites on which it spams referrals under a ghost account. Since this particular type of spam is spread on websites that contain low-quality security, the cyber-criminals may have used a method, known as Google Dorking. This method involves using scripts to perform searches in google for specific types of websites based on what security features they have. This technique could be combined together with the spamming software which also has the same feature based on dorking – to crawl the web for web-sites based on a pre-configured criteria which could be dorking code as well.

Whatever the case may be, the Web Crawler bots are more oriented towards spamming massively on different websites, than remaining persistent on one site. In addition to this they are also easier to be blocked primarily because they are not so persistent. But if they are combined with other spamming tools, they become very dangerous.

Type 2: Ghost Referrer Spam

Also known as Ghost Referrals, this type of spam is named like this for a purposes. The spamming software aims to target a specific website and while it is spamming it aims to do it as remotely as possible, without having to be directly connected to the website being spammed with Sharebutton URL’s. This technique is more effective than Web Crawlers because it uses sophisticated combination of exploiting the free HTTP protocol and connect remotely to the website it aims to spam with web links. This makes banning the spammer significantly harder because his source IP address may easily be changed often or obfuscated.

Fact is, that both spam methods are being used more and more often and can quickly render the data about traffic on your website useless.

ShareButton Domains In-Depth

The attacks related to the ShareButton domains exist for quite some time now and they are created for several different purposes. One of those purposes is to generate traffic to websites that are third-party and want to be boosted and sold online with high traffic that is actually a hoax. Another goal of referral spam may be to spam not only ShareButton as a service but also generate custom URLs that redirect the users to malicious sites. This means that the web links may contain malware and even ransomware, like Cerber v4, for example, which holds your files hostage until you pay a hefty sum to get them unlocked.

The network of domains that lead to the ShareButton web page has been reported by security experts to be potentially harmful, so all users of your website who have clicked on such URLs are advised to perform an anti-malware scan to see if they have been infected by malware:


Malware Removal Tool

The other primary purpose of redistributing referral spam is to promote the suspicious plugin of sharing buttons that ShareButton advertises. This plugin may obtain crucial user information and may redirect your users not to the actual social media websites, but to phishing websites that may be fraudulent and phishing and may steal the login information, so users, beware what you click on.

How to Fully Stop Spam from ShareButton Domains

Since this type of spam may result in the rapid devaluation of website statistics, we recommend not only blocking the different domain extensions of ShareButton, but also using the instructions below to block them in your web server as well. In addition to this, we also advise you to check the list of blacklisted websites link for which you can find in step “2. Block ShareButton domains from your Server” by to further block domains that are generally blacklisted and associated with referral spam.

After following the instructions we also recommend you to check the our suggested methods to protect yourself from referral spam by ShareButton or other domains in the future:

Exclude All Hits from Known Bots and Spiders In Google Analytics

1: Filtering ShareButton Domains in Google Analytics

Step 1: Click on the ‘Admin’ tab on your GA web page.

Step 2: Choose which ‘View’ is to be filtered and then click the ‘Filters’ button.

Step 3: Click on ‘New Filter’.

Step 4: Write a name, such as ‘Spam Referrals’.

Step 5: On Filter Type choose Custom Filter –>Exclude Filter –> Field: Campaign Source–> Filter Pattern. Then on the Pattern, enter the domain name – ShareButton Domains

Step 6: Select Views to Apply Filter.

Step 7: Save the filter, by clicking on the ‘Save’ button.

You are done! Congratulations!

Also, make sure you check out these several methods to help you further block out this referrer spam from Google Analytics:

More Methods To Stop Spam Bots and Spiders In Google Analytics

1: Block ShareButton Domains from Your Server.

In case you have a server that is Apache HTTP Server, you may want to try the following commands to block ShareButton Domains domains in the .htaccess file:

RewriteEngine on

RewriteCond %{HTTP_REFERER} ^https://.*sharebutton \.com/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*sharebutton \-for\-website\.com/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*sharebutton \.to/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*sharebutton \-for\-website\.to/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*share-button \.xyz/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*share-button \-for\-website\.xyz/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*sharebutton \.net/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*sharebutton \-for\-website\.net/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*sharebuttons \.xyz/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*sharebutton \-for\-website\.xyz/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*Get-Your-Social-Buttons \.info/ [NC,OR]

RewriteCond %{HTTP_REFERER} ^https://.*Get-Your-Social-Buttons\-for\-website\.info/ [NC,OR]

RewriteRule ^(.*)$ – [F,L]

Also here is a web link to some spam URLs being blacklisted from other servers:

Ultimate Referrer Blacklist by

Disclaimer: This type of domain blocking in Apache servers has not yet been tested and it should be done by experienced professionals. Backup is always recommended.

3: Stop ShareButton Domains via WordPress.

There is a method outlined by security researchers online that uses WordPress plugins to block referrer spams from sites. There are many plugins that help deal with referrer spam, simply do a google search. We have currently seen one particular plugin reported to work, called WP-Ban, but bear in mind that you may find an equally good or better. WP-Ban has the ability to block users based on their IP address and other information such as the URL, for example.

Also, in case you feel like you may have clicked and been redirected to one of the domains mentioned in the spam message, and you believe your system may be compromised, you should scan your computer with a particular anti-malware tool. Downloading such software will also make sure your computer is safe against any future intrusions as well.

Spy Hunter scanner will only detect the threat. If you want the threat to be automatically removed, you need to purchase the full version of the anti-malware tool.Find Out More About SpyHunter Anti-Malware Tool / How to Uninstall SpyHunter


Ventsislav Krastev

Ventsislav is a cybersecurity expert at SensorsTechForum since 2015. He has been researching, covering, helping victims with the latest malware infections plus testing and reviewing software and the newest tech developments. Having graduated Marketing as well, Ventsislav also has passion for learning new shifts and innovations in cybersecurity that become game changers. After studying Value Chain Management, Network Administration and Computer Administration of System Applications, he found his true calling within the cybersecrurity industry and is a strong believer in the education of every user towards online safety and security.

More Posts - Website

Follow Me:

Leave a Comment

Your email address will not be published. Required fields are marked *

Time limit is exhausted. Please reload CAPTCHA.

Share on Facebook Share
Share on Twitter Tweet
Share on Google Plus Share
Share on Linkedin Share
Share on Digg Share
Share on Reddit Share
Share on Stumbleupon Share