Deadliest Catch: by SEO Spammers!
I’ve always loved the HBO show, “Deadliest Catch,” and it’s past 7 seasons have been chock full of the worst kind of northern exposure to hyper captains, bad fishing and bad weather than I’d ever imagine possible. The character that I tended to like best, was Capt. Phil Harris, who passed away in Feb of this year, and as I’d missed the episodes that showed same, I thought I’d google for them, and see if I could catch-up to him and his ship the Cornelia Marie online.
So as you can maybe tell, I backed into this Spam Scam via a simple search on google for “cornelia marie deadliest catch,” and the surprising thing is that even tho I’m a long time SEO practitioner, I didn’t even notice at all, what was on the page of web results.
Here’s a screenshot of what I found…do you see what I see?
Sure, the #1 web result is properly for the official site and so’s #2…but then what do you see? #3 appears to be a hacker at work here, as they spam the site (note the URL link does “point at” the offical site) by using their own <title> to gain strength but it goes to the tv shows site. Or does it? Most of the page listed the <title> as drug oriented, but sent clicks to the Cornelia Marie site? Huh?
So yup, I clicked. And guess what I found…that first, I got a blank screen with the this title showing — “Wait a few seconds…” and the onscreen phrase “Click here if page is not loading…” shown. A simple grab of the source code showed that this was a <form>and that clicking on same would send me to this site — http://95.143.xxx.xxx/sutra/in — which would then run a php script that would send the visitor over to an offshore pharma site…to sell pills.
…sigh….and this hacker’s spam site is yes, labelled as (head hung here in shame, eh!) as the “Canadian Family Pharmacy” site….boy, we canucks wear this one, eh!
So, think about this. Somehow, this hacker (yes I grabbed the script, delved into same and notified both Google and the tvShow site that hacks were being applied to their rankings AND their pages) was able to hijack the real web results pages for the Cornelia Marie official site — and then turn that hack into a hijacked link to try to sell the unaware Deadliest Catch tvShow fan, pills.
…sigh….can you imagine anything else “stupider???” I can’t….honestly, this is totally idiotic and if I backed “into” this kind of hacker spam, anyone can.
Oh, the rest of the links…yup, I clicked on item after item….and found much more too.
For instance, some of you might be thinking, hey…these Cornelia Marie guys are crab fishermen up in the Bering Sea….how “educated” are they about the web and hackers….least that did come to mind.
Thing of it is, tho, what I did was I grabbed some of the title text (“order plavix online now”) from that Cornelia Marie page and plugged it into g.com too…and guess what I got – some very, very educated web folks who suffered from exactly the same type of hack….here’s a screenshot for you to see too —
Note the various hits on this term — which shows just how widespread this hacker has grown his spammy results? The Cornelia Marie is yes #2 on this one, but further down are the VC folks from Idaho, the PodCamp Toronto sites…the list goes on and on and on, eh! Not that anyone is immune…but at the same time, the “how” this hack was done appears to me to maybe include scripting as well as FTP access too…so that pages can be “doctored” right at their source. I’ve no other ideas, as I’m just not going to bother…but I did notify all that I found….but only the top 10 on each query….I mean a guy can only do so much, eh!
Amazing really….but then again, aint the web like that! And to the Cornelia Marie crew….I salute you lads! I’ll miss Capt. Phil greatly as I’m sure millions of others will too…RIP Capt. Phil!
UPDATE: I heard back today from Morgan Howard, the folks who I believe “own” the Deadliest Catch show, and this is what they said in that email –
“Jim…For the most part, it’s cleaned up now – I paid for a malware removal service called sucuri.net. I’ve known about it since the beginning – it doesn’t seem to affect anything except for the google search results. But, wordpress is so vulnerable to this type of behavior so I have to really keep on it. BTW- it looks like you actually copied some of that bogus information when you wrote your description in your blog. “Deadliest Catch” airs on the “Discovery Channel” and not “HBO”…” … Morgan Howard
So, looks like after a quick check that all those scam URLs have been replaced with real ones….the Google index cache will also undoubtedly be updated soon too….if only PodCampToronto and others could do the same, eh! Oh, and yes, mea culpa….I did mistakely identify the Canadian network that shows “Deadliest Catch” up here as HBO — when in fact it is the Discovery Channel….my bad! I blame the late nights sitting here at the monitor for same….Google