Welcome to Admin Junkies, Guest — join our community!

Register or log in to explore all our content and services for free on Admin Junkies.

New users using avatar of initial

Joined
Dec 22, 2022
Messages
2,118
Website
astrowhat.com
Credits
3,671
Has anyone else noticed an increase in what appears to be valid users that are using "custom" avatars that are actually the initial of their username?
I use a customized avatar for new users that don't set one... but I have noticed an increase lately of users not getting caught by spam processes that are using what would normally appear to be dynamic avatars for XenForo.

Screen Shot 2023-07-30 at 4.50.14 AM.png


The weird thing is... I use custom fields and some of these actually input valid data.. meanwhile, others don't do anything other than the "default" that gets put in if no selection is taken. Their emails and IP's don't check negative against any DB's.
 
Last edited:
Advertisement Placeholder
That's odd, I've only seen that on forums that don't have a default custom avatar. Did something break on your forum that's causing the default avatars to no longer show up for new accounts?
No, those are custom uploaded images... they just appear to be dynamic. That is what is throwing me off as you can see the standard default on shows up for users (the two green ones with the man standing in the foreground). All those users joined in the last few days.
 
I let the default do its thing, If a person joins with his account and starts with E then you see an avatar with the letter E however so many of them do not even change their images. I myself have a system in place that allows them to earn points via update there profile
It seems though in the OP’s post though that he has a default avatar set… but people are registering and uploading what would look like a default regular one lol. It’s strange right?
 
It seems though in the OP’s post though that he has a default avatar set… but people are registering and uploading what would look like a default regular one lol. It’s strange right?
I would check the logs :) If they are really uploading.

If they re then defo being attacked or bots or someone is doing it...
 
I let the default do its thing, If a person joins with his account and starts with E then you see an avatar with the letter E however so many of them do not even change their images. I myself have a system in place that allows them to earn points via update there profile
That's the thing... I do NOT use dynamic avatars on my site... I have a specific avatar set for those that do NOT upload a custom one (the green based one you can see several of in the screenshot). These users are actually uploading custom avatars that have the appearance of dynamic ones.
I'm wondering if there is a site that you can create what appears to be dynamic avatars and download them for use on sites that don't have them, and those users like that look..... or if it might be bot related. So far, I have found no indication that there is any spam related activity based upon those accounts nor checking the IP/email against more check sources.

Screen Shot 2023-07-31 at 2.18.40 PM.png


I would check the logs :) If they are really uploading.

They definitely are uploading a custom avatar that appears to be dynamically generated style.

From the screenshot above.. the one on the top left has the default.. his user profile contains this for his avatar

Screen Shot 2023-07-31 at 2.21.44 PM.png


The one adjacent to him with the E contains this

Screen Shot 2023-07-31 at 2.21.14 PM.png


Which shows it was a manually uploaded image for the second, the first is using the default.
The other thing that is suspicious is that the user with the E avatar username starts with a T BUT his email starts with an E. This is something that I noticed has been consistent with almost every one of those accounts.

I've got a sneaking suspicion that these ARE actually humans... but overseas spammers setting up accounts to "blend in" according to a script they follow, as one of them, for telescope type, put in Hair.

Screen Shot 2023-07-31 at 2.29.18 PM.png


meanwhile, others will input in what would be acceptable as a response. The one thing that puts that theory into question is where the IP's are coming from that they are joining from, unless there is a new bot system out that is infecting "real people" and they are back-boning on that bot system like a VPN.
 
Last edited:
What does their email address look like?
 
What does their email address look like?
not much different than any other user that uses gmail... they don't have the standard [email protected] formatting.
But the thing is... with only 1 or 2 exceptions... they email address names don't correspond to the actual user name like most users do.

Another questionable issue is one of the very first ones was like this that I noticed.
Username: adgwgwd
Email: darkstrike30@removed
Avatar uploaded
Screen Shot 2023-07-31 at 2.45.53 PM.png
and you can tell it's a low quality graphic.
 
Seems too fishy to be fair. Think it's a "new" generation of spam bots, I'd eliminate them. If they haven't post yet, they likely would only come back to post spam. Put them under approval if you don't want to delete them.
 
Seems too fishy to be fair. Think it's a "new" generation of spam bots, I'd eliminate them. If they haven't post yet, they likely would only come back to post spam. Put them under approval if you don't want to delete them.
Yeah, but the "weird" thing is.. that user above used an IPv6 address for connecting to the site (and registering). And it's not a VPN, TOR or such.. it appears to be a "valid" address provided by AT&T.

Screen Shot 2023-07-31 at 2.48.30 PM.png


Another one with the same "issues" on IPv6

Screen Shot 2023-07-31 at 2.51.00 PM.png


And then another one... registered under one IPv4 address and logged back in later under another but both based on the same ISP.

Screen Shot 2023-07-31 at 2.52.42 PM.png


Then another who registered under one IP
Screen Shot 2023-07-31 at 2.54.38 PM.png

But next login was via a VPN (which honestly for some of my "real" users is also normal).

Screen Shot 2023-07-31 at 2.54.20 PM.png


It really has me curios. At first I thought I might have an Aussie trolling the site on foot.... but with the variety of originating connection addresses that's unlikely.
If it was an automated bot, also some of the "catch you" fields that are getting correctly filled in are unlikely to have valid data. One of them I have now made mandatory, so will see if this behavior continues. Only thing I can think of is a new bot that is using AI features.
I'm waiting to see if the accounts generate any traffic... several of them have logged in multiple times, but no posts.
 
Hmm. It is odd indeed. Wouldn’t be surprised if there was a new bot script on the market though. Keep a close eye, that’s all I can say.
 
Yeah, it's really a weird situation... and if my site was large, I probably would not have caught it.
I was curios if anyone else was seeing anything similar and wanted to put it out there so others could look for it also.
 
This is the first time I have seen that and if you have a default avatar set so that it does not use the Xenforo default then they have to be somehow uploading the default Xenforo one themselves.

Spam bots do seem to be getting more clever as well I have noticed so this does look like an influx of potential spam bots.
 

Log in or register to unlock full forum benefits!

Log in or register to unlock full forum benefits!

Register

Register on Admin Junkies completely free.

Register now
Log in

If you have an account, please log in

Log in
Who read this thread (Total readers: 0)
No registered users viewing this thread.

Would You Rather #9

  • Start a forum in a popular but highly competitive niche

    Votes: 9 27.3%
  • Initiate a forum within a limited-known niche with zero competition

    Votes: 24 72.7%
Win this space by entering the Website of The Month Contest

Theme editor

Theme customizations

Graphic Backgrounds

Granite Backgrounds