I've been getting these on a daily basis for several weeks and I've simply been marking them as Junk and then deleting them. This evening, I decided to see just where those hot links went:

I don't have the time this evening to do a Who Is or Trace Route on the IP. I'm assuming that it is from an infected machine rather than the original launch point.

EDIT: I did do a Whois and a Traceroute.
Whois ID'd it as a server in St. Petersburg, Russia and the Traceroute confirmed it.

Whois is very informative yielding the hosting service's name, address, building number, and office number. Anyone wanna go egg the place? wink

Edited by MacBozo (06/27/13 01:00 AM)