IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

208.66.195.3

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | OpenRBL | Spamcop | SenderBase | Google Groups | Google

Geographic Location Unknown

Harvester First Seen approximately 2 years, 5 months, 3 weeks ago
Harvester Last Seen within 2 years, 2 months, 3 weeks
Harvester Sightings 1,261 visit(s) to 577 honey pot(s)
Harvester Results 2238.879 messages per visit
2,823,227 message(s) resulting from harvests
- First: approximately 2 years, 5 months, 2 weeks ago
- Last: approximately 1 week ago
1,261 harvested address(es) have seen message(s)
- First: approximately 2 years, 5 months, 3 weeks ago
- Last: Mon, 04 Sep 2006 15:00:11 -0400
Time From Harvest
To First Spam
Fastest: 1 hour, 18 mins, 26 secs
Slowest: 2 months, 3 weeks, 1 day, 2 hours, 43 mins, 6 secs
Average: 1 month, 14 hours, 24 mins, 58 secs
Std Dev: 3 weeks, 5 days, 18 hours, 27 mins, 56 secs

Associated Mail Servers
82.29.88.133 | S
124.121.67.250 | SD
119.84.150.5 | S
78.99.105.238 | SD
84.38.80.98 | S
201.243.83.62 | SD
117.35.250.199 | S
190.80.227.141 | S
124.191.68.15 | SD
213.33.147.162 | SD
58.108.184.31 | SD
59.95.163.217 | S
89.253.27.61 | S
217.14.192.43 | S
83.46.52.73 | S
88.7.15.97 | SD
75.41.231.254 | SD
79.100.91.227 | S
87.207.73.168 | SD
80.54.236.18 | SD
217.132.222.79 | S
116.28.124.230 | S
190.87.128.142 | SD
125.37.239.194 | S
116.21.68.128 
123.17.146.66 | S
221.207.175.161 | S
92.226.91.51 | S
190.67.151.72 | S
81.149.240.12 | S
201.219.85.48 | SD
75.161.69.158 | S
201.42.188.134 | S
219.236.100.80 | S
163.13.202.79 | SD
196.46.74.227 | SD
195.138.93.97 | S
213.23.42.202 | SD
190.99.134.68 | SD
61.4.246.229 | S
189.104.215.145 | S
190.66.72.48 | S
201.1.47.133 | S
209.206.247.7 | SD
83.39.24.197 | SD
71.28.202.29 | SD
88.252.4.112 | S
76.65.206.146 | SD
189.104.221.108 | S
89.252.192.77 | S
190.144.19.58 | SD
221.127.5.204 | S
189.18.80.173 | S
84.60.19.29 | S
221.201.209.160 | S
91.147.254.101 | S
79.148.23.108 | S
190.72.17.43 | SD
121.88.144.40 
125.164.194.108 | S
213.172.16.9 | S
125.103.76.176 | SD
71.72.111.220 | SD
221.191.228.183 
201.41.164.146 | SD
130.13.53.161 | SD
92.83.89.72 | SD
77.122.193.98 | SD
194.74.226.190 | SD
89.231.202.81 | S
189.24.154.213 | S
118.216.141.39 | S
222.78.250.139 | S
124.229.164.122 | SD
61.90.83.48 | SD
IPs In The Neighborhood
208.66.194.154 | H
208.66.194.162
208.66.194.163
208.66.194.164
208.66.194.165
208.66.194.166
208.66.194.167
208.66.194.168
208.66.194.169
208.66.194.170
208.66.194.171
208.66.194.172
208.66.194.173
208.66.194.174
208.66.194.178
208.66.194.179
208.66.194.199 | S
208.66.195.2 | H
208.66.195.4 | H
208.66.195.5 | H
208.66.195.6 | H
208.66.195.7 | H
208.66.195.8 | H
208.66.195.9 | H
208.66.195.10 | H
208.66.195.11 | H
208.66.195.15 | H
208.66.195.19 | H
208.66.195.20 | H
208.66.195.21 | H
208.66.195.22 | H
208.66.195.71
208.66.195.175 | S
P.Hauser commented...
This log shows why you should block TWO criteria and not only one:

First approach as UA "psycheclone", which received 302:

208.66.195.2 [20/Jun/2006:17:37:55 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
208.66.195.2 [20/Jun/2006:17:37:58 +0200] "GET / " 302 214 "-" "[same UA]"
208.66.195.4 [22/Jun/2006] "[same UA]"
208.66.195.6 [26/Jun/2006] "[same UA]"
208.66.195.6 [27/Jun/2006] "[same UA]"
208.66.195.3 [28/Jun/2006] "[same UA]"
208.66.195.4 [01/Jul/2006] "[same UA]"
208.66.195.6 [01/Jul/2006] "[same UA]"
208.66.195.3 [12/Jul/2006] "[same UA]"

Changing UA from "psycheclone" to
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)"
receiving 200:

208.66.195.9 [14/Jul/2006:00:42:50 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
208.66.195.9 [14/Jul/2006:00:43:20 +0200] "GET / " 200 66380 "-" "[same UA]"

208.66.195.5 [27/Jul/2006] "[same UA]"
[...]
208.66.195.5 [27/Jul/2006] "[same UA]"
208.66.195.10 [08/Aug/2006] "[same UA]"
[...]
208.66.195.10 [08/Aug/2006] "[same UA]"

First harvest with this UA:

208.66.195.10 [08/Aug/2006:12:53:09 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
[42 continued requests in 40 minutes / every minute one request]
208.66.195.10 [08/Aug/2006:13:24:20 +0200] "GET /[URL]&lang=cs " 200 68400 "-" "[same UA]"

208.66.195.19 [30/Aug/2006] [same UA]"
[...]
208.66.195.19 [30/Aug/2006] "[same UA]"

Second harvest with this UA:

208.66.195.22 [30/Aug/2006:10:45:54 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
[38 continued requests in 25 minutes / every minute one request, little faster]
208.66.195.22 [30/Aug/2006:11:07:09 +0200] "GET /[URL]&lang=es " 200 68965 "-" "[same UA]"

We stopped him:

208.66.195.9 [03/Sep/2006] "[same UA]"
[...]
208.66.195.9 [03/Sep/2006] "[same UA]"
208.66.195.7 [04/Sep/2006] "[same UA]"
[...]
208.66.195.7 [04/Sep/2006] "GET / " 302 214 "-" "[same UA]"
July 31 2007 10:25 PM

P.Adams commented...
mccolo.com states "Our datacenter is situated in top-level modern MarketPostTower IT center, San Jose, CA, USA." so it can get an american flag
May 13 2007 07:12 AM

Page generated on: November 19 2008 07:15:04 PM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | Contact Us

Copyright © 2004–08, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

MITS