IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

194.165.42.151

The Project Honey Pot system has detected behavior from the IP address consistent with that of a comment spammer. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | OpenRBL | Spamcop | SenderBase | Google Groups | Google

Geographic Location Switzerland
Spider First Seen approximately 1 year, 2 weeks ago
Spider Last Seen within 10 months, 4 weeks
Spider Sightings 47,132 visit(s)
User-Agents seen with 2 user-agent(s)

First Post On approximately 1 year, 2 weeks ago
Last Post On within 10 months, 4 weeks
Form Posts 49,630 web post submission(s) sent from this IP

IPs In The Neighborhood
194.165.41.229 | S
194.165.42.0
194.165.42.1
194.165.42.2
194.165.42.5 | C
194.165.42.7
194.165.42.9 | C
194.165.42.15 | C
194.165.42.18
194.165.42.19 | C
194.165.42.21 | C
194.165.42.23 | C
194.165.42.27 | C
194.165.42.29 | C
194.165.42.31 | C
194.165.42.33
194.165.42.35 | C
194.165.42.37 | C
194.165.42.39 | C
194.165.42.41
194.165.42.43
194.165.42.45 | C
194.165.42.47 | C
194.165.42.49 | C
194.165.42.51 | C
194.165.42.53 | C
194.165.42.54
194.165.42.55 | C
194.165.42.56 | C
194.165.42.59 | C
194.165.42.61 | C
194.165.42.63 | C
194.165.42.65 | C
194.165.42.67 | C
194.165.42.69 | C
194.165.42.71 | C
194.165.42.73 | C
194.165.42.75 | C
194.165.42.77 | C
194.165.42.79 | C
194.165.42.81 | C
194.165.42.83 | C
194.165.42.85 | C
194.165.42.87 | C
194.165.42.89 | C
194.165.42.91 | C
194.165.42.93 | C
194.165.42.95 | C
194.165.42.101
194.165.42.103 | C
194.165.42.105 | C
194.165.42.107 | C
194.165.42.109 | C
194.165.42.111 | C
194.165.42.113 | C
194.165.42.119 | C
194.165.42.121 | C
194.165.42.123 | C
194.165.42.125 | C
194.165.42.127 | C
194.165.42.129 | C
194.165.42.135 | C
194.165.42.137 | C
194.165.42.139 | C
194.165.42.141 | C
194.165.42.143 | C
194.165.42.149 | C
194.165.42.152
194.165.42.153 | C
194.165.42.154
194.165.42.155 | C
194.165.42.157 | C
194.165.42.159
Sample Spam URLs & Keywords Posted From 194.165.42.151
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZocor
Keywords: zocor
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZoloft
Keywords: zoloft
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZyprexa
Keywords: zyprexa
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZyrtec
Keywords: zyrtec
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZocor
Keywords: zocor
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZoloft
Keywords: zoloft
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZyprexa
Keywords: zyprexa
Domain: www.linkedin.com
URL: http://www.linkedin.com/in/BuyCheapZyrtec
Keywords: zyrtec
Domain: www.bimmerwerkz.com
URL: http://www.bimmerwerkz.com/forum/member.php?u=40705
Keywords: capoten
Domain: www.bimmerwerkz.com
URL: http://www.bimmerwerkz.com/forum/member.php?u=40706
Keywords: cardura
Domain: www.bimmerwerkz.com
URL: http://www.bimmerwerkz.com/forum/member.php?u=40707
Keywords: combipres
Domain: www.bimmerwerkz.com
URL: http://www.bimmerwerkz.com/forum/member.php?u=40708
Keywords: coreg
Domain: www.bimmerwerkz.com
URL: http://www.bimmerwerkz.com/forum/member.php?u=40709
Keywords: coversyl
Domain: www.bimmerwerkz.com
URL: http://www.bimmerwerkz.com/forum/member.php?u=40710
Keywords: cozaar
Domain: www.bimmerwerkz.com
URL: http://www.bimmerwerkz.com/forum/member.php?u=40711
Keywords: diovan
194.165.42.151's User Agent Strings
Mozilla/4.0 (compatible; MSIE 6.
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
O.Wichmann commented...
Whois of their network:
http://www.stopforumspam.com/whois/194.165.42.151
Note the contact address in Saudi Arabia was blatantly stolen from "nashirnet.net" whois, a legitimate hosting company in Saudi Arabia. "nashirnet.biz" is entirely unrelated to them and was fraudulently registered to bypass Name/Adress checks done by RIPE. So we have a clear case of identity theft here.

A look at their email domains used as whois contacts:

"nashirnet.biz" (92.48.126.216, v3servers) was anonymously registered at Chinese spam support registrar OnlineNic (they themselves former forum spammers) on October 6th, 2008.

"comunmente.info" (85.12.44.71, Euroaccess) was also anonymously registered at some directi reseller (privacyprotect.org is associated with Directi) on February 20th, 2008.

I'm curious for how long this will go on like this...
November 22 2008 03:19 PM

O.Wichmann commented...
These fine fellows posing as arab fake ISP "nashirnet" are in fact the usual pack of Russian spammers. All ips in their /24 are routed to Euroaccess in the Netherlands:

Also see this message at NANAE:
http://groups.google.com/group/news.admin.net-abuse.email/msg/96642dc61a1c0f1f

Routing of "nashirnet"

route: 194.165.42.0/24
origin: AS34305
descr: EUROACCESS Euroaccess Global Autonomous System
lastupd-frst: 2008-10-07 17:35Z 193.203.0.21@rrc05
lastupd-last: 2008-11-22 05:19Z 195.66.224.54@rrc01
seen-at: rrc00,rrc01,rrc04,rrc05,rrc06,rrc07,rrc10,rrc11,rrc12,rrc13,rrc14,rrc15,rrc16
num-rispeers: 108
source: RISWHOIS

spam sample as evidence:
http ://www .angelinajolie.com/forum/member.php?u=158131

=> spamvertised profile with link to "nenene.org" (62.109.1.60).

Whois of 62.109.1.60:

inetnum: 62.109.0.0 - 62.109.7.255
netname: ISPSYSTEM
descr: ISPsystem at MSM
country: RU
admin-c: PAS28-RIPE
tech-c: AB11726-RIPE
status: ASSIGNED PA
mnt-by: ISPSYSTEM-MNT
source: RIPE # Filtered

whois of domain:

Domain ID:D153615495-LROR
Domain Name:NENENE.ORG
Created On:17-Aug-2008 13:33:53 UTC
Last Updated On:12-Nov-2008 11:47:01 UTC
Expiration Date:17-Aug-2009 13:33:53 UTC
Sponsoring Registrar:EstDomains, Inc. (R1345-LROR)
Status:OK
Registrant ID:DI_3517281
Registrant Name:Alex
Registrant Organization:Alex&Alex
Registrant Street1:Usa
Registrant Street2:
Registrant Street3:
Registrant City:New-York
Registrant State/Province:New York
Registrant Postal Code:na
Registrant Country:US
Registrant Phone:+001.41512345678
Registrant Phone Ext.:
Registrant FAX:
Registrant FAX Ext.:
Registrant Email:jaimsbond@gmail.com
November 22 2008 11:41 AM

A.Degives Mas commented...
Comment spammer without doubt; engages in repeated automated attempts to inject comment spam.

User agent shown as: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
November 16 2008 06:08 AM

I.Ellis commented...
wanted one and only one file - guestbook - and nothing else. Guestbook was disallowed in robots.txt, but that was ignored.
November 15 2008 08:28 PM

Page generated on: November 22 2009 12:58:32 AM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | Contact Us

Copyright © 2004–09, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email