IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

195.229.242.54

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester and comment spammer. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location United Arab Emirates (Dubai, Dubayy)

Harvester First Seen approximately 6 years, 3 months, 5 weeks ago
Harvester Last Seen within 4 months, 4 weeks
Harvester Sightings 301 visit(s) to 32 honey pot(s)
Harvester Results 0.133 messages per visit
40 message(s) resulting from harvests
- First: approximately 6 years, 2 months, 4 weeks ago
- Last: approximately 5 months, 1 week ago
201 email address(es) harvested
- First: approximately 6 years, 3 months, 5 weeks ago
- Last: Wed, 27 Jul 2011 15:27:33 -0700
Time From Harvest
To First Spam
Fastest: 56 mins, 14 secs
Slowest: 2 days, 20 hours, 56 mins, 44 secs
Average: 1 day, 1 hour, 6 mins, 36 secs
Std Dev: 22 hours, 58 mins, 16 secs

First Post On approximately 3 years, 6 months, 3 weeks ago
Last Post On within 6 months, 3 weeks
Form Posts 26 web post submission(s) sent from this IP

Associated Mail Servers
69.147.85.78 | S
72.14.252.157 | S
74.55.34.18 | S
83.110.187.210 | S
83.110.191.106 | S
86.97.163.20 | S
86.98.174.75 | SD
86.99.144.102 | S
98.136.45.7 | S
184.154.130.218 | S
202.91.248.34 | SD
207.59.32.146 | S
209.85.217.23 | SD
209.85.218.29 | S
209.85.220.173 | Se
211.75.39.200 | S
211.245.24.198 | SD
213.4.129.20 | S
213.42.1.90 | S
213.42.1.92 | S
213.42.1.94 | S
217.164.2.241 | S
217.164.3.213 | S
217.164.201.219 | S
217.164.202.203 | S
217.164.210.46 | S
217.164.252.119 | S
217.164.254.162 | S
217.165.106.156 | S
IPs In The Neighborhood
195.229.241.85 | SD
195.229.241.169 | H
195.229.241.171 | HC
195.229.241.172 | HC
195.229.241.173 | HSC
195.229.241.174 | HC
195.229.241.175 | C
195.229.241.176 | C
195.229.241.177 | HC
195.229.241.178 | HSCR
195.229.241.179 | C
195.229.241.180 | HC
195.229.241.181 | HC
195.229.241.182 | HC
195.229.241.183 | H
195.229.241.184 | H
195.229.241.186 | H
195.229.241.187 | HC
195.229.241.188 | H
195.229.241.193
195.229.241.194
195.229.241.205
195.229.241.211
195.229.241.222
195.229.241.251
195.229.241.254
195.229.242.0
195.229.242.52 | HC
195.229.242.53 | HCR
195.229.242.55 | HCR
195.229.242.56 | HC
195.229.242.57 | HC
195.229.242.58 | HC
195.229.242.59 | HC
195.229.242.60 | HC
195.229.242.61 | HC
195.229.242.62 | HC
195.229.242.83
195.229.242.84 | H
195.229.242.85
195.229.242.86 | H
195.229.242.88 | H
195.229.242.89 | H
195.229.242.90 | H
195.229.242.92
195.229.242.93
195.229.242.146 | C
195.229.242.154 | HC
195.229.242.155 | HC
195.229.242.215
Sample Spam URLs & Keywords Posted From 195.229.242.54
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9160
Keywords: preteen halloween upskirt
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9138
Keywords: hentai preteen fucking
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9142
Keywords: preteen gallaries model
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9149
Keywords: pedo cp preteen
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9156
Keywords: europe models preteen
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9150
Keywords: topless beach preteen
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9147
Keywords: extreme models preteens
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9144
Keywords: preteen boy actors
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9136
Keywords: preteen thumbnails vids
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9166
Keywords: preteen young twat
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9165
Keywords: preteen crossdresser bbs
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9140
Keywords: nude preteen spanking
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9161
Keywords: amateur nude preteen
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9167
Keywords: preteen sex practices
Domain: tacho.13.forumer.com
URL: http://tacho.13.forumer.com/viewtopic.php?p=9148
Keywords: spreading legs preteen
195.229.242.54's User Agent Strings
none/blank
iTunes/10.1 (Windows; Microsoft Windows Vista Business Edition Service Pack 2 (Build 6002)) AppleWebKit/533.19.4
Java/1.4.1_04
Java/1.4.2_03
Java/1.6.0_04
Java/1.6.0_11
Java/1.6.0_12
Java/1.6.0_17
Java/1.6.0_20
Java/1.6.0_21
Mozilla/4.0 (compatible;)
Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) XX
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Mozilla/4.0 (compatible ; MSIE 6.0; Windows NT 5.1)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; GTB5; .NET CLR 2.0.50727; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; AntivirXP08; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; OfficeLiveConnector.1.3; OfficeLivePatch.0.0)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; FunWebProducts; .NET CLR 2.0.50727)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6.5; AskTb/5.6.6.117)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6.5; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.2; AskTB5.6)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6; InfoPath.1)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6; InfoPath.2)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6; .NET CLR 2.0.50727)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.2)
P.Hauser commented...
IPs 195.229.242.84, 195.229.242.85, were also seen here with different UA.

195.229.242.84 [04/May/2006:16:11:16 +0200] "GET /index.php?lang=es HTTP/1.1" 200 66583 "-" "Mozilla/5.0"

208.184.111.58 [04/May/2006:16:14:36 +0200] [.]
[.]
208.184.111.58 [04/May/2006:16:14:46 +0200] [.]

195.229.242.84 [04/May/2006:16:23:58 +0200] [.]
[.]
195.229.242.84 [04/May/2006:16:30:31 +0200] [.]

The full harvest started at
[04/May/2006:16:01:35 +0200]
until
[04/May/2006:16:46:49 +0200].

Along with these a few more IPs, all using "Mozilla/5.0" UA and doing the same requests, were involved. We thus believe, they all belong to the same harvest. IPs were:

Administradores Telefonica de Espana, Ronda de la Comunicación s/n, Edificio Norte 1, planta 6ª, 28050 Madrid, SPAIN
80.58.205.32 32.Red-80-58-205.staticIP.rima-tde.net Network: RIMA

Abdulla Hashim, Emirates Telecommunication Corporation, P.O. Box 1150, Dubai, United Arab Emirates
195.229.242.84 ig890d2o.emirates.net.ae Network: EMIRNET-EMIRNET
195.229.242.85 492ycd5n.emirates.net.ae Network: EMIRNET-EMIRNET

Abovenet Communications, Inc, 4255 Shelbourne St., Victoria, New York
208.184.111.58 six.baremetal.com USA - Network: MFN-B687-208-184-111-0-26

Unicom China Hostmaster, 911 Room,Xin Tong Center,No.8 Beijing Railway Station, East Avenue, Beijing,PRC.
220.201.38.3 - Network: UNICOM

Saudi Network Information Center, ISU, King Abdulaziz City for Science and Technology,, P.O.Box 6086, Riyadh 11442, Saudi Arabia.
212.138.47.29 cache9-4.ruh.isu.net.sa Network: ISU-5
212.138.113.13 cache3-2.ruh.isu.net.sa Network: ISU-8-1
212.138.47.22 - Network: ISU-5
212.138.47.17 cache7-4.ruh.isu.net.sa Network: ISU-5
212.138.47.20 - Network: ISU-5
212.138.113.16 cache6-1.ruh.isu.net.sa Network: ISU-8-1
212.138.47.15 cache5-1.ruh.isu.net.sa Network: ISU-5
212.138.47.23 - Network: ISU-5
212.138.47.18 cache8-4.ruh.isu.net.sa Network: ISU-5
212.138.47.21 - Network: ISU-5
July 31 2007 04:25 PM

P.Hauser commented...
IP 195.229.242.54 was here, though with a different UA:

195.229.242.54 - - [17/Oct/2005:06:58:11 +0200] "GET / HTTP/1.1" 200 65801 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)"
195.229.242.54 - - [06/Dec/2005:14:50:29 +0100] "GET / HTTP/1.1" 200 65916 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows NT)"
July 31 2007 03:56 PM

Page generated on: February 15 2012 11:30:33 PM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | CloudFlare Site Protection | Contact Us

Copyright © 2004–12, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email