IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

208.66.195.10

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | OpenRBL | Spamcop | SenderBase | Google Groups | Google

Geographic Location Unknown
IP Characteristics Blocklisted By: SpamHaus

Harvester First Seen approximately 3 years, 5 months, 3 weeks ago
Harvester Last Seen within 3 years, 2 months, 3 weeks
Harvester Sightings 1,123 visit(s) to 558 honey pot(s)
Harvester Results 6976.947 messages per visit
7,835,111 message(s) resulting from harvests
- First: approximately 3 years, 5 months, 3 weeks ago
- Last: approximately 1 week ago
1,124 harvested address(es) have seen message(s)
- First: approximately 3 years, 5 months, 3 weeks ago
- Last: Sun, 03 Sep 2006 04:07:05 -0400
Time From Harvest
To First Spam
Fastest: 2 hours, 14 mins, 41 secs
Slowest: 1 week, 2 days, 21 hours, 32 mins, 24 secs
Average: 2 days, 23 hours, 28 mins, 30 secs
Std Dev: 1 day, 19 hours, 49 mins, 26 secs

Associated Mail Servers
79.97.4.92 | SD
97.118.206.39 | SD
118.92.211.108 | SD
58.10.213.84 | SD
200.112.85.66 | SD
95.28.15.71 
58.20.137.214 | S
68.150.34.23 | S
125.161.235.225 | S
71.184.79.141 | S
200.203.110.219 | SD
41.196.178.71 | SD
201.35.45.51 | S
203.232.99.172 | SD
221.223.83.221 | S
221.2.8.165 | S
201.214.174.78 | SD
94.28.191.205 | SD
200.29.125.243 | S
71.98.100.176 | SD
72.38.170.113 | S
201.78.98.155 | S
58.25.29.122 | SD
119.119.80.121 | S
173.68.126.156 | SD
218.2.77.165 | S
206.174.63.97 | SD
58.143.16.193 | SD
222.253.174.177 | SD
220.177.0.87 | S
24.176.210.30 | SD
58.173.153.99 | SD
190.26.179.194 | S
60.212.252.76 | S
116.226.102.42 
92.73.123.68 | SD
118.71.168.182 | SD
120.129.127.106 | SD
64.127.65.58 | SD
91.124.181.69 | SD
190.107.98.159 | S
190.245.175.223 | SD
77.234.12.151 | SDC
89.241.86.249 | S
86.166.250.55 
202.70.42.26 | SD
98.16.17.146 | S
201.54.27.2 | SD
84.217.72.232 | SD
89.240.208.71 | SD
190.65.224.10 | SC
84.127.207.151 | SD
196.217.70.42 | S
123.100.32.139 | SD
200.115.237.42 | S
200.101.251.101 | SD
189.26.65.199 | S
78.190.6.109 | S
77.25.195.167 | S
190.232.65.1 | SD
72.27.28.251 | S
201.240.245.125 | S
89.139.96.254 | SD
189.47.14.172 | S
60.32.51.162 | S
83.11.253.157 | S
98.198.208.5 | S
86.110.187.172 | SD
124.135.19.100 | SD
189.82.226.148 | SD
189.62.230.74 | D
203.163.255.66 | SD
87.210.154.65 | SD
92.39.212.4 | SD
85.100.236.173 | S
IPs In The Neighborhood
208.66.194.154 | H
208.66.194.162
208.66.194.163
208.66.194.164
208.66.194.165
208.66.194.166
208.66.194.167
208.66.194.168
208.66.194.169
208.66.194.170
208.66.194.171
208.66.194.172
208.66.194.173
208.66.194.174
208.66.194.178
208.66.194.179
208.66.194.184
208.66.194.199 | S
208.66.194.240
208.66.195.2 | H
208.66.195.3 | H
208.66.195.4 | H
208.66.195.5 | H
208.66.195.6 | H
208.66.195.7 | H
208.66.195.8 | H
208.66.195.9 | H
208.66.195.11 | H
208.66.195.12
208.66.195.15 | H
208.66.195.19 | H
208.66.195.20 | H
208.66.195.21 | H
208.66.195.22 | H
208.66.195.30
208.66.195.71
208.66.195.175 | S
208.66.195.10's User Agent Strings
none/blank
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)
psycheclone
P.Hauser commented...
This log shows why you should block TWO criteria and not only one:

First approach as UA "psycheclone", which received 302:

208.66.195.2 [20/Jun/2006:17:37:55 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
208.66.195.2 [20/Jun/2006:17:37:58 +0200] "GET / " 302 214 "-" "[same UA]"
208.66.195.4 [22/Jun/2006] "[same UA]"
208.66.195.6 [26/Jun/2006] "[same UA]"
208.66.195.6 [27/Jun/2006] "[same UA]"
208.66.195.3 [28/Jun/2006] "[same UA]"
208.66.195.4 [01/Jul/2006] "[same UA]"
208.66.195.6 [01/Jul/2006] "[same UA]"
208.66.195.3 [12/Jul/2006] "[same UA]"

Changing UA from "psycheclone" to
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)"
receiving 200:

208.66.195.9 [14/Jul/2006:00:42:50 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
208.66.195.9 [14/Jul/2006:00:43:20 +0200] "GET / " 200 66380 "-" "[same UA]"

208.66.195.5 [27/Jul/2006] "[same UA]"
[...]
208.66.195.5 [27/Jul/2006] "[same UA]"
208.66.195.10 [08/Aug/2006] "[same UA]"
[...]
208.66.195.10 [08/Aug/2006] "[same UA]"

First harvest with this UA:

208.66.195.10 [08/Aug/2006:12:53:09 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
[42 continued requests in 40 minutes / every minute one request]
208.66.195.10 [08/Aug/2006:13:24:20 +0200] "GET /[URL]〈=cs " 200 68400 "-" "[same UA]"

208.66.195.19 [30/Aug/2006] [same UA]"
[...]
208.66.195.19 [30/Aug/2006] "[same UA]"

Second harvest with this UA:

208.66.195.22 [30/Aug/2006:10:45:54 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
[38 continued requests in 25 minutes / every minute one request, little faster]
208.66.195.22 [30/Aug/2006:11:07:09 +0200] "GET /[URL]〈=es " 200 68965 "-" "[same UA]"

We stopped him:

208.66.195.9 [03/Sep/2006] "[same UA]"
[...]
208.66.195.9 [03/Sep/2006] "[same UA]"
208.66.195.7 [04/Sep/2006] "[same UA]"
[...]
208.66.195.7 [04/Sep/2006] "GET / " 302 214 "-" "[same UA]"
July 31 2007 10:40 PM

Page generated on: November 20 2009 02:22:21 PM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | Contact Us

Copyright © 2004–09, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email