IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

208.66.195.4

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester and comment spammer. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location Unknown
IP Characteristics Blocklisted By: SpamHaus

Harvester First Seen approximately 8 years, 2 months, 1 week ago
Harvester Last Seen within 1 year, 1 week
Harvester Sightings 1,322 visit(s) to 589 honey pot(s)
Harvester Results 12685.434 messages per visit
16,770,144 message(s) resulting from harvests
- First: approximately 8 years, 1 month, 4 weeks ago
- Last: approximately 1 week ago
1,311 email address(es) harvested
- First: approximately 8 years, 2 months, 1 week ago
- Last: Mon, 04 Sep 2006 12:16:46 -0700
Time From Harvest
To First Spam
Fastest: 4 hours, 9 mins, 12 secs
Slowest: 1 week, 2 days, 20 hours, 9 mins, 49 secs
Average: 3 days, 23 mins, 28 secs
Std Dev: 1 day, 19 hours, 14 mins, 40 secs

First Post On approximately 1 year, 1 week ago
Last Post On within 1 year, 1 week
Form Posts 32 web post submission(s) sent from this IP

Associated Mail Servers
189.53.91.48 | S
189.81.152.75 | S
122.172.128.117 | SD
87.253.197.169 | S
77.106.14.93 | S
125.209.29.34 | SD
121.139.254.180 | S
89.80.150.243 | SD
113.8.26.235 | S
24.74.70.48 | SD
88.200.140.74 | S
87.20.220.135 | S
200.175.150.65 | S
93.120.187.198 | SD
201.92.177.210 | SD
124.43.59.127 | S
92.47.196.176 | SD
58.9.69.79 | S
194.78.101.2 | SD
189.47.200.197 | SD
62.29.78.124 
121.246.26.58 | SD
200.196.119.178 | SD
89.25.220.218 | S
72.50.74.31 | S
190.188.237.23 | S
193.93.219.222 | SD
219.238.219.27 | SD
83.27.3.134 | SD
70.168.13.182 | SD
189.47.200.179 | SDC
200.171.25.30 | SD
93.86.37.20 | SD
87.17.30.111 | S
200.68.112.121 | SD
221.209.43.2 | SD
201.63.159.33 | SD
81.38.175.231 | S
86.73.97.215 | S
59.103.91.84 | S
189.24.81.149 | S
189.58.170.214 | S
87.121.110.59 | SD
77.46.191.235 | S
116.209.225.163 | SD
88.232.237.220 | S
117.192.113.224 | SD
92.47.185.177 | SD
220.173.33.228 | S
82.208.122.58 | SD
201.62.135.51 | SD
93.84.85.231 | SD
122.159.246.32 | S
82.53.156.248 | S
93.112.74.186 | S
84.115.144.48 | SD
189.62.43.75 | SD
92.47.87.198 | S
201.54.171.167 | SD
94.178.35.26 | S
201.231.2.137 | SD
79.147.150.208 | S
190.133.140.244 | S
77.121.208.245 | S
92.83.251.250 | SD
189.101.4.132 | SD
212.15.152.92 | S
79.131.121.136 | S
190.99.184.138 | SD
190.174.94.147 | SD
125.176.21.69 | SD
222.87.4.240 | SD
78.36.247.190 | S
114.163.192.46 | SD
201.219.86.150 | SD
IPs In The Neighborhood
208.66.194.38
208.66.194.110
208.66.194.126
208.66.194.154 | H
208.66.194.160
208.66.194.162
208.66.194.163
208.66.194.164
208.66.194.165
208.66.194.166
208.66.194.167
208.66.194.168
208.66.194.169
208.66.194.170
208.66.194.171
208.66.194.172
208.66.194.173
208.66.194.174
208.66.194.178
208.66.194.179
208.66.194.184
208.66.194.199 | S
208.66.194.214
208.66.194.232
208.66.194.240
208.66.195.0
208.66.195.1
208.66.195.2 | H
208.66.195.3 | H
208.66.195.5 | H
208.66.195.6 | H
208.66.195.7 | H
208.66.195.8 | H
208.66.195.9 | H
208.66.195.10 | H
208.66.195.11 | H
208.66.195.12
208.66.195.13
208.66.195.14 | H
208.66.195.15 | H
208.66.195.19 | H
208.66.195.20 | H
208.66.195.21 | H
208.66.195.22 | H
208.66.195.23
208.66.195.30
208.66.195.31
208.66.195.35
208.66.195.41 | H
208.66.195.46
208.66.195.53
208.66.195.59
208.66.195.60
208.66.195.64
208.66.195.67
208.66.195.71
208.66.195.78
208.66.195.79 | H
208.66.195.83 | H
208.66.195.85
208.66.195.90 | H
208.66.195.101
208.66.195.110
208.66.195.116
208.66.195.121
208.66.195.123
208.66.195.125
208.66.195.126
208.66.195.140
208.66.195.145 | C
208.66.195.175 | S
208.66.195.203
Sample Spam URLs & Keywords Posted From 208.66.195.4
Domain: www.buyawindows7key.com
URL: http://www.buyawindows7key.com
Keywords: ray bans fake
Domain: pinterest.com
URL: http://pinterest.com/fashionsw/isabel-marant-sneakers-collection-box/
Keywords: isabel marant sneakers
Domain: onlineisabelmarantsneakers.tripod.com
URL: http://onlineisabelmarantsneakers.tripod.com
Keywords: isabel marant
Domain: onlineisabelmarant.tripod.com
URL: http://onlineisabelmarant.tripod.com
Keywords: sneakers isabel marant
Domain: isabelmarantsneaker.webpin.com
URL: http://isabelmarantsneaker.webpin.com
Keywords: isabel marant sneakers
Domain: isabelmarants.tripod.com
URL: http://isabelmarants.tripod.com
Keywords: isabel marant
Domain: isabelmarantsneakersstore.tripod.com
URL: http://isabelmarantsneakersstore.tripod.com
Keywords: sneakers isabel marant
Domain: imgfave.com
URL: http://imgfave.com/isabelmarantstore
Keywords: isabel marant
Domain: imgfave.com
URL: http://imgfave.com/isabelmarantsneakersoutlet
Keywords: isabel marant sneakers
Domain: isabelmarantoutlet.polyvore.com
URL: http://isabelmarantoutlet.polyvore.com
Keywords: isabel marant
Domain: www.luuux.com
URL: http://www.luuux.com/fashion/isabel-marant-sneakers-online-store-70-isabel-marant-shoes-outlet-store
Keywords: isabel marant shoes
Domain: www.luuux.com
URL: http://www.luuux.com/fashion/buy-isabel-marant-sneakers-70-isabel-marant-shoes-outlet-store
Keywords: isabel marant
Domain: www.facebook.com
URL: https://www.facebook.com/pages/Cheap-oakley-sunglassescheap-Oakleys-outlet/590234567656523
Keywords: cheap oakley sunglasses
Domain: fakeoakleysunglasses.zuhah.com
URL: http://fakeoakleysunglasses.zuhah.com
Keywords: fake oakleys
Domain: isabelmarantsneaker.webpin.com
URL: http://isabelmarantsneaker.webpin.com
Keywords: fake oakleys
208.66.195.4's User Agent Strings
none/blank
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; TencentTraveler ; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 2.0.50727 ; .NET CLR 4.0.30319)
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:19.0) Gecko/20100101 Firefox/19.0
psycheclone
P.Hauser commented...
This log shows why you should block TWO criteria and not only one:

First approach as UA "psycheclone", which received 302:

208.66.195.2 [20/Jun/2006:17:37:55 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
208.66.195.2 [20/Jun/2006:17:37:58 +0200] "GET / " 302 214 "-" "[same UA]"
208.66.195.4 [22/Jun/2006] "[same UA]"
208.66.195.6 [26/Jun/2006] "[same UA]"
208.66.195.6 [27/Jun/2006] "[same UA]"
208.66.195.3 [28/Jun/2006] "[same UA]"
208.66.195.4 [01/Jul/2006] "[same UA]"
208.66.195.6 [01/Jul/2006] "[same UA]"
208.66.195.3 [12/Jul/2006] "[same UA]"

Changing UA from "psycheclone" to
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)"
receiving 200:

208.66.195.9 [14/Jul/2006:00:42:50 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
208.66.195.9 [14/Jul/2006:00:43:20 +0200] "GET / " 200 66380 "-" "[same UA]"

208.66.195.5 [27/Jul/2006] "[same UA]"
[...]
208.66.195.5 [27/Jul/2006] "[same UA]"
208.66.195.10 [08/Aug/2006] "[same UA]"
[...]
208.66.195.10 [08/Aug/2006] "[same UA]"

First harvest with this UA:

208.66.195.10 [08/Aug/2006:12:53:09 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
[42 continued requests in 40 minutes / every minute one request]
208.66.195.10 [08/Aug/2006:13:24:20 +0200] "GET /[URL]&lang=cs " 200 68400 "-" "[same UA]"

208.66.195.19 [30/Aug/2006] [same UA]"
[...]
208.66.195.19 [30/Aug/2006] "[same UA]"

Second harvest with this UA:

208.66.195.22 [30/Aug/2006:10:45:54 +0200] "GET /robots.txt " 200 468 "-" "[same UA]"
[38 continued requests in 25 minutes / every minute one request, little faster]
208.66.195.22 [30/Aug/2006:11:07:09 +0200] "GET /[URL]&lang=es " 200 68965 "-" "[same UA]"

We stopped him:

208.66.195.9 [03/Sep/2006] "[same UA]"
[...]
208.66.195.9 [03/Sep/2006] "[same UA]"
208.66.195.7 [04/Sep/2006] "[same UA]"
[...]
208.66.195.7 [04/Sep/2006] "GET / " 302 214 "-" "[same UA]"
July 31 2007 07:26 PM

Page generated on: July 31 2014 08:21:34 AM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | CloudFlare Site Protection | Contact Us

Copyright © 2004–14, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email