IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

41.217.65.4

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester, mail server and dictionary attacker. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location Nigeria

Harvester First Seen approximately 2 years, 4 months, 5 weeks ago
Harvester Last Seen within 3 months, 4 weeks
Harvester Sightings 29 visit(s)
Harvester Results 0.483 messages per visit
14 message(s) resulting from harvests
- First: approximately 1 year, 5 months, 1 week ago
- Last: approximately 2 months, 3 weeks ago
6 email address(es) harvested
- First: approximately 1 year, 5 months, 2 weeks ago
- Last: Wed, 19 Oct 2011 09:14:45 -0700

First Received From approximately 2 years, 4 months, 5 weeks ago
Last Received From within 3 months, 3 weeks
Number Received 692 email(s) sent from this IP

Dictionary Attacks 246 email(s) sent from this IP
First Received From approximately 2 years, 4 months, 1 week ago
Last Received From within 3 months, 3 weeks

Associated Mail Servers
12.220.17.98 | S
59.125.176.137 | S
69.10.135.5 | SD
69.49.111.76 
69.64.155.204 
122.152.128.114 | SW
200.68.94.105 | S
207.65.96.30 
217.19.237.58 | S
218.94.114.198 | SD
Associated Harvesters
86.12.250.130 | HS
71.158.134.213 | HC
70.84.146.34 | H
66.148.67.101 | H
82.208.169.20 | HS
64.59.144.24 | H
210.4.61.230 | H
71.139.1.122 | HS
66.197.145.5 | HS
121.44.249.133 | H
204.15.164.206 | H
75.51.169.122 | H
24.63.58.72 | H
67.176.57.125 | H
208.66.195.22 | H
74.54.184.162 | H
75.69.196.5 | H
82.156.248.15 | H
85.204.225.133 | H
64.56.66.38 | H
80.90.233.234 | H
74.86.209.74 | H
216.40.222.66 | H
216.40.220.34 | H
216.40.222.82 | HSD
75.125.47.162 | HSDW
208.101.44.3 | H
74.53.243.18 | HC
74.53.249.34 | HW
75.125.18.178 | H
216.40.222.98 | H
70.85.113.242 | H
75.125.52.146 | H
74.62.254.109 | H
83.143.233.170 | H
74.54.110.194 | H
208.66.195.6 | H
76.109.206.211 | H
84.151.8.203 | H
208.66.195.10 | H
208.66.195.3 | H
220.246.128.225 | H
75.125.52.82 | H
75.125.52.98 | HS
208.53.147.89 | H
216.40.222.50 | H
81.169.235.127 | HSC
91.105.35.154 | H
67.86.138.59 | HC
75.125.194.194 | HS
208.66.195.20 | H
123.112.169.19 | H
74.170.103.240 | H
75.125.194.210 | H
220.161.98.30 | H
74.86.14.10 | H
208.66.195.8 | H
208.66.195.4 | H
216.12.207.226 | HC
208.66.195.2 | H
84.233.247.100 | HS
64.34.255.239 | HC
62.193.27.246 | H
70.86.161.50 | HC
125.24.83.163 | HS
91.21.101.237 | H
208.66.195.5 | H
74.86.249.98 | H
209.59.143.197 | HS
70.87.196.242 | H
208.65.60.105 | H
201.243.39.33 | H
216.40.220.18 | H
70.84.228.106 | H
70.85.172.170 | H
IPs In The Neighborhood
41.217.64.220
41.217.65.3 | HSD
41.217.65.5 | HSD
41.217.65.10 | HSD
41.217.65.11 | HSD
41.217.65.13 | HSDC
41.217.65.14 | HSD
41.217.65.113
41.217.65.4's User Agent Strings
Java/1.4.1_04
Java/1.6.0_21
Mozilla/4.0 (compatible; MSIE 6.0; Win32)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.2)
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; InfoPath.2; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident/4.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.0.30618; .NET CLR 3.5.30729)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; Trident/4.0; GTB6.3; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Mozilla/4.0 (compatible; MSIE 8.0; Win32)
Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US) AppleWebKit/532.5 (KHTML, like Gecko) Chrome/4.0.249.11 Safari/532.5
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.10) Gecko/20100914 Firefox/3.6.10
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.2.8) Gecko/20100722 Firefox/3.6.8
Mozilla/5.0 (Windows; U; Windows NT 6.0; de; rv:1.8.1.12) Gecko/20080201 Firefox/2.0.0.12
Mozilla/5.0 (Windows; U; Windows NT 6.0; en-GB; rv:1.9.1.2) Gecko/20090729 Firefox/3.5.2 (.NET CLR 3.5.30729)
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.62 Safari/534.3
Mozilla/5.0 (X11; U; Linux i686; en-US) AppleWebKit/533.2 (KHTML, like Gecko) Chrome/5.0.342.9 Safari/533.2
Example Messages Sent From 41.217.65.4
From:
Subject: Still single?look at my profile, Olga from Russia
From:
Subject: Дocт
From:
Subject: I am still a virgin is like? Not want to help me r
From:
Subject: I'll gently kiss your neck, lower and lower, come
From:
Subject: ione_u_consolini@hop.bernd.priv.at Rolex For You N
From:
Subject: ХОТИТЕ ЧИТАТЬ ЧУЖИЕ СМС?
From:
Subject: Re: Fw: Re: Fw: Windows 7, Office 2010, Adobe CS5
From:
Subject: Fw: Windows 7, Office 2010, Adobe CS5 ...
From:
Subject: Fw: Windows 7, Office 2010, Adobe CS5 ...
From:
Subject: Fw: Fw: Windows 7, Office 2010, Adobe CS5 ...
From:
Subject: Fw: Fw: Windows 7, Office 2010, Adobe CS5 ...
From:
Subject: ACH Payment 2138686 Canceled
From:
Subject: The validity of the football forecasts is limited.
From:
Subject: The validity of the football forecasts is limited.
From:
Subject: Connecting Today's Global Businesses with Translat
From:
Subject: Connecting Today's Global Businesses with Translat
From:
Subject: Connecting Today's Global Businesses with Translat
From:
Subject: Connecting Today's Global Businesses with Translat
From:
Subject: Re: SoftwareStore
From:
Subject: Экспресс проверка квартальной
From:
Subject: =?windows-1251?B?0vPw+yDi+/Xu5O3u4+4g5O3/IO3gIO3u/=?=
From:
Subject: Maintain their health.
From:
Subject: ione_benike@epsilon.sm-wg.net Rolex For You Now -9
Example User Names Used By 41.217.65.4
User-name: a
User-name: ab
User-name: advertising
User-name: aepq
User-name: ascheman
User-name: buh
User-name: buhg
User-name: buhgalter
User-name: buhgalteria
User-name: bux
User-name: christopher-blowiron
User-name: dbbndjfeadfdj
User-name: dbbndjfkaxfdj
User-name: desimone
User-name: dir
User-name: director
User-name: direktor
User-name: ehlen
User-name: ein
User-name: fcnk
User-name: finance
User-name: glavbuh
User-name: heister
User-name: hmt
User-name: iamjustsendingthisleter
User-name: ifjx
User-name: info
User-name: izrdj
User-name: jmbip
User-name: kerencaparros
H.User7043 commented...
419 "Take Away" SpamScam from above IP, using IP 221.143.46.9 as relay. Spammer warns that someone else is trying to claim my millions:

Did you authorize
Mr.Alex Godwin
CBN
E-mail address;(alex_godwin@qatar.io)
+234 808-241-5183
October 22 2010 06:48 AM

H.User7043 commented...
Pfishing email from above IP, using IP 58.68.145.51 as relay, purporting to be from YAHOO! and threatening to close my account if I don't fill out my log-in details via a special link they have conveniently provided.
October 22 2010 06:43 AM

M.Mathews3 commented...
Received:from smtp2.wealdnet.co.uk ([82.147.22.82]) by col0-mc3-f22.Col0.hotmail.com with MicrosoftSMTPSVC(6.0.3790.4675)Sun,17Oct2010 20:09:59-0700Received:from User([41.217.65.4])
by smtp2.wealdnet.co.uk (8.13.8/8.13.8)ESMTP id o9I39BJE003557;
Mon,18Oct2010 04:09:19+0100Message-Id:
From:Date: Mon, 18 Oct 2010 04:09:51 +0100Return-Path: mrswalt6@hotmail.com
X-OriginalArrivalTime: 18 Oct 2010 03:09:59.0414(UTC) FILETIME=[F2CE0960:01CB6E71]
Dear Friend,
Iam Mrs.SusanWalter,I am anAmerican,39 yearsOld.Ireside in Houston Texas.My residential address is as follows;NANES DR108 HOUSTON,TX77090, UnitedState.I am oneof thosethat executed a contract in Nigeria yearsback and they refused to pay me,I paid over$20,000 trying to getmy payment all to no avail.So I decided to travel down to Nigeria with mycontract documents,And I was directed to meet BarristerAfam Morgan Esq, who is a member ofCONTRACT AWARD COMMITTEE,I contacted him and he explained everything to me.He said that those contacting us through emails are fake.Then he took me to the payment issuing bank,which is OceanicBank of Nigeria.I am the happiest woman on earth because I have received my contract payment of $4.2Million. Moreover,Barrister Afam Morgan Esq, showed me the full information of those that have not received their payment which was how I saw your name as the beneficiary, and your email address/Telephone number including your contract amount.You have to contact him directly with the below informations.Cont Name: Barrister Afam Morgan Esq Email:barristerafam26@gmail.com
Tel: +234-7067834560
Office Address:13,Zion Street,Ikeja Lagos Nigeria.You really have to stop your dealings with those contacting you because they will dry you up until you have nothing left with you.The only money I paid was just$420 for IRS permit which you know, So you have to take note of that.Mrs.Susan Walter.
October 17 2010 11:39 PM

H.User7043 commented...
419 SpamScam from above IP, using IP 60.251.44.198 as relay:

I am seeking your assistance
MRS. ESTHER KOMBAYI
estherkombayi@gmail.com
September 30 2010 02:52 PM

H.User7043 commented...
419 SpamScam from above IP, using IP 212.56.101.103 as relay:

Family's Estate
Mohammed Abacha.
ma7766731@yahoo.cn
September 23 2010 08:28 AM

J.White-Mounta commented...
trustedtman2010@yahoo.com with the 41.217.65.4 IP address recently scammed a friend of mine out of $6000.00+
September 21 2010 06:45 PM

H.User7043 commented...
419 SpamScam from above IP, using 3 hijacked servers at vassar.edu as relays:

Your Reply
BANK CONTACT INFORMATION
Contact Person: Mr. Robert Diamond
Contact E-mail: info@barclaysgroups.org
Contact Phone No.: +447035971348
September 19 2010 07:03 AM

H.User7043 commented...
419 SpamScam:

Law Chamber Principal Attorney
Okoh Frank & Associates
44, Kofo Abayomi Avenue,
Victoria Island,
Lagos-Nigeria.
September 08 2010 08:09 PM

H.User7043 commented...
Attachment email from above IP, using IP 195.4.92.91 as relay:

Message From Mrs Debraca Ford
From: "Ddert@aol.com" (Ddert@aol.com)

Mrs Debraca Ford.rtf (8KB)
August 30 2010 10:29 AM

H.User7043 commented...
419 SpamScam from above IP, using IP 221.143.46.9 as relay:

From the desk of Alex Godwin,
The Manager of the International
Remittance Department of the
Central Bank of Nigeria.
August 28 2010 06:02 PM

H.User3937 commented...
a TON of email harvesting keywords coming through search engines. SHUT THESE GUYS DOWN!
March 04 2010 12:24 PM

C.Seton commented...
Received from IP Nigeria..........spam

From: Windows Live™ (gerl_helena_94@hotmail.com)
Sent: Monday, 15 February 2010 2:13:37 PM
To:
Update and Verify your Account

Windows Live Hotmail Alert !!!

CONFIRM YOUR WINDOWS LIVE ACCOUNT SERVICES. VERIFY YOUR HOTMAIL ACCOUNT NOW TO AVOID IT CLOSED !!!

If you are still interested please confirm your account by filling the space below.Your User name, password, date of birth and your country information would be needed to verify your account.

Confirm your E-mail by filling out your Login Information below after clicking the reply button, or your account will be suspended within 48 hours for security reasons.

* User Name: .............................
* Password: ................................
* Date of Birth: ..............................
* Country Or Territory: ................

After following the instructions in the sheet, your account will not be interrupted and will continue as normal. Thanks for your attention to this request. We apologize for any inconveniences.

Sincerely,
The Windows Live Hotmail Team

* Bring in your contacts from your Yahoo! or Gmail address book

* Personalize your email by changing the color of your inbox

Hotmail is part of Windows Live.
* This assumes a reasonable growth rate.
Microsoft respects your privacy. To learn more, please read our online Privacy Statement.
For more information or for general questions regarding your e-mail account, please visit Windows Live Hotmail Help.Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA © 2009 Microsoft Corporation. All rights reserved.
February 14 2010 09:52 PM

H.User1939 commented...
Cutwail Botnet Rootkit, using standard reporting would be no good, please contact server owner to pull the plug and take the botnet harvestor offline.
January 12 2010 06:29 AM

Page generated on: February 11 2012 04:07:32 AM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | CloudFlare Site Protection | Contact Us

Copyright © 2004–12, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email