IP Address Inspector

84.90.89.157

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester and mail server. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | OpenRBL | Spamcop | SenderBase | Google Groups | Google

Geographic Location Portugal (Santarem)

Harvester First Seen approximately 1 year, 5 months, 3 weeks ago
Harvester Last Seen within 1 month, 1 week
Harvester Sightings 210 visit(s) to 84 honey pot(s)
Harvester Results 0.91 messages per visit
191 message(s) resulting from harvests
- First: approximately 1 year, 4 months, 1 week ago
- Last: approximately 1 week ago
958 harvested address(es) have seen message(s)
- First: approximately 1 year, 5 months, 3 weeks ago
- Last: Tue, 15 Jul 2008 09:34:47 -0400
Time From Harvest
To First Spam
Fastest: 3 days, 15 hours, 39 mins, 41 secs
Slowest: 11 months, 2 weeks, 6 days, 19 hours, 56 mins, 51 secs
Average: 3 months, 2 weeks, 1 day, 12 hours, 36 mins, 4 secs
Std Dev: 2 months, 3 weeks, 6 days, 19 hours, 21 mins, 42 secs

First Received From approximately 1 year, 2 months, 1 week ago
Last Received From within 4 weeks
Number Received 147 email(s) sent from this IP

Associated Mail Servers
66.227.102.30 | SD
66.227.102.45 | SD
66.227.102.100 | SD
66.227.102.127 | S
66.227.102.133 | S
66.227.102.191 | S
68.142.206.39 | S
72.55.156.199 | S
76.13.13.75 | S
76.13.13.78 | S
77.54.134.10 | S
77.232.66.165 | S
84.90.89.157 | HS
84.90.249.184 | S
85.240.149.120 
85.240.156.169 
85.240.157.140 
87.103.7.21 
87.103.85.23 | S
93.108.18.126 | S
93.108.96.177 | S
93.108.99.108 | S
93.108.105.64 | S
93.108.111.198 
93.108.127.3 | S
123.49.48.4 
212.18.167.162 | SD
Associated Harvesters
84.90.89.157 | HS
87.103.44.95 | H
213.63.21.8 | H
213.63.21.28 | H
213.63.21.46 | H
213.63.55.254 | H
IPs In The Neighborhood
84.90.88.189 | S
84.90.88.190 | S
84.90.88.192 | S
84.90.88.195 | S
84.90.88.197 | S
84.90.88.203 | S
84.90.88.204 | S
84.90.88.209 | S
84.90.88.213 | S
84.90.88.220 | S
84.90.88.226 | S
84.90.88.228 | S
84.90.88.229 | S
84.90.88.230
84.90.88.239 | S
84.90.88.243 | S
84.90.88.246 | S
84.90.88.247 | S
84.90.88.251 | S
84.90.89.1 | S
84.90.89.4 | S
84.90.89.7 | S
84.90.89.9 | S
84.90.89.10 | S
84.90.89.11 | S
84.90.89.13 | S
84.90.89.21 | S
84.90.89.30 | S
84.90.89.36 | S
84.90.89.38 | S
84.90.89.40 | S
84.90.89.42 | S
84.90.89.48 | S
84.90.89.56 | S
84.90.89.61 | S
84.90.89.63 | S
84.90.89.67 | S
84.90.89.69 | S
84.90.89.85 | S
84.90.89.89 | S
84.90.89.90 | S
84.90.89.91 | S
84.90.89.92 | S
84.90.89.96 | S
84.90.89.105 | S
84.90.89.109 | S
84.90.89.111 | S
84.90.89.113 | S
84.90.89.118 | S
84.90.89.119 | S
84.90.89.123 | S
84.90.89.125 | S
84.90.89.134 | S
84.90.89.138 | S
84.90.89.139 | S
84.90.89.144 | S
84.90.89.146 | S
84.90.89.153 | S
84.90.89.154 | SD
84.90.89.155 | S
84.90.89.160 | S
84.90.89.165 | S
84.90.89.166 | S
84.90.89.167 | S
84.90.89.170 | SD
84.90.89.173 | S
84.90.89.176 | S
84.90.89.181 | S
84.90.89.183 | S
84.90.89.192 | S
84.90.89.195 | S
84.90.89.196 | S
84.90.89.198 | S
84.90.89.203 | S
Example Messages Sent From 84.90.89.157
From:
Subject: A FINEARTSPORTUGAL proporciona-lhe momentos de gra
From:
Subject: GO LAMPS
From:
Subject: My lamp at GOLAMPS
From:
Subject: My lamp at GOLAMPS
From:
Subject: My lamp at GOLAMPS
From:
Subject: New lamp generation
From:
Subject: One needs light in different ways.
From:
Subject: Yes to 30.000 lamps world
From:
Subject: You can now grow your own plants with this new lam
From:
Subject: Projector de video
From:
Subject: Video Projector
P.Hauser commented...
This IP was seen here again over and over with useless spoofing proxy probes.
84.90.89.157 is currently listed in APEWS :
Entry matching your Query: E-216059
84.90.88.0/21
CASE: C-82
IP space of "hot" UCE/UBE operations per NANAS, NANAE, UCEtraps & published statistics
Special Reason:
If your IP address is listed, go to Google Groups and search for your criteria in news.admin.net-abuse.sightings for evidence of your problem, you are causing abuse. If your IP address is NOT listed but is part of a larger IP listing, only the block owner can solve the problem, contact your ISP, see FAQ 16. Your ISP needs to action FAQ 42
History:
Entry created 2007-06-18
February 26 2008 01:50 AM

P.Hauser commented...
Block the whole range from 84.90.88.0 to 84.90.95.255. If you have a LINUX-shell, put all your apache-logfiles in one directory and check for these random user-agents with the following awk-command across your logs:

awk -F[\"] '($6!~ "[./(_):;\\+]"){print $1 $2 $3 $4 $5 $6 $7}' *_WhatEverYourLogNameIs

You could also put this regular expression into your .htaccess or some c-, php-check-code for live check of such

"harvester-spoofing"

and filter them out easily. Thus IP 84.90.89.157 (and many others) were here in vain:

84.90.89.157 - - [06/Aug/2007:19:04:47 +0200] "GET /index.php?lang=es HTTP/1.1" 403 2424 "-" "irp8iSjShmtwef SbqSyixglexvcf"
84.90.89.157 - - [06/Aug/2007:18:54:33 +0200] "GET /index.php?lang=es HTTP/1.1" 403 2424 "-" "dbw gGG ff2rmrGGbklfykgy"
84.90.89.157 - - [06/Aug/2007:17:11:28 +0200] "GET /index.php?lang=fr-fr HTTP/1.1" 403 2424 "-" "wk5vdhhlnsctiflnusgosggfk"
84.90.89.157 - - [06/Aug/2007:14:39:13 +0200] "GET /index.php?lang=it HTTP/1.1" 403 2424 "-" "djjtivbsHxdqvdywud3shdo m"

IPs also seen here:

84.90.89.34
84.90.89.207
84.90.89.109
84.90.89.157
84.90.89.157
84.90.89.214
84.90.90.68
August 06 2007 11:53 PM

P.Hauser commented...
IP 84.90.89.34 is not yet honey-pot-trapped and visited here in February with a random user-agent (apache-log):
84.90.89.34 - - [16/Feb/2007:09:26:10 +0100] "GET /index.php?lang=es HTTP/1.1" 200 66862 "-" "dlkqvfwlyfwlfgwrhxjvfxyh"
84.90.89.34 - - [16/Feb/2007:16:00:34 +0100] "GET /index.php?lang=es HTTP/1.1" 200 66870 "-" "gpFwF lhg f r rusbaqvsvocmlorwF"
84.90.89.34 - - [16/Feb/2007:16:36:45 +0100] "GET /index.php?lang=es HTTP/1.1" 200 66870 "-" "hm5wo5oxfj5hpbvxaatshn iqccwdr"
So it is obviously that this is NOT a HARMLESS spider.

% Information related to '84.90.88.0/21AS13156'

route: 84.90.88.0/21
whole range: 84.90.88.0 - 84.90.95.255
counting: 2048 IPs
descr: Cabovisao SA - Internet Provider
descr: F.Ferro (Equip2) Residential Customers Net
role: Cabovisao Network Team
address: Cabovisao, SA
address: Lugar de pocos
address: Palmela
address: Portugal
phone: +351 21 080 10 80
fax-no: +351 21 080 10 01
e-mail: network@cabovisao.pt
abuse-mailbox: abuse@netvisao.pt
July 24 2007 11:46 AM

P.Hauser commented...
IP 84.90.89.157 visits here with a random user-agent (apache-log):
84.90.89.157 - - [23/Jul/2007:11:35:30 +0200] "GET /index.php?lang=es HTTP/1.1" 403 2424 "-" "fStf igSocctmbmg ruosu"
84.90.89.157 - - [24/Jul/2007:10:22:10 +0200] "GET /index.php?lang=es HTTP/1.1" 403 6936 "-" "c8jebft8oyxpaufp8b fcTybs Torbmmui uflh"
So it is obviously that this is NOT a HARMLESS spider.
July 24 2007 11:11 AM

Page generated on: December 02 2008 11:23:32 PM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | Contact Us

Copyright © 2004–08, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

MITS