IP Address Inspector

85.214.73.63

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester and comment spammer. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location Germany

Harvester First Seen approximately 4 years, 2 months, 4 weeks ago
Harvester Last Seen within 2 weeks
Harvester Sightings 2,746 visit(s)
Harvester Results 0.003 messages per visit
8 message(s) resulting from harvests
- First: approximately 2 years, 10 months, 2 weeks ago
- Last: approximately 2 years, 7 months, 1 week ago
7 email address(es) harvested
- First: approximately 2 years, 10 months, 3 weeks ago
- Last: Wed, 01 Jul 2009 12:40:31 -0700

First Post On approximately 3 years, 11 months, 2 weeks ago
Last Post On within 2 weeks
Form Posts 770 web post submission(s) sent from this IP

Associated Mail Servers
78.41.233.122 | SW
79.120.54.173 | SD
IPs In The Neighborhood
85.214.72.106
85.214.72.137
85.214.72.142
85.214.72.166 | C
85.214.72.201 | S
85.214.72.223
85.214.72.248 | S
85.214.73.32
85.214.73.35
85.214.73.40
85.214.73.66
85.214.73.74 | W
85.214.73.78
85.214.73.79
85.214.73.81
85.214.73.107 | W
85.214.73.110
85.214.73.118
85.214.73.125
85.214.73.126 | S
85.214.73.141
85.214.73.160 | SC
85.214.73.166
85.214.73.176
85.214.73.178 | D
85.214.73.192
85.214.73.206
85.214.73.210
85.214.73.223 | W
85.214.73.229 | SD
85.214.73.234 | W
85.214.73.251
85.214.74.17
85.214.74.18 | SW
85.214.74.21
Sample Spam URLs & Keywords Posted From 85.214.73.63
Domain: blog.erolove.in
URL: http://blog.erolove.in/land?ps.html
Domain: bookgrill.com
URL: http://bookgrill.com/?geted.html
Domain: www.drdrebeatsdeutschland.eu
URL: http://www.drdrebeatsdeutschland.eu
Keywords: beats by dre detox
Domain: www.drdrebeatsdeutschland.e
URL: http://www.drdrebeatsdeutschland.e
Keywords: beats by dre detox
Domain: bookgrill.com
URL: http://bookgrill.com/?getes.html
Domain: www.moncleronlineshopwien.eu
URL: http://www.moncleronlineshopwien.eu
Keywords: moncler jacken wien
Domain: www.moncleronlineshopwien.e
URL: http://www.moncleronlineshopwien.e
Keywords: moncler jacken wien
Domain: nwarriors.com
URL: http://nwarriors.com
Keywords: adult dating in cornlea nebraska
Domain: nwarriors.com
URL: http://nwarriors.com
Keywords: adult dating in cornlea nebraska
Domain: members.aol.com
URL: http://members.aol.com/fno08i3co/august-693.html
Keywords: autogara cluj napoca
Domain: members.aol.com
URL: http://members.aol.com/fno08i3co/august-63.html
Keywords: us army promotion worksheet
Domain: members.aol.com
URL: http://members.aol.com/fno08i3co/august-777.html
Keywords: us attorney northern district of ohio
Domain: members.aol.com
URL: http://members.aol.com/fno08i3co/august-464.html
Keywords: us army uniform pictures
Domain: members.aol.com
URL: http://members.aol.com/fno08i3co/august-42.html
Keywords: huachuca mountain elementary school
Domain: members.aol.com
URL: http://members.aol.com/fno08i3co/august-324.html
Keywords: us army sniper pictures
85.214.73.63's User Agent Strings
none/blank
Akregator/1.5.1; syndication
Akregator/1.6.3; syndication
Akregator/1.6.5; syndication
ArabyBot (compatible; Mozilla/5.0; GoogleBot; FAST Crawler 6.4; http://www.araby.com;)
CJB.NET
curl/7.19.4 (i686-pc-linux-gnu) libcurl/7.19.4 OpenSSL/0.9.8k zlib/1.2.3
HPPrint
Mozilla/0.6 Beta (Windows)
Mozilla/0.91 Beta (Windows)
Mozilla/1.22 (compatible; MSIE 2.0d; Windows NT)
Mozilla/1.22 (compatible; MSIE 2.0; Windows 95)
Mozilla/2.0 compatible; Check&Get 1.14 (Windows NT)
Mozilla/2.0 (compatible; MSIE 3.02; Windows CE; 240x320)
Mozilla/3.0 (compatible; WebCapture 2.0; Auto; Windows)
Mozilla/3.0 (x86 [en] Windows NT 5.1; Sun)
Mozilla/4.0 (compatible; MSIE 4.01; Digital AlphaServer 1000A 4/233; Windows NT; Powered By 64-Bit Alpha Processor)
Mozilla/4.0 (compatible; MSIE 5.01; Windows 95; MSIECrawler)
Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Mozilla/4.0 (compatible; MSIE 5.0; Mac_PowerPC; AtHome021)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 2000) Opera 6.0 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows 3.1)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; BCD2000)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0; .NET CLR 1.0.2914)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0 )
F.Fox commented...
Used in a dictionary (password) attack on member accounts on our board. Over 100 different IPs used.
March 10 2011 03:49 AM

C.Johnson18 commented...
trying to log in our SMF forums too. banned.
February 15 2011 06:55 AM

A.Weil commented...
TOR exit used for multiple dictionary attacks
February 11 2011 09:21 AM

H.User875 commented...
Related IPs:
* 85.214.73.63
- 195.148.124.67
- 77.70.54.81
- 63.214.236.116
- 222.106.131.46

(Identical nonsense Request from these IPs within a few seconds)
January 24 2010 05:07 AM

B.Smith24 commented...
85.214.73.63 - Tried to register in our forums. Defeated by captcha... :)
December 21 2009 09:09 AM

M.Duncan commented...
This IP hosts a Tor exit node :-(

http://torstatus.kgprog.com/tor_exit_query.php

These deserve a Honeypot category all of their own
September 23 2009 01:49 PM

Page generated on: February 09 2012 12:13:13 AM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | CloudFlare Site Protection | Contact Us

Copyright © 2004–12, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email