IP Address Inspector

ATTENTION
  • This IP has not seen any suspicious activity within the last 3 months. This IP is most likely clean and trustworthy now. (This record will remain public for historical purposes, however.)

89.122.29.80

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester and rule breaker. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location Romania

Harvester First Seen approximately 5 years, 3 months, 3 weeks ago
Harvester Last Seen within 2 years, 9 months, 5 weeks
Harvester Sightings 7,778 visit(s) to 270 honey pot(s)
Harvester Results 150.833 messages per visit
1,173,181 message(s) resulting from harvests
- First: approximately 5 years, 3 months, 2 weeks ago
- Last: approximately 1 week ago
6,291 email address(es) harvested
- First: approximately 5 years, 3 months, 3 weeks ago
- Last: Thu, 15 Jul 2010 08:57:40 -0700
Time From Harvest
To First Spam
Fastest: 3 hours, 29 mins, 36 secs
Slowest: 1 week, 5 days, 1 hour, 14 mins, 17 secs
Average: 3 days, 5 hours, 5 mins, 59 secs
Std Dev: 2 days, 10 hours, 58 mins, 57 secs

First Rule-Break On approximately 3 years, 1 week ago
Last Rule-Break On within 2 years, 10 months, 1 week
Rule Breaks 3 web page navigation rule(s) broken by this IP

Associated Mail Servers
1.209.163.3 | SD
1.226.83.81 | SD
1.226.83.199 | SD
1.226.84.175 | SD
1.234.4.33 | SD
1.234.4.166 | SD
1.234.6.7 | SD
1.234.6.81 | SD
1.234.6.211 | SD
1.234.50.245 | SD
1.234.50.252 | SD
1.234.51.209 | SD
1.234.62.98 | SDC
2.186.85.3 | S
5.46.49.23 
14.33.121.67 | SD
14.37.204.49 | SD
14.47.20.245 | SDC
14.97.217.75 | S
24.72.140.44 | S
27.110.222.109 | S
27.191.208.233 | SD
31.214.133.230 | HS
31.214.133.231 | HS
31.214.133.232 | HS
31.214.133.233 | S
31.214.139.72 | SC
31.214.139.73 | S
31.214.139.74 | SD
31.214.139.75 | S
31.214.169.112 | S
31.214.169.113 | S
31.214.169.114 | SC
31.214.201.54 | SC
31.214.201.55 | S
37.191.78.91 
41.140.132.200 | SD
41.146.152.161 | S
41.201.172.125 | SD
41.209.65.131 | SD
42.61.42.162 | SD
46.20.219.244 | SD
46.33.216.255 | SD
46.226.182.10 | S
46.251.237.74 | SDC
46.251.237.161 | SD
46.251.237.164 | SDC
46.251.237.166 | HSD
46.251.237.168 | SD
49.200.11.85 | S
58.23.9.75 | SD
58.30.227.42 | SD
58.49.59.80 | SD
58.53.144.35 | SD
58.57.12.29 | SD
58.64.228.224 | SD
58.68.80.117 | S
58.120.155.248 | SD
58.120.227.143 | SD
58.120.227.155 | SD
58.120.227.160 | SD
58.151.149.118 | SD
58.180.26.203 | SD
58.220.225.27 | HSD
58.227.21.27 | SD
58.230.118.125 | SD
58.232.221.43 | SD
58.244.204.66 | S
58.244.217.40 | S
58.244.217.47 | S
58.251.129.38 | SD
59.15.76.97 | SD
59.41.70.26 | SD
59.46.201.54 | SD
59.90.200.16 | S
IPs In The Neighborhood
89.122.28.142 | D
89.122.28.201
89.122.29.1
89.122.29.3 | HR
89.122.29.8
89.122.29.10 | S
89.122.29.12 | S
89.122.29.14
89.122.29.16
89.122.29.19
89.122.29.21
89.122.29.22 | S
89.122.29.25
89.122.29.27 | SD
89.122.29.29 | SD
89.122.29.30
89.122.29.31 | HR
89.122.29.32 | HSR
89.122.29.33 | HR
89.122.29.34 | S
89.122.29.35 | HR
89.122.29.36 | H
89.122.29.37 | HR
89.122.29.38 | SD
89.122.29.39 | HR
89.122.29.40 | H
89.122.29.42 | D
89.122.29.43 | S
89.122.29.47
89.122.29.49
89.122.29.50
89.122.29.54 | S
89.122.29.57
89.122.29.58
89.122.29.59
89.122.29.60
89.122.29.61 | H
89.122.29.65
89.122.29.68
89.122.29.70 | S
89.122.29.74 | SD
89.122.29.75 | SD
89.122.29.76 | H
89.122.29.77 | H
89.122.29.78
89.122.29.79 | H
89.122.29.81 | H
89.122.29.82 | HSDR
89.122.29.83 | S
89.122.29.84 | S
89.122.29.85 | S
89.122.29.86
89.122.29.87
89.122.29.88
89.122.29.89
89.122.29.90
89.122.29.91 | S
89.122.29.92 | SD
89.122.29.94
89.122.29.96 | SD
89.122.29.100
89.122.29.101
89.122.29.104 | H
89.122.29.105 | H
89.122.29.107 | S
89.122.29.108
89.122.29.112
89.122.29.113
89.122.29.118
89.122.29.121 | S
89.122.29.122 | H
89.122.29.123 | SD
89.122.29.124 | H
89.122.29.125 | H
89.122.29.126 | H
89.122.29.127 | H
89.122.29.128 | H
89.122.29.131 | S
89.122.29.133 | SD
89.122.29.136 | S
89.122.29.138 | C
89.122.29.140 | S
89.122.29.147
89.122.29.148
89.122.29.150
89.122.29.153 | SD
89.122.29.155
89.122.29.159
89.122.29.205 | S
89.122.29.215 | S
89.122.29.218 | SD
89.122.29.227
89.122.29.237
89.122.29.245
89.122.29.250 | S
89.122.30.4 | SD
89.122.30.9 | SD
89.122.29.80's User Agent Strings
Java/1.6.0_04
Java/1.6.0_11
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727)
M.Pasquale commented...
Name: Unknown
IP Address: 89.122.29.80
Location: BUCURESTI (44.433N, 26.106E)
Network: 89-RIPE
June 01 2009 06:53 AM

K.Sumurai commented...
Bot did 12 times a request on my wiki. Seems to like HTTP/1.1

Bot tries some files (even root and some kind of google-analytics-js that was placed at the end of my pages). First searched some png-files, then used a piece of a .js-script (404-error), then took the api to search the site and tried to access the search.php-file. Stopped when trying to access root; (301-error)

Bot is using Java/1.6.0_04 now. No known
April 27 2009 02:13 PM

V.De Waal commented...
I saw it today for the second time in a week. It tried to bypass a login.
I shall change the script, so not only the ipadress is showed, but also the words he uses to get in.
February 21 2009 02:35 AM

I.Ellis commented...
This IP was blocked, as all from China are blocked from my site.
It used UA "Java/1.6.0_04" coming for homepage, but maybe gave up after it got a 403.

Some time in the past my site has also seen nearby IPs, and are now specifically on my deny list for trying to access the guestbook trap:
deny from 89.122.29.105
deny from 89.122.29.127
January 18 2009 09:20 AM

A.Degives Mas commented...
Repeatedly and in rapid succession attempts to probe for access to a variety of files, arguably trying to fingerprint the server system. Displays a UA of Java/1.6.0_11. Operates in very close time proximity and with almost identical probes from IP 81.202.14.52 - that one differs merely on a different UA namely Java/1.6.0_07.

One interesting feature these all have in common is that in the headers they send they show Accept: text/html, image/gif, image/jpeg, *; q=.2, */*; q=.2
December 30 2008 02:28 PM

Page generated on: May 20 2013 09:01:55 AM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | CloudFlare Site Protection | Contact Us

Copyright © 2004–13, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email