IP Address Inspector

93.166.121.107

The Project Honey Pot system has detected behavior from the IP address consistent with that of a spam harvester, comment spammer and rule breaker. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location Denmark

Harvester First Seen approximately 1 year, 10 months, 5 weeks ago
Harvester Last Seen within 1 week
Harvester Sightings 6,235 visit(s)
Harvester Results 0 messages per visit
1 message(s) resulting from harvests
- First: approximately 7 months, 4 weeks ago
- Last: approximately 7 months, 4 weeks ago
1 email address(es) harvested
- First: approximately 8 months, 2 weeks ago
- Last: Tue, 11 Sep 2012 02:52:02 -0700

First Post On approximately 1 year, 10 months, 5 weeks ago
Last Post On within 1 week
Form Posts 2,228 web post submission(s) sent from this IP

First Rule-Break On approximately 5 months, 2 weeks ago
Last Rule-Break On within 5 months, 2 weeks
Rule Breaks 1 web page navigation rule(s) broken by this IP

Associated Mail Servers
217.197.114.153 | SD
IPs In The Neighborhood
93.166.121.106 | C
93.166.121.108
Sample Spam URLs & Keywords Posted From 93.166.121.107
Domain: bardclub.net
URL: http://bardclub.net/goto/http://www.facebook.com/profile.php?id=1435583192
Domain: www.facebook.com
URL: http://www.facebook.com/profile.php?id=1435583192
Domain: tomsukshoes.webeden.co.uk
URL: http://tomsukshoes.webeden.co.uk/
Keywords: longchamp uk
Domain: buylongchampukbags.blogspot.com
URL: http://buylongchampukbags.blogspot.com/
Keywords: longchamp uk
Domain: uklongchamp-bag.webeden.co.uk
URL: http://uklongchamp-bag.webeden.co.uk
Keywords: longchamp uk
Domain: tomsukshoes.webeden.co.uk
URL: http://tomsukshoes.webeden.co.uk
Keywords: toms shoes uk
Domain: buylongchampukbags.blogspot.com
URL: http://buylongchampukbags.blogspot.com
Keywords: longchamp bags
Domain: www.neuroblastomafoundation.org
URL: http://www.neuroblastomafoundation.org/members/xulioxui/default.aspx
Domain: ispropranololprescripiju.metroblog.com
URL: http://ispropranololprescripiju.metroblog.com/
Keywords: propranolol hcl 40 mg
Domain: longdoes20mgpropranolydu.metroblog.com
URL: http://longdoes20mgpropranolydu.metroblog.com/
Keywords: how long does 40 mg propranolol last
Domain: ispropranololprescripiju.metroblog.com
URL: http://ispropranololprescripiju.metroblog.com/
Keywords: much does propranolol cost
Domain: ispropranololprescripiju.metroblog.com
URL: http://ispropranololprescripiju.metroblog.com/
Keywords: propranolol anxiety rash
Domain: www.net999.cn
URL: http://www.net999.cn/web
Domain: www.kangnuanlai.com
URL: http://www.kangnuanlai.com/bbs/forum.php?mod=viewthread&tid=352380
Domain: bbs4.gcxabbs.com
URL: http://bbs4.gcxabbs.com/forum.php?mod=viewthread&tid=63
93.166.121.107's User Agent Strings
EPOC32-WTL/2.0 (VGA) STNC-WTL/2.0(230)
FeedshowOnline (http://www.feedshow.com) 
Mozilla/0.6 Beta (Windows)
Mozilla/0.91 Beta (Windows)
Mozilla/1.22 (compatible; MSIE 2.0d; Windows NT)
Mozilla/1.22 (compatible; MSIE 2.0; Windows 95)
Mozilla/2.0 (compatible; MSIE 3.02; Windows CE; 240x320)
Mozilla/3.0 (compatible; Indy Library)
Mozilla/3.0 (compatible; WebCapture 2.0; Auto; Windows)
Mozilla/4.0 (compatible; ICS)
Mozilla/4.0 (compatible; MSIE 4.01; Digital AlphaServer 1000A 4/233; Windows NT; Powered By 64-Bit Alpha Processor)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 2000) Opera 6.0 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows 3.1)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT 5.1; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt)
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt; DTS Agent
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; BCD2000)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; MSOCD; AtHomeNL191)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0; .NET CLR 1.0.2914)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)
Mozilla/4.0 (compatible; MSIE 6.0; America Online Browser 1.1; rev1.2; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1)
mozilla/4.0 (compatible; msie 6.0; aol 9.0; windows nt 5.1; sv1; .net clr 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 4.0) Opera 7.0 [en]
H.User7152 commented...
Does weird stuff with referrers and can't get its URL request right:

122.224.216.162 - - [02/Nov/2012:12:25:50 +0000] "GET /http:/[my server]/archives/1721/archives/1721/archives/1721/archives/1721/archives/1721/archives/1721/archives/1721 HTTP/1.0" 403 1061 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
122.224.216.162 - - [02/Nov/2012:12:25:54 +0000] "GET / HTTP/1.0" 403 939 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
202.102.48.205 - - [02/Nov/2012:12:26:04 +0000] "GET /http://[my server]//archives/1721 HTTP/1.0" 403 979 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
93.166.121.107 - - [02/Nov/2012:12:26:11 +0000] "GET /http://[my server]//archives/1721 HTTP/1.0" 403 979 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
93.166.121.107 - - [02/Nov/2012:12:26:14 +0000] "GET / HTTP/1.0" 403 939 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
122.224.216.162 - - [02/Nov/2012:12:26:18 +0000] "GET /http://[my server]//archives/1721 HTTP/1.0" 403 979 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
106.187.37.167 - - [02/Nov/2012:12:26:19 +0000] "GET /http:/[my server]/archives/1721/archives/1721/archives/1721 HTTP/1.0" 403 1005 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
42.120.49.48 - - [02/Nov/2012:12:26:27 +0000] "GET /http:/[my server]/archives/1721/archives/1721/archives/1721/archives/1721 HTTP/1.0" 403 1019 "http://[my server]/archives/1721" "Opera/9.80 (Windows NT 6.1; U; ru) Presto/2.10.289 Version/12.00"
November 02 2012 05:38 AM

H.User7152 commented...
Extremely stupid spambot, look at the GETs:

93.166.121.107 - - [04/Oct/2012:01:15:31 +0000] "GET /archives/692/ HTTP/1.0" 403 952 "http://[my server]/archives/692/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
93.166.121.107 - - [04/Oct/2012:01:15:48 +0000] "GET / HTTP/1.0" 403 939 "http://[my server]/archives/692/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
202.171.253.103 - - [04/Oct/2012:01:16:03 +0000] "GET /http:/[my server]/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/ HTTP/1.0" 403 1094 "http://[my server]/archives/692/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
202.171.253.103 - - [04/Oct/2012:01:16:07 +0000] "GET / HTTP/1.0" 403 939 "http://[my server]/archives/692/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
93.166.121.107 - - [04/Oct/2012:01:16:16 +0000] "GET /http:/[my server]/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/ HTTP/1.0" 403 1120 "http://[my server]/archives/692/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
173.48.37.68 - - [04/Oct/2012:01:16:20 +0000] "GET /http:/[my server]/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/archives/692/ HTTP/1.0" 403 1120 "http://[my server]/archives/692/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)"
October 03 2012 11:28 PM

C.S3 commented...
Contact form spammer hit today.
May 06 2012 03:48 PM

C.Hill3 commented...
spammer
September 15 2011 07:32 AM

Page generated on: May 24 2013 08:55:51 AM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | CloudFlare Site Protection | Contact Us

Copyright © 2004–13, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email