IP Address Inspector

94.142.128.140

The Project Honey Pot system has detected behavior from the IP address consistent with that of a mail server, dictionary attacker and comment spammer. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | Spamcop | SenderBase | Google Groups | Google

Geographic Location Latvia
Spider First Seen approximately 2 years, 10 months, 4 weeks ago
Spider Last Seen within 1 week
Spider Sightings 4,048 visit(s)
User-Agents seen with 30 user-agent(s)

First Received From approximately 2 years, 11 months, 4 weeks ago
Last Received From within 2 years, 11 months, 4 weeks
Number Received 44 email(s) sent from this IP

First Post On approximately 2 years, 10 months, 4 weeks ago
Last Post On within 1 week
Form Posts 1,514 web post submission(s) sent from this IP

Dictionary Attacks 5 email(s) sent from this IP
First Received From approximately 2 years, 11 months, 4 weeks ago
Last Received From within 2 years, 11 months, 4 weeks

Associated Harvesters
70.87.196.242 | H
208.66.195.9 | H
216.40.220.18 | H
71.162.176.37 | HS
74.53.249.34 | HW
87.118.98.62 | H
74.86.209.74 | H
70.85.113.242 | H
80.78.18.11 | HS
216.40.222.98 | H
67.86.138.59 | HC
216.40.222.50 | H
75.125.47.162 | HSDW
216.40.220.34 | H
62.12.37.3 | HS
123.110.20.199 | HS
74.86.14.10 | H
208.66.195.2 | H
216.40.222.82 | HSD
208.101.44.3 | H
65.93.203.49 | H
208.66.195.8 | H
208.53.147.89 | H
208.66.195.6 | H
204.15.164.206 | H
208.66.195.21 | H
208.66.195.5 | H
IPs In The Neighborhood
94.142.128.0
94.142.128.2
94.142.128.4
94.142.128.5
94.142.128.10
94.142.128.12
94.142.128.13
94.142.128.41
94.142.128.43
94.142.128.45
94.142.128.59 | C
94.142.128.69 | C
94.142.128.82
94.142.128.91 | C
94.142.128.100
94.142.128.101
94.142.128.102
94.142.128.106
94.142.128.115 | C
94.142.128.151 | C
94.142.128.152 | C
94.142.128.153 | C
94.142.128.154 | C
94.142.128.156 | C
94.142.128.157 | C
94.142.128.200
94.142.128.201 | C
94.142.128.207
94.142.128.220 | C
94.142.128.221 | C
94.142.128.222 | C
94.142.128.223 | C
94.142.128.224 | C
94.142.128.225 | C
94.142.128.231 | C
94.142.129.21
94.142.129.31 | C
94.142.129.32 | C
94.142.129.33 | C
94.142.129.34 | C
94.142.129.35
94.142.129.36 | C
94.142.129.47
94.142.129.51
94.142.129.53
94.142.129.62
94.142.129.82
94.142.129.98 | C
94.142.129.99
Sample Spam URLs & Keywords Posted From 94.142.128.140
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: apetinol (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ????????? ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ????????(495)925-51-40 ??????? ???????? ???????
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: apetinol ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????????????? ????? ???????????? ???????????? ?? ????????????(495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ????????(495)925-51-40 ??????? ???????? ???????
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: apetinol ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ????????? ???????? ?????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ?????????. ?????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: apetinol ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ????????? ???????? ?????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? ?????? ? ??????(495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? (495)925-51-40
94.142.128.140's User Agent Strings
Mozilla/0.6 Beta (Windows)
Mozilla/0.91 Beta (Windows)
Mozilla/1.22 (compatible; MSIE 2.0d; Windows NT)
Mozilla/1.22 (compatible; MSIE 2.0; Windows 95)
Mozilla/2.0 (compatible; MSIE 3.02; Windows CE; 240x320)
Mozilla/3.0 (compatible; WebCapture 2.0; Auto; Windows)
Mozilla/3.0 (x86 [en] Windows NT 5.1; Sun)
Mozilla/4.0 (compatible; MSIE 4.01; Digital AlphaServer 1000A 4/233; Windows NT; Powered By 64-Bit Alpha Processor)
Mozilla/4.0 (compatible; MSIE 5.01; Windows 95; MSIECrawler)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 2000) Opera 6.0 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows 3.1)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; BCD2000)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0; .NET CLR 1.0.2914)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)
Mozilla/4.0 (compatible; MSIE 6.0; America Online Browser 1.1; rev1.2; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1)
Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 4.0) Opera 7.0 [en]
Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]
Mozilla/4.0 (compatible; MSIE 6.0; Update a; AOL 6.0; Windows 98)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90; Creative)
Mozilla/4.0 (compatible; MSIE 6.0; Windows ME) Opera 7.11 [en]
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Example Messages Sent From 94.142.128.140
From:
Subject: Сeриалы нa DVD
From:
Subject: Семейка Аддамс (The Addams Fa
From:
Subject: Acrobat 9 Extended
From:
Subject: Adobe Acrobat 9 Extended
From:
Subject: Полиция Майами: Отдел нравов
From:
Subject: Полиция Майами: Отдел нравов
From:
Subject: Полиция Майами: Отдел нравов
From:
Subject: Побег (Prison break) - 4 сезо
From:
Subject: Побег (Prison break) - 4 сезо
From:
Subject: Беверли-Хиллз, 90210 (Beverly
From:
Subject: Беверли-Хиллз, 90210 (Beverly
From:
Subject: Беверли-Хиллз, 90210 (Beverly
Example User Names Used By 94.142.128.140
User-name: director
User-name: ihtgt
User-name: petgord34truew
User-name: taivogelzang
User-name: yuh
H.User6441 commented...
Catch with UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1) Netscape/8.0.4
December 11 2010 06:07 PM

B.Smith24 commented...
94.142.128.140 - March 17, 2010, 12:49:34 pm GMT - Pulled up every board on the forums in an effort to find one that wasn't R/O at the Topic or Subject line level. Boards can only be accessed as far as the topic if not registered and logged in.
March 17 2010 06:56 AM

H.User2159 commented...
Name:

ValeryLep
Email: med.v.alery6@gmail.com
ICQ UIN: 325122
Date Registered: November 21, 2009
Last Activity: December 28, 2009

Bot registered at my VBulletin forum. Posted on message and generated mass Private Messages to some (not all) members as follows: "About your message...Profi?
Hi [screen names deleted].D o you have XRumer 5.0.12 ?My friend was recommended this well-known tool for advertisement my website and money earning.Can you share it? PLEASE!Or maybe download link.... Thank you. Kiss you...:-* ...))"
December 28 2009 10:54 AM

R.MEOW commented...
Name: Lyagushkka
IP: 94.142.128.140
Hostname: h-128-140.cssgroup.lv
Email: lyagushkka@gmail.com
Date Registered: September 23, 2009 at 10:20:26 PM

This bot got past our SMF Forum registration defenses, but never got approved by our admins to post topics. It has been banned on our website from the dns level... *.cssgroup.lv

Actions taken by spammer to bypass registration:

Sep 23, 2009 10:20:26 PM CDT /forum/index.php?action=register2
Sep 23, 2009 10:20:13 PM CDT /forum/index.php?action=verificationcode;rand=3522636dda16214689a31b920f063a07
Sep 23, 2009 10:20:11 PM CDT /forum/index.php?action=register

It appears that it creates its own verification code... It has attempted several other times and failed, but this time it was successful...
September 24 2009 03:55 AM

A.E4 commented...
This bot spammed once again under a new name and email address.

Date Registered: September 03, 2009, 08:39:28 AM EDT
Date of first post: September 05, 2009, 04:15:46 PM EDT
Lyagushkka
lyagushkka@gmail.com
94.142.128.140

Subject: Who knows where to download XRumer 5.0 Palladium?

Post:

Who knows where to download XRumer 5.0 Palladium?
Help, please. All recommend this program to effectively advertise on the Internet, this is the best program!

Other info in the member's profile is an ICQ # which is 325122
September 05 2009 08:39 PM

A.E4 commented...
Posted as a different name on another forum (I am on a few) where I noticed something I didn't know previously about this bot. This one takes posts from other people and posts them elsewhere. This is why many times this bot seems to sound just like any other posting member. I realized this because one of the posts were a direct post of MINE! This bot posted 11 times under the name of MagicOPromotion before I realized it was a bot! Then one of the posts it posted a link to http://www.botmasternet.com/

94.142.128.140
MagicOPromotion
magicpromotionmm@gmail.com

Date of post: 06-04-2009, 12:01 PM

Post which link was in:

Jody. The thought that also came to my mind as I read your post was this: If your Dad is unable to garden this summer, and I pray he is, why dont you get him or make one of those up-side down tomato plants--needs a something quite sturdy to hang on. I believe also you can purchase or make one of those little pyramid type mini gardens, where you plant things on each level. If he cant get out to the garden, bring a smaller version TO him.

God bless you both and I pray he gets better soon.
__________________
XRumer 5.0 Palladium: best promotion software

(that last part is the bot's signature but no link there. The link was in the post in the word purchase
July 04 2009 01:03 AM

A.E4 commented...
Posted as CocoChanels onJune 27th at 09:51:37 PM and posted a message titled:

Who knows where to download XRumer 5.0 Palladium?

and the message had no links but said:

Who knows where to download XRumer 5.0 Palladium?
Help, please. All recommend this program to effectively advertise on the Internet, this is the best program!
June 27 2009 10:34 PM

A.E4 commented...
This time posted as CocoChanels on Fri Jun 26, 2009 2:48 pm so STILL is causing trouble spamming forums..
June 26 2009 10:53 PM

A.Ole commented...
CocoChanels cocochanelske@gmail.com 94.142.128.140
June 25 2009 08:39 PM

A.Bolchis commented...
Comment Spammer, Ignores Robots
June 22 2009 06:10 AM

A.E4 commented...
advertised XRumer as if it was a great new thing he found .. unwanted so I deleted his post. When I realized on the net it said his IP was trouble I banned his IP.
June 19 2009 01:42 PM

R.G10 commented...
User linked in his forum profile to a Google search for XRumer, forum spamming software. According to profile, geographic location is England. Calls himself MagicOPromotion. Hardly subtle.
May 24 2009 10:51 AM

Page generated on: February 10 2012 03:59:52 PM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | CloudFlare Site Protection | Contact Us

Copyright © 2004–12, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email