IP Address Inspector

94.142.128.140

The Project Honey Pot system has detected behavior from the IP address consistent with that of a mail server, dictionary attacker and comment spammer. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment.

Lookup IP In: Domain Tools | SpamHaus | OpenRBL | Spamcop | SenderBase | Google Groups | Google

Geographic Location Latvia
Spider First Seen approximately 8 months, 2 weeks ago
Spider Last Seen within 1 week
Spider Sightings 1,401 visit(s)
User-Agents seen with 30 user-agent(s)

First Received From approximately 9 months, 1 week ago
Last Received From within 9 months, 1 week
Number Received 44 email(s) sent from this IP

First Post On approximately 8 months, 2 weeks ago
Last Post On within 1 week
Form Posts 542 web post submission(s) sent from this IP

Dictionary Attacks 5 email(s) sent from this IP
First Received From approximately 9 months, 1 week ago
Last Received From within 9 months, 1 week

Associated Harvesters
208.66.195.9 | H
70.87.196.242 | H
208.66.195.5 | H
208.66.195.21 | H
204.15.164.206 | H
208.66.195.6 | H
208.53.147.89 | H
208.66.195.8 | H
65.93.203.49 | H
208.101.44.3 | H
216.40.222.82 | H
208.66.195.2 | H
74.86.14.10 | H
123.110.20.199 | HS
62.12.37.3 | HS
216.40.220.34 | H
75.125.47.162 | H
216.40.222.50 | H
67.86.138.59 | HC
216.40.222.98 | H
80.78.18.11 | HS
70.85.113.242 | H
74.86.209.74 | H
87.118.98.62 | H
74.53.249.34 | H
71.162.176.37 | HS
216.40.220.18 | H
IPs In The Neighborhood
94.142.128.0
94.142.128.2
94.142.128.13
94.142.128.59 | C
94.142.128.69 | C
94.142.128.91 | C
94.142.128.100
94.142.128.115 | C
94.142.128.151 | C
94.142.128.152 | C
94.142.128.153 | C
94.142.128.154 | C
94.142.128.156 | C
94.142.128.157 | C
94.142.128.200
94.142.128.201 | C
94.142.128.220 | C
94.142.128.221 | C
94.142.128.222 | C
94.142.128.223 | C
94.142.128.224 | C
94.142.128.225 | C
94.142.128.231 | C
94.142.129.21
94.142.129.31 | C
94.142.129.32 | C
94.142.129.33 | C
94.142.129.34 | C
94.142.129.35
94.142.129.36 | C
94.142.129.47
94.142.129.53
94.142.129.62
94.142.129.82
94.142.129.98 | C
Sample Spam URLs & Keywords Posted From 94.142.128.140
Domain: tdz.ru
URL: http://tdz.ru/
Keywords: ??????? ?????????
Domain: tdz.ru
URL: http://tdz.ru/
Keywords: ??????? ?????????
Domain: tdz.ru
URL: http://tdz.ru/
Keywords: ?????????
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ????????? ???????? ?????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? ??? ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? (495)925-51-40
Domain: www.apetinol-stop.ru
URL: http://www.apetinol-stop.ru
Keywords: ???????? ????????? ????????(495)925-51-40
Domain: www.apetinol-stop.ru
URL: http://www.apetinol-stop.ru
Keywords: ???????? . ????????? -??????????? ?????? ? ???????? ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ????????(495)925-51-40 ??????? ???????? ???????
Domain: www.apetinol-stop.ru
URL: http://www.apetinol-stop.ru
Keywords: ???????? ????????? - ????? ?????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? - ????? ?????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: appetinol ???????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: apetinol ????????? (495)925-51-40
Domain: www.apetinol-stop.r
URL: http://www.apetinol-stop.r
Keywords: ???????? ?????????. ?????? (495)925-51-40
94.142.128.140's User Agent Strings
Mozilla/0.6 Beta (Windows)
Mozilla/0.91 Beta (Windows)
Mozilla/1.22 (compatible; MSIE 2.0d; Windows NT)
Mozilla/1.22 (compatible; MSIE 2.0; Windows 95)
Mozilla/2.0 (compatible; MSIE 3.02; Windows CE; 240x320)
Mozilla/3.0 (compatible; WebCapture 2.0; Auto; Windows)
Mozilla/3.0 (x86 [en] Windows NT 5.1; Sun)
Mozilla/4.0 (compatible; MSIE 4.01; Digital AlphaServer 1000A 4/233; Windows NT; Powered By 64-Bit Alpha Processor)
Mozilla/4.0 (compatible; MSIE 5.01; Windows 95; MSIECrawler)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 2000) Opera 6.0 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows 3.1)
Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Mozilla/4.0 (compatible; MSIE 5.0; Windows NT; DigExt)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; BCD2000)
Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 4.0; .NET CLR 1.0.2914)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0; T312461)
Mozilla/4.0 (compatible; MSIE 6.0; America Online Browser 1.1; rev1.2; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1)
Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 4.0) Opera 7.0 [en]
Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 5.0) Opera 7.02 Bork-edition [en]
Mozilla/4.0 (compatible; MSIE 6.0; Update a; AOL 6.0; Windows 98)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90)
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; Win 9x 4.90; Creative)
Mozilla/4.0 (compatible; MSIE 6.0; Windows ME) Opera 7.11 [en]
Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Example Messages Sent From 94.142.128.140
From:
Subject: Adobe Acrobat 9 Pro
From:
Subject: Сeриалы нa DVD
From:
Subject: Семейка Аддамс (The Addams Fa
From:
Subject: Adobe Acrobat 9 Extended
From:
Subject: Полиция Майами: Отдел нравов
From:
Subject: Полиция Майами: Отдел нравов
From:
Subject: Полиция Майами: Отдел нравов
From:
Subject: Побег (Prison break) - 4 сезо
From:
Subject: Побег (Prison break) - 4 сезо
From:
Subject: Беверли-Хиллз, 90210 (Beverly
From:
Subject: Беверли-Хиллз, 90210 (Beverly
From:
Subject: Беверли-Хиллз, 90210 (Beverly
Example User Names Used By 94.142.128.140
User-name: director
User-name: ihtgt
User-name: petgord34truew
User-name: taivogelzang
User-name: yuh
R.MEOW commented...
Name: Lyagushkka
IP: 94.142.128.140
Hostname: h-128-140.cssgroup.lv
Email: lyagushkka@gmail.com
Date Registered: September 23, 2009 at 10:20:26 PM

This bot got past our SMF Forum registration defenses, but never got approved by our admins to post topics. It has been banned on our website from the dns level... *.cssgroup.lv

Actions taken by spammer to bypass registration:

Sep 23, 2009 10:20:26 PM CDT /forum/index.php?action=register2
Sep 23, 2009 10:20:13 PM CDT /forum/index.php?action=verificationcode;rand=3522636dda16214689a31b920f063a07
Sep 23, 2009 10:20:11 PM CDT /forum/index.php?action=register

It appears that it creates its own verification code... It has attempted several other times and failed, but this time it was successful...
September 24 2009 06:55 AM

A.E4 commented...
This bot spammed once again under a new name and email address.

Date Registered: September 03, 2009, 08:39:28 AM EDT
Date of first post: September 05, 2009, 04:15:46 PM EDT
Lyagushkka
lyagushkka@gmail.com
94.142.128.140

Subject: Who knows where to download XRumer 5.0 Palladium?

Post:

Who knows where to download XRumer 5.0 Palladium?
Help, please. All recommend this program to effectively advertise on the Internet, this is the best program!

Other info in the member's profile is an ICQ # which is 325122
September 05 2009 11:39 PM

A.E4 commented...
Posted as a different name on another forum (I am on a few) where I noticed something I didn't know previously about this bot. This one takes posts from other people and posts them elsewhere. This is why many times this bot seems to sound just like any other posting member. I realized this because one of the posts were a direct post of MINE! This bot posted 11 times under the name of MagicOPromotion before I realized it was a bot! Then one of the posts it posted a link to http://www.botmasternet.com/

94.142.128.140
MagicOPromotion
magicpromotionmm@gmail.com

Date of post: 06-04-2009, 12:01 PM

Post which link was in:

Jody. The thought that also came to my mind as I read your post was this: If your Dad is unable to garden this summer, and I pray he is, why dont you get him or make one of those up-side down tomato plants--needs a something quite sturdy to hang on. I believe also you can purchase or make one of those little pyramid type mini gardens, where you plant things on each level. If he cant get out to the garden, bring a smaller version TO him.

God bless you both and I pray he gets better soon.
__________________
XRumer 5.0 Palladium: best promotion software

(that last part is the bot's signature but no link there. The link was in the post in the word purchase
July 04 2009 04:03 AM

A.E4 commented...
Posted as CocoChanels onJune 27th at 09:51:37 PM and posted a message titled:

Who knows where to download XRumer 5.0 Palladium?

and the message had no links but said:

Who knows where to download XRumer 5.0 Palladium?
Help, please. All recommend this program to effectively advertise on the Internet, this is the best program!
June 28 2009 01:34 AM

A.E4 commented...
This time posted as CocoChanels on Fri Jun 26, 2009 2:48 pm so STILL is causing trouble spamming forums..
June 27 2009 01:53 AM

A.Ole commented...
CocoChanels cocochanelske@gmail.com 94.142.128.140
June 25 2009 11:39 PM

A.Bolchis commented...
Comment Spammer, Ignores Robots
June 22 2009 09:10 AM

A.E4 commented...
advertised XRumer as if it was a great new thing he found .. unwanted so I deleted his post. When I realized on the net it said his IP was trouble I banned his IP.
June 19 2009 04:42 PM

R.G10 commented...
User linked in his forum profile to a Google search for XRumer, forum spamming software. According to profile, geographic location is England. Calls himself MagicOPromotion. Hardly subtle.
May 24 2009 01:51 PM

Page generated on: November 22 2009 07:02:24 PM
do not follow this link

Privacy Policy | Terms of Use | About Project Honey Pot | FAQ | Contact Us

Copyright © 2004–09, Unspam Technologies, Inc. All rights reserved.

Advertisements displayed on this page are not necessarily endorsed by Project Honey Pot

contact | wiki | email