Forum Moderators: open

Message Too Old, No Replies

Babya Discoverer

         

keyplyr

7:24 pm on Oct 25, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Babya Discoverer 8.0:
rDNS: none
IP: 77.92.224.***
Host: SILKNET, Georgia
route: 77.92.224.0/19
robots.txt: no


Previous mention: [webmasterworld.com...]

Pfui

9:03 pm on Oct 25, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Was that an isolated hit? Both IP and UA? I ask because it's been years since I've seen that UA in other than a botnet attack (typically courtesy of Russian Federation and/or Chinese Hosts/IPs).

Dijkgraaf

10:38 pm on Oct 25, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I put that one down to being used by a botnet that is looking for guestbooks and comment pages to post to.
It comes from a variety of IP addresses and usually has the referrer set to the page it is requesting (self referring).
The same IP address will use a variety of other Fake UA's (currently I know 112).
Check that IP address in Project Honeypot and they will probably have labeled it a Comment Spammer.

keyplyr

10:40 pm on Oct 25, 2010 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



From yesterday.

77.92.224.110 - - [24/Oct/2010:03:14:35 -0700] "GET www.example.com/++++++++++++++++++++++++++++++++++++++++++++++++++++Result:+\xe8\xf1\xef\xee\xeb\xfc\xe7\xf3\xe5\xec+SOCKS+207.194.87.105:1080;\xed\xe5+\xed\xe0\xf8\xeb\xee\xf1\xfc+\xf4\xee\xf0\xec\xfb+\xe4\xeb\xff+\xee\xf2\xef\xf0\xe0\xe2\xea\xe8; HTTP/1.0" 404 4509 "http://www.example.com/++++++++++++++++++++++++++++++++++++++++++++++++++++Result:+%E8%F1%EF%EE%EB%FC%E7%F3%E5%EC+SOCKS+207.194.87.105:1080;%ED%E5+%ED%E0%F8%EB%EE%F1%FC+%F4%EE%F0%EC%FB+%E4%EB%FF+%EE%F2%EF%F0%E0%E2%EA%E8;" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Babya Discoverer 8.0:"

77.92.224.110 - - [24/Oct/2010:03:14:35 -0700] "GET www.example.com/ HTTP/1.0" 403 10753 "http://www.example.com/" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) Babya Discoverer 8.0:"

(All instances of "example.com" are my own site.)

These are the only hits I've noticed. Others may have come in under the radar.