Forum Moderators: open

Message Too Old, No Replies

Dirty bot grabs from multiple IPs & UAs

65.102.17.*

         

Justanotherseotype

11:18 am on Sep 14, 2002 (gmt 0)



65.102.17.41 "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98; Win 9x 4.90)"
65.102.17.89 "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
65.102.17.57 "Mozilla/4.0 (compatible; MSIE 5.0; Mac_PowerPC)"
65.102.17.33 "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"
65.102.17.33 "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"
65.102.17.33 "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"
65.102.17.33 "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"
65.102.17.49 "Mozilla/5.0 (compatible; Konqueror/2.1.2; X11)"
65.102.17.57 "Mozilla/4.0 (compatible; MSIE 5.0; Mac_PowerPC)"
65.102.17.89 "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)"
65.102.17.33 "Mozilla/4.0 (compatible; MSIE 5.5; Windows NT 5.0)"
65.102.17.49 "Mozilla/5.0 (compatible; Konqueror/2.1.2; X11)"
65.102.17.49 "Mozilla/5.0 (compatible; Konqueror/2.1.2; X11)"
65.102.17.65 "Mozilla/4.0 (compatible; MSIE 4.0; Windows 95)"
65.102.17.105 "Mozilla/4.0 (compatible; MSIE 5.5; Windows 98)"
and so on...

The bot(s) come in and sucks a site dry within minutes. As you can see it flips UAs and IPs to avoid setting any alarms.

This took a bit of snooping.

whois 65.102.17.89

Web content International WEBCO-DSL-4 (NET-65-102-17-88-1)
65.102.17.88 - 65.102.17.95
-------------------------------------
whois WEBCO-DSL-4

OrgName: Web content International
OrgID: WCI-12

NetRange: 65.102.17.88 - 65.102.17.95
CIDR: 65.102.17.88/29
NetName: WEBCO-DSL-4
NetHandle: NET-65-102-17-88-1
Parent: NET-65-100-0-0-1
NetType: Reassigned
Comment:
RegDate: 2001-12-18
Updated: 2001-12-18

TechHandle: IO-ORG-ARIN
TechName: Internet Operations, U S WEST
TechPhone: +1-800-672-8520
TechEmail: dns-info@uswest.net

# ARIN Whois database, last updated 2002-09-13 19:05
# Enter? for additional hints on searching ARIN's Whois database.
----------------------------------------
whois WCI-12
OrgName: Web content International
OrgID: WCI-12
Address: 3636 NE 63rd Avenue Portland, OR 97213-4404
Country: US
Comment:
RegDate: 2001-09-25
Updated: 2001-09-25
---------------------------------------
google search for "3636 NE 63rd Avenue Portland, OR 97213-4404"
brings up
www.horsebrass.com
-------
whois horsebrass.com

Horse Brass Pub (HORSEBRASS-DOM)
4534 S.E. Belmont Street
Portland, OR 97215

Domain Name: HORSEBRASS.COM

Administrative Contact:
Hagerman, Pat (PH456) pat@REALBEER.COM
Real Beer, Inc.
2325 Third St. Suite 426
San Francisco, CA 94107
415-522-1516 (FAX) 415-522-1535
Technical Contact:
Scott, Jeff (JS15066) jeff.scott@REALBRANDING.COM
Real Branding
2325 Third Street, Ste. 426
San Francisco, CA 94107
US
(415) 522-1516 (415) 522-1535

Record expires on 19-Jun-2003.
Record created on 18-Jun-1996.
Database last updated on 14-Sep-2002 06:49:30 EDT.

Domain servers in listed order:

NS1.REALBRANDING.COM 209.61.183.160
NS2.REALBRANDING.COM 66.216.94.192
NS3.REALBRANDING.COM 209.61.187.153
------------------------------------------------------
REALBRANDING.COM
That's them, those are they guys running the dirty bot.
Took about 5 minutes to dig them out.

jdMorgan

1:15 pm on Sep 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



justan,

Welcome to WebmasterWorld!

Good job! See related post [webmasterworld.com] on WebContent IP addresses.

Jim

mivox

7:48 pm on Sep 14, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



So, do you suppose they own the whole 65.102.17.* block (or did I miss an incredibly obvious piece of information in the first post here)? They're using between .33 to .105 in the list you gave... (just trying to figure out the most efficient way of blocking them)

fiestagirl

10:08 pm on Sep 14, 2002 (gmt 0)

10+ Year Member



From what I can find out they don't own the whole group, in fact some of them are owned by Dow Corning. But here is what I have been able to gather:
65.102.17.32-39
65.102.17.56-63
65.102.17.88-95
65.102.17.104-11
65.102.23.152-159
65.102.23.160-167
65.102.12.224-231

jdMorgan

12:49 am on Sep 15, 2002 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



fiestagirl,

I've also got 65.102.17.40-71

This info is from www.arin.net

Jim

MarieC

9:23 pm on Nov 10, 2002 (gmt 0)

10+ Year Member



Hi! I don't know if this is appropriate or not, and I was a little relucant, but I went to those two web sites.

[horsebrass.com...] Welcome to the world famous Horse Brass Pub. A visit to Portland, Oregon is never complete without a trip to the Brass, a haven for good friends and craft beer in Portland, Oregon -- aka "Beervana" and "Munich on the Willamette". [snipped the rest ... it goes on]

[realbranding.com...] Real Branding has been delivering interactive solutions since 1994 for packaged-goods and Internet clients along with top-line advertising agencies. The company has offices in the U.S., UK and Canada. Real Branding has developed successful, award winning online strategies for over 300 companies and brands including: Corona, Dos Equis, Environmental Sampling, Newcastle Brown Ale, Moosehead, Pete's Brewing Company, Samuel Adams, Sic-Em Advertising and Smirnoff Ice.

My first question, I guess, is, what is a company like this doing in the business of crawling unsuspecting web sites and sucking up so much bandwidth? Or am I missing something?

My next question, is, would it be unwise to write to the company and ask them what the deal is and/or asking them to cease and desist?

Thanks.

GMKS Webmaster

8:59 am on Dec 2, 2002 (gmt 0)



I fear that you guys may have jumped the gun a bit. The
www.horsebrass.com website only came up on Google because
it happens to share a lot of the same address elements
with the "Web Content International" address. If you do
the search on the full address yourself -- WITH quotes --
you won't get any results at all.

Instead, try a search on the shortened form:
"3636 NE 63rd Ave". This turns up a non-profit organization
called CITE. See my related post on the other thread:

[webmasterworld.com...]

Unfortunately, THEY may not be the culprits either, but
if they're NOT, then they may be able to put a stop to the
activity by notifying US West that the mailing address for
"Web Content International" is fraudulent and damaging
their reputation.

BTW, it took me quite a bit longer than "five minutes" to
sort all this out. It's worth the time to get the facts
right before jumping to conclusions and hurling accusations
at uninvolved third parties. The Devil's in the details.