Forum Moderators: open
The blocks are:
63.146.244.*-**
65.121.208.***-***
65.121.209.**-***
216.206.87.***-***
That's 245 ip addresses in total. 62 in the first range, 61 in each of the other 3 ranges. Every single IP in those ranges was used. Whois indicates that all ranges are owned by Qwest.
Does anyone know who this bot is?
Some sample user agents:
Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
Mozilla/5.0 (Windows; U; Windows NT 5.1; en-uS; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
Opera/8.5 (Macintosh; Intel Mac OS X; U; en)
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; InfoPath.1; .NET CLR 2.0.50727)
[edited by: volatilegx at 1:57 am (utc) on Aug. 7, 2007]
[edit reason] obfuscated ip addresses [/edit]
Deny from 63.144.0.0/13
Deny from 65.118.38.0/24
Deny from 65.121.208.0/23
Deny from 216.206.87.0/24
Based on behaviour, and depending on whose reverse-DNS you believe, it was either a pharm group's content scraper or a gubmint research project.
Jim