Forum Moderators: open

Message Too Old, No Replies

Japanese AV bot?

         

Megaclinium

7:12 pm on Nov 9, 2008 (gmt 0)

10+ Year Member



starting 7/7/2008, I noticed that whenever certain IPs hit my site, who appear to be real users.

Then I get hits from:
150.70.84.xx about 45 seconds later to some or all of the pages they visit.
Definitely a bot as collects just text from the page that would show media files for real users.
The real user#s change but the above IP is always the same.

it resolves under apnic.net to:
role: Japan Network Information Center
address: Kokusai-Kougyou-Kanda Bldg 6F, 2-3-4 Uchi-Kanda
address: Chiyoda-ku, Tokyo 101-0047, Japan
country: JP
phone: +81-3-5297-2311
fax-no: +81-3-5297-2312
e-mail: hostmaster@nic.ad.jp

and has a UA of:
"Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)"

Any idea what this is?
maybe a cloaked trend micro scanner?

Samizdata

3:57 am on Nov 10, 2008 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



trend micro scanner?

I have that range listed as Trend Micro.

Lots of odd things seem to come from Japan Network Information Center.

...

Megaclinium

9:02 pm on Nov 10, 2008 (gmt 0)

10+ Year Member



glad is not an email harvester

I doubted that many PCs would be infected such that an additional scan would be performed by a different PC with the same address. If they were infected I suppose they would just quietly send the page when they browsed to a dift address without showing up in my logs.

Thanks!