Given the array of its subdomains and IPs using the same two UAs, thenewpush.com appears routinely keen on checking others' sites...
RECENTLY:
unsecured.thenewpush.com
libwww-perl/5.812
libwww-perl/5.805
host-72-18-152-8.thenewpush.com
Mozilla/4.0
Same two UAs: [
projecthoneypot.org...]
PREVIOUSLY:
mail.thenewpush.com
Mozilla/4.0
mx.thenewpush.com
libwww-perl/5.805
host-72-18-150-13.thenewpush.com
libwww-perl/5.805
host-72-18-150-14.thenewpush.com
libwww-perl/5.805
72.18.143.158
libwww-perl/5.805
Even when IP only, same two UAs: [
projecthoneypot.org...]
NOTES:
NO robots.txt ever. Files requested always ONLY favicon.ico and bot traps (directly; oddly). For your convenience:
Range: 72.18.128.0 through 72.18.159.255
CIDR: 72.18.128.0/19