Forum Moderators: open

Message Too Old, No Replies

Comment spammer?

         

CyberShadow

11:21 am on Apr 13, 2011 (gmt 0)

10+ Year Member



Didn't find anything on the web about this guy, maybe someone will find this useful or interesting. I like it how it switches IPs twice after hitting a 401. Not too smart about large binary files, either.

User-agent is "Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.5) Gecko/2008120122 Firefox/3.0.5" (trimmed from below log for readability).

50.17.110.161 - - [13/Apr/2011:08:03:29 +0200] "GET /33/worms_bug_video HTTP/1.1" 200 8524 "-"
50.17.110.161 - - [13/Apr/2011:08:03:29 +0200] "POST /?action=comment&movie=33 HTTP/1.1" 200 3829 "http://wormtube.worms2d.info/33/worms_bug_video"
50.17.110.161 - - [13/Apr/2011:08:03:30 +0200] "GET /?action=comment&movie=33 HTTP/1.1" 200 3829 "-"
50.17.110.161 - - [13/Apr/2011:08:03:31 +0200] "GET /33/worms_bug_video HTTP/1.1" 200 8524 "-"
50.17.110.161 - - [13/Apr/2011:08:03:31 +0200] "GET /33/ HTTP/1.1" 200 8524 "-"
50.17.110.161 - - [13/Apr/2011:08:03:32 +0200] "GET / HTTP/1.1" 200 12262 "-"
50.17.110.161 - - [13/Apr/2011:08:03:32 +0200] "GET /browse/category/compilation HTTP/1.1" 200 52431 "-"
50.17.110.161 - - [13/Apr/2011:08:03:33 +0200] "GET /browse/category/solo HTTP/1.1" 200 27007 "-"
50.17.110.161 - - [13/Apr/2011:08:03:33 +0200] "GET /browse/category/clan HTTP/1.1" 200 30089 "-"
50.17.110.161 - - [13/Apr/2011:08:03:33 +0200] "GET /browse/category/mini HTTP/1.1" 200 30503 "-"
50.17.110.161 - - [13/Apr/2011:08:03:37 +0200] "GET /rss.php HTTP/1.1" 200 10343 "-"
50.17.110.161 - - [13/Apr/2011:08:03:37 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
193.146.135.126 - - [13/Apr/2011:08:03:38 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
88.149.179.124 - - [13/Apr/2011:08:03:43 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
88.149.179.124 - - [13/Apr/2011:08:03:44 +0200] "GET /browse/author/Lalo HTTP/1.1" 200 5551 "-"
88.149.179.124 - - [13/Apr/2011:08:03:44 +0200] "GET /browse/author/Ajvu HTTP/1.1" 200 5551 "-"
88.149.179.124 - - [13/Apr/2011:08:03:45 +0200] "GET /vids/Worms_Bug_video.wmv HTTP/1.1" 200 69030987 "-"

87.208.114.147 - - [13/Apr/2011:08:12:33 +0200] "GET /7/the_sexy_lords HTTP/1.1" 200 7848 "-"
87.208.114.147 - - [13/Apr/2011:08:12:34 +0200] "POST /?action=comment&movie=7 HTTP/1.1" 200 3829 "http://wormtube.worms2d.info/7/the_sexy_lords"
87.208.114.147 - - [13/Apr/2011:08:12:35 +0200] "GET /?action=comment&movie=7 HTTP/1.1" 200 3829 "-"
87.208.114.147 - - [13/Apr/2011:08:12:36 +0200] "GET /7/the_sexy_lords HTTP/1.1" 200 7848 "-"
87.208.114.147 - - [13/Apr/2011:08:12:37 +0200] "GET /7/ HTTP/1.1" 200 7848 "-"
87.208.114.147 - - [13/Apr/2011:08:12:38 +0200] "GET / HTTP/1.1" 200 12278 "-"
87.208.114.147 - - [13/Apr/2011:08:12:39 +0200] "GET /browse/category/compilation HTTP/1.1" 200 52431 "-"
87.208.114.147 - - [13/Apr/2011:08:12:41 +0200] "GET /browse/category/solo HTTP/1.1" 200 27007 "-"
87.208.114.147 - - [13/Apr/2011:08:12:42 +0200] "GET /browse/category/clan HTTP/1.1" 200 30089 "-"
87.208.114.147 - - [13/Apr/2011:08:12:44 +0200] "GET /browse/category/mini HTTP/1.1" 200 30503 "-"
87.208.114.147 - - [13/Apr/2011:08:12:49 +0200] "GET /rss.php HTTP/1.1" 200 10343 "-"
87.208.114.147 - - [13/Apr/2011:08:12:50 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
195.229.241.177 - - [13/Apr/2011:08:12:51 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
57.90.36.29 - - [13/Apr/2011:08:12:52 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
57.90.36.29 - - [13/Apr/2011:08:12:52 +0200] "GET /browse/author/fr4nk HTTP/1.1" 200 8008 "-"

84.51.23.158 - - [13/Apr/2011:09:14:10 +0200] "GET /68/the_tag_effect_trailer HTTP/1.1" 200 7747 "-"
84.51.23.158 - - [13/Apr/2011:09:14:11 +0200] "POST /?action=comment&movie=68 HTTP/1.1" 200 3829 "http://wormtube.worms2d.info/68/the_tag_effect_trailer"
84.51.23.158 - - [13/Apr/2011:09:14:14 +0200] "GET /?action=comment&movie=68 HTTP/1.1" 200 3829 "-"
84.51.23.158 - - [13/Apr/2011:09:14:15 +0200] "GET /68/the_tag_effect_trailer HTTP/1.1" 200 7747 "-"
72.53.176.40 - - [13/Apr/2011:09:14:24 +0200] "GET /10 HTTP/1.0" 200 8562 "-"
72.53.176.40 - - [13/Apr/2011:09:14:25 +0200] "POST /?action=comment&movie=10 HTTP/1.0" 200 3829 "http://wormtube.worms2d.info/10"
72.53.176.40 - - [13/Apr/2011:09:14:25 +0200] "GET /?action=comment&movie=10 HTTP/1.0" 200 3829 "-"
72.53.176.40 - - [13/Apr/2011:09:14:25 +0200] "GET /10 HTTP/1.0" 200 8562 "-"
72.53.176.40 - - [13/Apr/2011:09:14:26 +0200] "GET / HTTP/1.0" 200 12179 "-"
72.53.176.40 - - [13/Apr/2011:09:14:27 +0200] "GET /browse/category/compilation HTTP/1.0" 200 52431 "-"
72.53.176.40 - - [13/Apr/2011:09:14:28 +0200] "GET /browse/category/solo HTTP/1.0" 200 27007 "-"
72.53.176.40 - - [13/Apr/2011:09:14:28 +0200] "GET /browse/category/clan HTTP/1.0" 200 30089 "-"
72.53.176.40 - - [13/Apr/2011:09:14:29 +0200] "GET /browse/category/mini HTTP/1.0" 200 30503 "-"
72.53.176.40 - - [13/Apr/2011:09:14:32 +0200] "GET /rss.php HTTP/1.0" 200 10343 "-"
72.53.176.40 - - [13/Apr/2011:09:14:33 +0200] "GET /admin/ HTTP/1.0" 401 472 "-"
67.216.175.132 - - [13/Apr/2011:09:14:33 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
84.51.23.158 - - [13/Apr/2011:09:14:40 +0200] "GET /68/ HTTP/1.1" 200 7747 "-"
175.137.3.100 - - [13/Apr/2011:09:14:44 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
175.137.3.100 - - [13/Apr/2011:09:14:46 +0200] "GET /10/walnut HTTP/1.1" 200 8562 "-"
175.137.3.100 - - [13/Apr/2011:09:14:47 +0200] "GET /browse/author/Master+of+Disaster HTTP/1.1" 200 7070 "-"
175.137.3.100 - - [13/Apr/2011:09:14:49 +0200] "GET /featured HTTP/1.1" 200 26021 "-"

61.139.104.207 - - [13/Apr/2011:09:15:44 +0200] "GET / HTTP/1.1" 200 12381 "-"
61.139.104.207 - - [13/Apr/2011:09:15:48 +0200] "GET /browse/category/compilation HTTP/1.1" 200 52431 "-"
61.139.104.207 - - [13/Apr/2011:09:15:53 +0200] "GET /browse/category/solo HTTP/1.1" 200 27007 "-"
61.139.104.207 - - [13/Apr/2011:09:15:56 +0200] "GET /browse/category/clan HTTP/1.1" 200 30089 "-"
61.139.104.207 - - [13/Apr/2011:09:15:58 +0200] "GET /browse/category/mini HTTP/1.1" 200 30503 "-"
61.139.104.207 - - [13/Apr/2011:09:16:08 +0200] "GET /rss.php HTTP/1.1" 200 10343 "-"
61.139.104.207 - - [13/Apr/2011:09:16:10 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
188.220.32.40 - - [13/Apr/2011:09:16:10 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
62.20.250.41 - - [13/Apr/2011:09:16:11 +0200] "GET /admin/ HTTP/1.0" 401 472 "-"
62.20.250.41 - - [13/Apr/2011:09:16:11 +0200] "GET /browse/author/Knight HTTP/1.0" 200 5649 "-"
62.20.250.41 - - [13/Apr/2011:09:16:12 +0200] "GET /vids/The_TaG_Effect_Trailer.mp4 HTTP/1.0" 200 34712986 "-"

24.123.189.2 - - [13/Apr/2011:11:47:45 +0200] "GET /66/in_the_matrix HTTP/1.1" 200 9719 "-"
24.123.189.2 - - [13/Apr/2011:11:47:46 +0200] "POST /?action=comment&movie=66 HTTP/1.1" 200 3829 "http://wormtube.worms2d.info/66/in_the_matrix"
24.123.189.2 - - [13/Apr/2011:11:47:46 +0200] "GET /?action=comment&movie=66 HTTP/1.1" 200 3829 "-"
24.123.189.2 - - [13/Apr/2011:11:47:47 +0200] "GET /66/in_the_matrix HTTP/1.1" 200 9719 "-"
24.123.189.2 - - [13/Apr/2011:11:47:47 +0200] "GET /66/ HTTP/1.1" 200 9719 "-"
24.123.189.2 - - [13/Apr/2011:11:47:49 +0200] "GET / HTTP/1.1" 200 12272 "-"
24.123.189.2 - - [13/Apr/2011:11:47:49 +0200] "GET /browse/category/compilation HTTP/1.1" 200 52431 "-"
24.123.189.2 - - [13/Apr/2011:11:47:50 +0200] "GET /browse/category/solo HTTP/1.1" 200 27007 "-"
24.123.189.2 - - [13/Apr/2011:11:47:51 +0200] "GET /browse/category/clan HTTP/1.1" 200 30089 "-"
24.123.189.2 - - [13/Apr/2011:11:47:52 +0200] "GET /browse/category/mini HTTP/1.1" 200 30503 "-"
24.123.189.2 - - [13/Apr/2011:11:47:55 +0200] "GET /rss.php HTTP/1.1" 200 10343 "-"
24.123.189.2 - - [13/Apr/2011:11:47:55 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
67.192.253.140 - - [13/Apr/2011:11:47:59 +0200] "GET /admin/ HTTP/1.1" 401 472 "-"
88.8.26.63 - - [13/Apr/2011:11:48:02 +0200] "GET /admin/ HTTP/1.0" 401 472 "-"
88.8.26.63 - - [13/Apr/2011:11:48:02 +0200] "GET /browse/author/OutofOrder HTTP/1.0" 200 16173 "-"
88.8.26.63 - - [13/Apr/2011:11:48:04 +0200] "GET /vids/In%20the%20Matrix.mp4 HTTP/1.0" 200 84240181 "-"

wilderness

1:44 am on Apr 15, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



50.17.110.161

Pfui been building this long thread [webmasterworld.com] just for you

CyberShadow

1:51 am on Apr 15, 2011 (gmt 0)

10+ Year Member



50.17.110.161 is just one of many IPs this bot used. It's probably just an open proxy or compromised machine. The rest aren't from Amazon.

wilderness

2:28 am on Apr 15, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



That the Amazon range if the first one you listed, and if in fact it was the initial-point-of-entry, that's enough to to warrant reaction/action.

dstiles

7:54 pm on Apr 15, 2011 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



12/13th April I got a LOT of bad hits from a botnet. In my case I detected and blocked each as it arrived so I only had one hit per IP. It could be this is the same source.