Forum Moderators: open

Message Too Old, No Replies

Curios George

         

lucy24

9:13 pm on Aug 3, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



IP: 162.251.134 (probably .128/25 or less)
robots.txt: never heard of it
Method: HEAD
UA: Curios George/0.1 (+https://usecurio.com/bot.html)

Stop me if you've heard this one: The URL in the UA leads directly to a 404. Do not pass Go, do not collect a 200. Front page suggests it's got something to do with social media, but no clue about whether they're being clever or they honestly can't spell.

First seen: 10 June of this year. Requests pages found via a certain directory, sometimes right away, sometimes up to a week later.

[edited by: keyplyr at 10:44 pm (utc) on Aug 3, 2017]
[edit reason] Title of thread edited to enable site search [/edit]

keyplyr

9:27 pm on Aug 3, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Is their host snetconnect.com ?
62.251.128.0 - 162.251.135.255
162.251.128.0/21

These are the IPs currently leased to them at AWS:
54.192.122.143
54.192.122.90
54.192.122.150
54.192.122.166
54.192.122.88
54.192.122.59
54.192.122.79
54.192.122.184

AWS range:
54.192.0.0 - 54.192.255.255
54.192.0.0/16

lucy24

11:40 pm on Aug 3, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Is their host snetconnect.com?

I suppose so. When I looked them up, I was shown a range of 162.251.128.128/25; I didn't investigate any closer. So far, all actual visits have been in the ..14x - ..15x range (i.e. a subset of .128/25)

keyplyr

2:53 am on Aug 4, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Same rang in June? Ever seen this UA from AWS?

lucy24

3:53 am on Aug 4, 2017 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I only noticed them today while checking for something else. Finding several requests on the same day, I then did a UA check of comprehensive logs, which is when I discovered they first showed their faces already in June. (403, so out of sight out of mind.)

162.251.134.146, ..152, ..153, ..156, ..158
i.e. so far contained within 162.251.135.144/28

On the off-chance that they used to know how to spell and then forgot, I've just cross-checked for the string "George" instead. That just led to a bunch of false positives, mostly involving George Chapman.

I may have misread the range though; re-checking, I get 162.251.128.0 - 162.251.135.255 i.e. your /21.

:: wandering off to look up exact significance of Content-Length header, since "Content-Length: 0" seems kinda redundant with a HEAD request ::