Comment spammers chewing blogger bandwidth like crazy

Date: Sat, 13 Jan 2007 18:58:02 +0000 (GMT)
From: "Chris L. Morrow" <christopher.morrow@verizonbusiness.com>
Subject: Re: Comment spammers chewing blogger bandwidth like crazy
To: Thomas Leavitt <thomas@thomasleavitt.org>
Cc: nanog <nanog@merit.edu>

> Why has 195.225.177.46, an IP in Ukraine, been eating a tremendous
> amount of bandwidth? What are they doing?

this isn't in the ukraine, it's in NYC behind ISPrime. Phil is fairly
hhelpful, you might ask them to 'figure out what the heck is going on'
with that ip :slight_smile:

-Chris
(unless the ukraine got a whole lot closer to IAD than I thought:
64 bytes from 195.225.177.46: icmp_seq=1 ttl=55 time=13.1 ms
64 bytes from 195.225.177.46: icmp_seq=2 ttl=55 time=24.5 ms

Um-m-m-m...

% Information related to '195.225.176.0 - 195.225.179.255'

inetnum: 195.225.176.0 - 195.225.179.255
netname: NETCATHOST
descr: NetcatHosting
country: UA
admin-c: VS1142-RIPE
tech-c: VS1142-RIPE
status: ASSIGNED PI
mnt-by: RIPE-NCC-HM-PI-MNT
mnt-lower: RIPE-NCC-HM-PI-MNT
mnt-by: NETCATHOST-MNT
mnt-routes: NETCATHOST-MNT
notify: vs@netcathost.com
changed: hostmaster@ripe.net 20040304
source: RIPE
remarks: ***************************************
remarks: * Abuse contacts: abuse@netcathost.com *
remarks: ***************************************

person: Vsevolod Stetsinsky
address: 01110, Ukraine, Kiev, 20Á, Solomenskaya street. room 206.
phone: +38 050 6226676
e-mail: vs@netcathost.com
nic-hdl: VS1142-RIPE
changed: vs@netcathost.com 20040303
source: RIPE

yes, but 'whois info' is not often 'correct' especially in this case,
traceroute to it, unless ISPrime has some time-space vortex that ip
(that one of the /22) is actually in NYC. speed-o-light don't often lie...

Surprise, a spammer is operating from IPs with fake registration data.
I'm shocked... NOT!

Owen

Hi Owen,

  What makes you think that the registration is fake?

  Just curious. :slight_smile:

Pierre.