... guess that's how is looks like ?
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/cgi-bin/pennywize/pennyw.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/cgi-bin/r_manage.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/cgi/add-passwd.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/cgibin//add-passwd.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/cgibin/recon.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/epoch/add-passwd.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/template.html" 200 3986
http://XXX.XXX.XXX.XXX/data/verotellog.txt [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/template.html" 200 3819
http://XXX.XXX.XXX.XXX/epwd/.passwd [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/template.html" 200 3407
http://XXX.XXX.XXX.XXX/ibill/.passwd [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:19 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/nbmember.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:20 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/cgi-bin/glocation.cgi [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:20 +0000] "GET XXX.XXX.XXX.XXX/template.html" 200 3570
http://XXX.XXX.XXX.XXX//.passwd [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:20 +0000] "GET XXX.XXX.XXX.XXX/nothing.txt" 200 200
http://XXX.XXX.XXX.XXX/cgi-bin/pennywize/penny.pl.bak [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
213.67.45.221 - [18/Feb/2004:02:45:20 +0000] "GET XXX.XXX.XXX.XXX/template.html" 200 3644
http://XXX.XXX.XXX.XXX/passwd/.htpasswd [Mozilla/4.0%20(compatible;%20MSIE%206.0;%20Windows%20NT%20 5.1)]
... and that's what it stops:
/sbin/route add -host 213.67.45.221 127.0.0.1
... and that's who it is:
TeliaSonera AB (TELIA2-DOM)
Marbackegatan 11
Farsta, - s-123 86
SE
Domain Name: TELIA.COM
Administrative Contact:
TeliaSonera AB (LOLVXQTUPO)
[email protected]
Box 10066
Stockholm, - s-121 27
SE
+46 8 456 81 28 fax: +46 8 456 89 85
Technical Contact:
TeliaSonera AB (VOACPYJEEO)
[email protected]
Box 10707
Stockholm, - s-121 29
SE
+46 8 456 89 30 fax: +46 8 456 89 35
Record expires on 18-Aug-2011.
Record created on 19-Aug-1995.
Database last updated on 18-Feb-2004 06:48:16 EST.
Domain servers in listed order:
DNS1.TELIA.COM 194.22.190.10
DNS2.TELIA.COM 194.22.194.14
NS.TELIA.SE 131.115.15.7
NS2.CW.NET 204.70.57.242