Why are they going to so much trouble to have multiple IP's?
I’m not sure what I’m seeing. I've either gained a very avid fan or I’m spotting a very odd trend.
Los Angeles, California, US
38.98.19.68
Bookmark or direct
1 Performance Systems International
Los Angeles, California, US
38.98.19.66
Bookmark or direct
1 Performance Systems International
Los Angeles, California, US
38.98.19.111
Bookmark or direct
1 Performance Systems International
Los Angeles, California, US
38.98.19.113
Bookmark or direct
1 Performance Systems International
Los Angeles, California, US
38.98.19.67
Bookmark or direct
1 Performance Systems International
Washington, District of Columbia, US
cmcturbo.net 38.102.12.190
www.bloglines.com/myblogs_...
1 Performance Systems International
Los Angeles, California, US
38.98.19.112
Bookmark or direct
1 Performance Systems International
Los Angeles, California, US
38.98.19.114
Bookmark or direct
1 Performance Systems International
San Francisco, California, US
38.114.145.145
www.google.com/search?sour... Search: netsuite
1 Performance Systems International
Washington, District of Columbia, US
38.98.135.210
Bookmark or direct
1 Performance Systems International
Washington, District of Columbia, US
38.97.94.83
www.detroitchamber.com/det...
1 Performance Systems International
Washington, District of Columbia, US
cogentco.com 38.99.199.142
www.managingautomation.com...
1 Performance Systems International
Detroit, Michigan, US
38.196.106.2
www.automationalley.com/au...
1 Performance Systems International
Subscribe to:
Post Comments (Atom)
25 comments:
same here, I think it's a cloaked US gov run anti terror spider caterorising all sites into petencial suspects. Big brother is watching us.
Did anyone find out why the ip address 38.98.19.(with multiple different last numbers), continue to appear on various websites? Each time I check the location, it seems to be located in Illinois. Is that correct? What is Performance Systems International, and why does it appear soon after visiting your personal website or blog? Thanks
There are a couple of other ideas over on digg that respond. Not sure any are good so far. Performance Systems International is still a very frequent happening and no real answer.
http://www.psi-cu-software.com/Products.aspx
If you start up a broswer with weatherbug integrated you'll probably see an ISAPI call to this company with references to wxbug.com or some variant.
My guess is weatherbug is using parts of the xml middleware for the zip code processing.
psi is an isp, sometimes associated with free wi-fi. don't bug out.
It started appearing on my site after I signed up for snap.com and the links I hovered over referenced my site. Maybe someone linked to you and they have those snap.com links and someone hovered over yours.
Hello i'm french , PSI try to hacking my computer today, i read your post and i deduct it's an security program for terrorist ?
Lol i'm not, i'm true french, i don't want war or other but i want to defend my country against terrorist if needed. I now your country in war but mine too !
Thanks for this support (maybe us gov support :)) No problem i'm clean.
It's a preview tool. Someone wants to see a screen shot of your site before they visit it.
We get it all the time for http://opencubicle.net from blogs and search engines that has a preview tool.
I Don't think its an anti terror group more likely an anti piracy group though don't quote me on that
There are torrents uploaded that need a special codec/player these normally carry a trojan an example would be.
http://isohunt.com/torrent_details/34743075/2008?tab=comments
if you read the comment you need to goto http://kim-hayward.blogspot.com/2007/07/performance-systems-international.html
"Who or What is Performance Systems International"http://www.torrentmoviesupport.com/ and get the player
If you grab the peer list you will find.
38.103.50.130:47297
38.103.50.131:36917
38.103.50.132:40570
38.103.50.133:35387
38.103.50.135:49735
38.103.50.136:36447
38.103.50.137:38345
38.103.50.138:47822
38.103.50.139:51868
38.101.109.34:40220
38.101.109.36:33259
38.101.109.37:54962
38.103.50.140:44951
In the list thease ip's belong to Performance Systems International Inc.
I like open cubicle's response.
I was just on a site that uses that technique and left links to my blog there. So it's quite possible that someone touched on my link to see what image would pop up.
Dear Kim
My name is Christine. I believe I can shed a whole big light on your subject. I have recently been scammed by a Nigerian Scam artist. This site is one of the places he emails me from. The IP address is a hoax to get me to think it's based out of Washington DC. I am still running IP addresses from him, most come from a site called RIPE. However I have received several from Professiona Systems International. A bit more on this is they also seem to go after lending companies, I think they are copying information so as to get the victims banking info...or to get them sites so they can borrow more money to send to them. My Email is Christineajensen@yahoo.com please use the PSI in the subject as my spam has gone upwards of 700 msg per day. I can search for that subject and will respond. Also please do not publicly post this yet as I am trying still to recoup some loss if possible. Thank you. Hope this helps
I noticed it on my 3 blogs after I signed up with technorati.
I believe that the previous comments from "Mad" and "The Open Cubicle" were on the mark.
I blog at Wordpress.com, and I have been seeing hits from Performance Systems International showing up regularly. Latest one was from IP 38.98.19.68, in Washington DC. (I believe they are always listed as Washington DC whenever I've seen them hit me.
I did a traceroute to 38.98.19.68, and the next to last hop listed was IP 38.99.216.186 (perfect-market-technologies.demarc.cogentco.com). The last hop didn't have a rDNS entry, but I'm confident it's a router at perfect-market-technologies. Cogentco.com is Cogent Communications, based in Washington DC. Their website at www.cogentco.com says that they acquired the ISP formerly known as PSINet or Performance Systems International, among others.
Perfect Market Technologies appears to simply be a PSI / Cogent customer.
A Google search tells me that Perfect Market Technologies owns SNAP.COM, which is used by Wordpress (my blog host) to provide the "SnapShots" preview windows when you mouse over a link in my blog. I believe this probably explains PSI's interest in visiting my blog.
Perhaps others who are seeing traffic from PSI or Cogent or IP 38.98.x.x -or- 38.99.x.x can confirm whether a Snap.com product is used by their website or host.
If that is the case, mystery solved.
the truth and off the record: the person who said PSI is a cloaked US government run is partially correct. the government is not going to your site observing you per se. it is individuals, who subscribe to a service run secretly by the government that are visiting your websites. if big brother is watching anyone, it is these individuals every move. The suspicious things that are happening are because the individuals think they are anonymous--but they are not. there are thousands of individuals using this service. some are harmless, some are harmful. this is the government's way of catching the miscreants.
I got the same thing when I signed up on Technorati today 7/29/08. IP show 38.98.19.67/
Thanks, Alessandro Machi.
If ou have blogs, you will see it (PSI) more often. We link to sites we own as well or have a relationship with and we notice that those pages are now being scanned by PSI.
The plus side is whenever we upload or post a page Google now puts it in their index within 8 minutes.
Because of it, We had Viagra spammers trying to boost their PR and had to disable posts.
Don't block their whole IP range, block specific IP's.
These guys have several customers and I got some calls from customers saying they couldn't access the site anymore.
For example, Tonbridge Power uses some part of the 38.112.x.x range, though I don't know how much of it.
PSI is an ISP, dumbasses.
Next time do some research before reaching for the tinfoil hats.
I'm posting from a PSI IP, btw.
I just noticed on my gmail the following status.
"This account is open in 1 other location (38.101.10.101). Last account activity: 8 minutes ago at this IP (68.3.193.196). "
I am 68.3.193.196. Who the F has my account open at the other IP?
PSI visits me quite regulary...more so since the Justice Dept, State Dept, Dept of Defense, Social Security etc visited my site...no clue as to why me...
state.gov ? (U.S. Government)
169.253.4.# (U.S. Department of State)
U.S. Department of State
Continent : North America
Country : United States (Facts)
State : District of Columbia
City : Washington
Lat/Long : 38.9097, -77.0231 (Map)
whs.mil ? (Military)
199.173.226.# (Social Security Administration
140.185.96.# (The Pentagon)
The Pentagon
usdoj.gov ? (U.S. Government)
149.101.1.# (US Dept of Justice)
US Dept of Justice
Continent : North America
Country : United States (Facts)
State : District of Columbia
City : Washington
Lat/Long : 38.9097, -77.0231 (Map)
So what's all this about?
I've been hit by them twice so far as well, one on the 17th of this month and once in the morning.
I'm looking at mine right now through statscounter.com
Lets see...
Host Name - (Was Blank),
IP address - 38.98.19.(66 then 67),
Country - United States,
Reigion - Los Angeles, Califoria,
ISP - P.S.International,
Returning Visits - 0,
Visit Length - 0,
Browser - Snap 0,
Operating System - Unknown,
Resolution - 1024x768,
Javascript - Enabled,
- No referring Link,
Now going into 'Recent Visitor Maps'...
- The location that is coming up on my map is right in the middle of the 'Angelus Rosedale Cemetary' just off 'W Washington Blvd'.
Hope it helps in any way
Chris
Here is what I found when I followed the IP address:
http://www.botsvsbrowsers.com/ip/38.98.19.67/index.html
I guess it's the "snap preview" bot.
I pinpointed their location through an ip tracer just out of the white house. Definitely feds, I'm tempted to go down and check it out see what the deal is.
PSI have visited my site 95 times in the past few days. An art site. Perhaps this has something to do with the Snap.com thing. I did notice when I traced the IP 38.100.31.67 another name came up CYVEILLANCE ? Any ideas?
PSI may well be an ISP and used by different groups but is also being used by some government agency in large quantities which means that if Cogent owns PSI then makes sense that Cogent is a government owned company. There IP's are blocked using using PeerBlock and they seem to have much interest in P2P. As the last person wrote their email was opened by a PSI IP address then most likely apart of NSA perhaps. I do know for a fact that the NSA is and has been farming all of us illegally (legal in their minds) and also breaking many amendments of the Constitution. Don't be fooled into thinking they are not. Did you know that over 22000 thousand NSA employees farm all of us for information on a daily basis? They do
Post a Comment