Wednesday, October 10, 2007

Who is Abe Torkelton? - finding a webform bot

A recent web form hit made me curious, and a little bit of digging showed interesting behavior. Here's a bit about the observable anatomy of a form crawler bot going by the alias of "Abe Torkelton".

The bot has been tracked before, and apparently may show up as "Jorge Gonzales" leaving a phone number of 617-750-5939.

Hundreds of websites show in Google with hits from a registered user with a user string in the form:

Abe ???Torkelton????@cape-mail.com
The first three wildcards are letters, the last four are numbers - apparently part of a unique ID for the testing bot. Many more of these registrations can be seen by simply googling for either "Abe Torkelton"or "cape-mail.com".

The domain itself is registered through a domain proxy service run by gkg.net. This effectively hides the identity of the person running the bot.

What is the data being used for? I don't know yet - but somebody is finding every web form that they can submit user data to across the Internet, and they're seeing how those websites respond. Check your logs folks - this one is interesting to see.

UPDATE:

Thanks to comments on this post, I've posted an update.

20 comments:

Chuck N said...

Me too. at www.180bydesign.com, which doesn't have any linkage yet - so i'm not too sure how they found me.

Greg said...

My web site, www.gauntletwarbirds.com, got hit by this bot as well.

Sister Sunshine said...

I got hit by what I think is a variant: kkjTorkelton3094@cape-mail.com and my site is www.rainbow-websites.com

Curiouser and curiouser.

Wes said...

me too - my domain is www.ecartilage.co.uk, i got a hit from kbyTorkelton0986@cape-mail.com

however, my mailing list form also stores the user's IP address.

would this be useful to anyone?

Eduardo said...

I received his request today too!
Nombre - abe Torkelton
E-mail - knjTorkelton7650@cape-mail.com
Usuario - knjTorkelton7650

Im in Mexico City, my site: www.grupogalo.com

I delete him from my database, but in the middle I made a backup from all.

Saludos!

RKelly said...

Message = Praise
Comments =
Name = ABe Torkelton
Address = 198 Tremont Street, # 506
Phone = 6175075939


The above was left on mine. If the user has an email address it is automatically put in.

Very odd!

David said...

Thanks all for your comments - I'll keep adding these to my notes in case they prove useful.

Wes said...

The ID address I got was 64.5.40.122

Kate said...

I got one too... submission to my band's email list at thealphabeticalorder.org :

name:
Abe torkelton

email:
kqjTorkelton1989@cape-mail.com

addr1:
198 Tremont Street, Box 506

addr2:
198 Tremont Street, Box 506

city:
Boston

state:
MA

zip:
02116

country:
US

phone:
6175075939

From IP: 66.232.97.32

John said...

At my site www.ChampionshipRooms.com
I got:

name = abe Torkelton
email = ktdTorkelton6290@cape-mail.com
phone = 6175075939
REMOTE_HOST: 66.232.97.32

email didnt work either...

ecobookers said...

me too at www.ecobookers.com
email address sign up for a newsletter iqoTorkelton1997@cape-mail.com... strange.

Rene said...

He got me too on www.parkieten-freak.nl

bluesphee said...

I just received one too. Unfortunately for me I left a message after finding out that this is a bot. Any information on what this information is being used for? I left my name and a phone # since I run a business.

Josh said...

My website, www.questapalooza.com, got hit too.

No other information was supplied other than "Abe Torkelton" and the email "fqlTorkelton5287@cape-mail.com". I can supply the IP from my logs if that's helpful.

Lyme Regis SelfCatering Flat said...

Me too. I had a request for me to send a pdf of my brochure for holiday flat on www.lymebreak.co.uk.
Entered Abe as name and torkelton as email address, so I was just googling the name in the hope of finding an email address when I found this site. Can't contribute anything technical as I am a real newbie at this. Joan G

SquigY0 said...

Apparently, bots don't rest on Thanksgiving!

Below is the result of your feedback form. It was submitted by
() on Thursday, November 22, 2007 at 21:47:03
---------------------------------------------------------------------------

Artist: ABE Torkelton

Song: Abe TOrkelton

Requestor: Abe Torkelton

Message: 28

---------------------------------------------------------------------------

SJ said...

got hit today at www.iusedtobecool.com No info other than Abe Torkelton

BS said...

Abe just visited www.LocalPlaces.com and completed the web form nominating a business to advertise. The business name was quoted as "Abe torkelton", the address was completed as "198 Tremont Street, Box 506, Boston" and the URL was quoted was cape-mail.com. The email address field was left blank.

Earl said...

Got hit last week at gunshows-usa.com. Tried to call the number and get an answering machine.

Does seem strange what some folks try to do, Real question is why?

Michael Gandy said...

I think this just happened to me. Ive been receiving post to my contact form page that aren't real submissions. Thanks for the information I don't understand why people feel the need to create such bots, but what do I know.