Today for the second time (that I'm aware of) my site has received odd page calls, and I would like to know if this looks like something malicious that needs attention.
The requested addresses were:
I've never had anything at my site remotely like "sheetmetel". A few days ago I got a similar call (which had "sheetmetel"), but without the appended part of the address (after the "?").Code:http://mydomain.com/sheetmetel/wobbles.php?sheme=27&redirect=webcontrol1.net%2Fcheck%2Fweb.cgi&dgen=openmonitor1.net%2Fgenerator_root_1%2Fgenerator.php&secvalue=b651b3a917de86bfd567093f55691dff&cached=true&remove_file=true http://mydomain.com/sheetmetel/wobbles.php?sheme=27&redirect=http%3A%2F%2Fwebcontrol1.net%2Fcheck%2Fweb.cgi&dgen=http%3A%2F%2Fopenmonitor1.net%2Fgenerator_root_1%2Fgenerator.php&secvalue=b651b3a917de86bfd567093f55691dff&cached=true&remove_file=true
The lookup showed the IP to be in Germany. The earlier one was listed in Holland. A search on the earlier IP revealed that the site had crashed that day and was considered by some people (at a forum) to be unreliable.
My site is only for very limited private use, still in early development, not intended for any public access, marked "no index" in the robot.txt and all the file headers; and to my knowledge the domain hasn't been cited anywhere in the internet.
I'm wondering if this looks like something malicious that calls for some kind of action. Could a page call like this cause a problem? Is my domain name being used (via redirection) for hacking? I don't know how to read those appended parts, and wonder if they're some sort of script. And I wonder about that ending "remove_file=true".
Is this something my host company would want to know about?
I've blocked the IPs but of course a hacker would be using various IPs, so the block seems unlikely to do much.
Thanks for the guidance.








Bookmarks