Replies: 0
Just this morning started seeing strange entries in the Traffic Feed….
All (dozens and dozens) are from multiple IP addresses from various parts of the world, but each has a mangled URL with the following common browser reference:
—
Mozilla/5.0 (iPhone; CPU iPhone OS 9_3_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Mobile/13F69 [FBAN/FBIOS;FBAV/72.0.0.40.71;FBBV/43917395;FBRV/43917395;FBDV/iPhone6,1;FBMD/iPhone;FBSN/iPhone OS;FBSV/9.3.2;FBSS/2;FBCR/Bell;FBID/phone;FBLC/en_US;FBOP/5]
And the mangled URLs all have this form (I edited the domain name “nnnnn”):
http://nnnnn.cahttp://nnnnn.ca:80/home/
Note the doubling of the URL with no space, and the doubled URL has an :80 reference in it…
Is it just a mangled URL from a faulty IP/URL retrieval or something else more suggestive of a hack?
-
This topic was modified 22 hours, 58 minutes ago by
bluebearmedia.