Hey, hat jemand ne Ahnung was die Abuse möglicherweise auslöst bzw, wie ich es in den Griff bekomme?
Dear Sir/Madam,
we have detected abuse from the IP address *IP Entfernt*, which according to a whois lookup is on your network. We would appreciate if you would investigate and take action as appropriate.
Log lines are given below, but please ask if you require any further information.
If you are not the correct person to contact about this please accept our apologies - your e-mail address was extracted from the whois record by an automated process.
This mail was automatically generated.
Note: Local timezone is +0200 (CEST)
/var/log/apache2/access.log:*IP Entfernt* - - [25/Oct/2014:03:39:29 +0200] "GET /iiii/iii/ii.php HTTP/1.1" 404 293 "-" "-"
/var/log/apache2/access.log:*IP Entfernt* - - [25/Oct/2014:03:39:29 +0200] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 404 306 "-" "-"
/var/log/apache2/access.log:*IP Entfernt* - - [25/Oct/2014:03:39:29 +0200] "GET /pma/scripts/setup.php HTTP/1.1" 404 299 "-" "-"
/var/log/apache2/access.log:*IP Entfernt* - - [25/Oct/2014:03:39:29 +0200] "GET /myadmin/scripts/setup.php HTTP/1.1" 404 303 "-" "-"
With best regards
Clusters GmbH
und
To whom it may concern,
we see scan/probe attempts coming from your IP *IP Entfernt*. This is the logfile entry of the attempted scan at our honeypot:
*IP Entfernt* - - [24/Oct/2014:07:59:51 +0000] "GET /phpMyAdmin/scripts/setup.php HTTP/1.1" 403 43
Regards,
OSN Abuse Team