I was logged into my Cloudflare account today attempting to setup Tunnels when I noticed various security events related to my domain. Upon further inspection I realized that they all originated from a Microsoft Owned IP address (I鈥檓 assuming somebody running a Azure VM instance).
Looking into the actual request headers I can see that whatever bot was running was looking for common PHP exploits or unsecured endpoints.
I usually ignore such instances as I have proper firewall rules both on the Cloudflare side as well as my local network side so I鈥檓 doubting there鈥檚 actually any threat to my network. However, I decided today to email the abuse contact provided from the WHOIS details. Was wondering if anybody else had experience with writing these? Is it even worth writing them or do they just end up being a waste of time?
Edit: Thanks everybody for the responses! Seems that it鈥檚 up in the air if I鈥檒l ever get a response back. Maybe that鈥檚 okay - Looks like the general consensus is that these usually do end up getting taken seriously (at least by some providers). I guess I鈥檒l keep composing away even if it鈥檚 just an exercise in good internet stewardship :)
Yea, I have submitted multiple abuse emails with details to domain registrars for scamming and phishing.
Didn鈥檛 receive any update from them on any action taken yet.