I am a customer of a cloud hosting provider (Cloudways). I create a new web site which gets a new automatically generated subdomain (like https://phpstack-xxxx-yyyy.cloudwaysapps.com/). I use Chrome on Windows 10 to set up the site. Within minutes of creating the new site I see in its access logs hits from the following IPs:
- 65.154.226.168 ("Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.71 Safari/537.36"),
- 133.242.174.119 & 133.242.140.127 ("Mozilla/5.0 (Linux; U; Android 2.2; ja-jp; SC-02B Build/FROYO) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1"),
- 193.169.244.228 ("Mozilla/5.0 (SymbianOS 9.4; Series60/5.0 NokiaN97-1/10.0.012; Profile/MIDP-2.1 Configuration/CLDC-1.1; en-us) AppleWebKit/525 (KHTML, like Gecko) WicKed/7.1.12344").
[edited out what turns out to be unrelated problem]
The question:
- How do I investigate where those leaks come from?