Did you file a detailed abuse report with all necessary logs?
"For hacking, VOIP/SIP Scanning, (D)Dos and malicious software: a description of the illegal activities, including date and timestamp, the IP address of servers that are subject of the illegal activities, the destination port, source port and log files."
They are most likely getting in touch with the client, Leaseweb has an Abuse Portal in their control panel.
|