> We have received a request from 144.24.162.178 for the removal of your I guess it's normal to reverse lookup this ip. I got Europe/London area using geoip2-database, which is low-end. I didn't get a reverse lookup result, which seems strange to me. Maybe things have changed since that was useful. It's better to have access to the system receiving the malicious requests. When queried on port 80 the host shows its domain name as [1]tschwaak.de , which appears to resolve to the same IP. References 1. http://tschwaak.de/