
As soon as the server gets a public IP address, automated scanners start checking it. They look for open SSH or RDP access, exposed databases, common passwords, and outdated services. This is a routine mass search for poorly protected systems, not necessarily an attack aimed specifically at your website.



