I currently was updating my vServer via console, updating also my letsencrypt certificates and so I checked my server-logs if there was any "special".
Nothing..but as i checked my nightly-subdomain log, there was something, UserAgent: "WebFuck V2.1 T0PHackTeam www.t0p.xyz", really? I checked...