These are great sites to check yours:
https://sitecheck.sucuri.net/
http://www.tcpiputils.com/
https://myip.ms/
We use them and some others along with our host and CDN provider to track and blacklist/block the bad guys.
I notified a couple of you guys about possible injections on your sites.
There is always the chance for false positives too right?
We started running some tests on our server a couple weeks back.
Found some injections.
Have cleaned them up. Have been updating and securing around the clock.
Check out mal detect and clamav server-scanner software. Host should have it or something similar depending on your server config.
If anyone uses wp, I recommend the sucuri plug in as well as wordfence. Both can log and check whose trying to brute force your admins. Plus it can stop them in as little as 1 try. We use 2 or 3 attempts before banning.
Inn our case they were looking for dormant/semi dormant sites and tried to squeeze their BS in those first. Unfortunately it worked.
Best of luck!