• Debian 11 has reached its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.81 is the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Plesk v10.4.4 spam-sending infection

AndriusB

New Pleskian
Hello,
Our plesk server is constantly being added to CBL list with a message:
This IP is infected (or NATting for a computer that is infected) with a spam-sending infection. In other words, it's participating in a botnet. If you simply remove the listing without ensuring that the infection is removed (or the NAT secured), it will probably relist again.
I tried scanning server with clamav antivirus, but it didn't find anything. Mail logs don't show anything and mailq is small (normally when user account is hacked and they start spamming queue fills up).
Maybe someone had a similar problem?
 
Back
Top