• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Question Possible ATP Attacks - can you help me?

Marcel.Zimmer

New Pleskian
Hello Values Community.

Unfortunately I have been struggling with ATP "attacks" for a few days now. Since a few days the firewall reports blocked DNS connection attempts to these domains in very irregular intervals:

betty.granithost.com
plesk.idvey.com

Unfortunately I can't find these DNS names anywhere in the log files. Probably the DNS queries are not logged (we don't have a BIND server in use) I suspect injection attacks, which are blocked.

Does anyone have an idea how I can better find out who or what is happening there?

Thanks a lot in advance!
 
I think that plesk security is down, Servers under ddos attack 24hrs, And we cannot do anything but jailing the requests IP's.

There's a lot of things that going wrong, and they don't care about anything but their money.
 
Back
Top