Regularly scanning systems for malware helps protect against the spread of malicious code that could undermine the trust customers and partners have in the security of a website. When malware is detected, affected files are disabled and the account holder is notified. Causes of malicious code can include outdated software or insecure passwords. In the event of abuse reports, immediate action should be taken to prevent further compromises. Repeated violations can lead to the domain being blocked. Security policies help prevent such incidents.
Our systems are regularly and thoroughly scanned for malware and other malicious code. To avoid collateral damage, detected files are temporarily disabled and a notification is sent to the account holder via email.
Why are the scans performed?
Files containing malicious code can be used to distribute unwanted mass emails and/or potentially infect the computers of website visitors. To minimize damage, active malware scans are carried out.
How does this affect me?
Customers and business partners rely on your website being secure. Malware on the website severely damages or completely destroys this trust. Customers who are warned about malware on your website or even get infected by it will no longer trust your website and, consequently, your company/organization.
If your website contains malware, web browsers and search engines may display a warning indicating that your site is dangerous. The website or domain can be placed on “blacklists” or, depending on the situation, temporarily taken offline.
General risks after malicious code injection:
- Manipulation of website content
- Deletion of content
- Theft of security-relevant data
- Addition of code to infect website visitors
- Blocking of the site by Google and other search engines
- Blocking of your .ch/.li domain by SWITCH
- Blocking of the domain by stopbadware and thus by all common browsers
- Damage to reputation with visitors and search engines
Here you will find more clearly explained information on the topic of malware.
What should I do if I have received an abuse notification?
The email includes instructions on the necessary measures. Please complete all steps to prevent a repeat compromise:
- Immediately review and update all web applications in use.
- Scan all workstations with FTP access to the specified website for viruses and trojans.
- If applicable, switch to encrypted FTP traffic.
- Change the FTP password via the Plesk admin tool.
- Remove the malicious code.
- Report to METANET.
- Regular maintenance and updating of web applications in use.
How could the malicious code have been injected?
Such cases can happen if:
- The used tool/CMS as well as plugins and themes are not regularly updated (security vulnerabilities).
- Files and folders have insecure permissions (chmod 777).
- Insecure passwords are used for FTP users.
My environment is up to date. It is unclear how this could happen. Who can help with root cause analysis?
We recommend the services of the company Sucuri. All details can be found at https://sucuri.net
To which email address is the information sent?
The email is sent to the email address stored in Plesk for the customer or, in reseller systems, to the reseller. This email address can be changed at any time independently in Plesk.
Why did I receive the notification about already blocked files with a delay and not immediately?
We perform a daily scan of all files changed in the last 24 hours. Therefore, notifications about malicious code are only sent once daily. The blocking of affected files occurs simultaneously with the notification.
Why can the files not be accessed?
Please note that the files have been disabled. To clean or download the files, you can adjust the permissions at any time via Plesk or with an FTP program (chmod 600).
The files have been on the server for several days/weeks. Why are they only being reported now?
Usually, one of the following reasons applies:
- The malware pattern was newly added to the malware database and was previously unknown.
- The content of the file was changed in the meantime and malicious code was injected. As a reference, the notification shows the found files with the timestamp of the last change.
The files belong to another user. How is this possible?
Spreading files on the server from other domains is possible as soon as directories have insecure permissions, such as chmod 777. This allows switching into this directory with an editor and creating or even removing files.
The domain does not resolve to the server or is not activated. Why do I still receive the notification?
The scan is performed on all files present on the system, regardless of whether the domain is active or not.
Since these files also pose a risk, please remove or clean all files.
Some legitimate files are reported. What can I do?
It can happen that legitimate files are classified as malicious code by the scanner due to certain search patterns. Please report such false positive files to us with the full path and a brief explanation so that we can exclude them from the next scan.
Can METANET perform a rescan?
Once all measures have been taken and the cleanup has been completed, we can repeat the scan at any time. Please reply to the received email to initiate this.
What are the consequences if none or not all measures are taken?
Repeated offenses can lead to the domain being blocked, meaning the domain will be password protected from website visitors.
On what legal basis is this blocking done?
This is defined in the Terms and Conditions under section 4.5 "Right to suspend services [...]":
METANET is [...] entitled to immediately suspend its services or block or remove the relevant customer account, server, service, content, program, etc., if the customer fails to comply with an obligation according to sections 5 and 6.4 – whether intentionally, unknowingly, or due to third-party fault.
How can such compromises be avoided?
Please refer to our security guidelines for this.