• I receive the following email form my server email address.
    My web hosting provider say that it is email from Wordfence and they scan my server with Plesk tool ImunifyAV and they did not find anything

    Proxmox Notification:

    Sender: info@*********.gr
    Receiver: **********@gmail.com
    Targets: **********@gmail.com

    Subject: Wordfence activity for 9 March 2020 on www.*********.gr

    Matching Rule: Virus Alert

    Rule: Virus Alert
    Receiver: **********@gmail.com
    Action: block message
    Action: notify info@*********.gr

    Virus Info: {HEX}Malware.Expert.malware.url.hastebin.com.0.UNOFFICIAL (clamav)

    Spam detection results: 0
    AWL 0.397 Adjusted score from AWL reputation of From: address
    BAYES_00 -1.9 Bayes spam probability is 0 to 1%
    HTML_MESSAGE 0.001 HTML included in message
    KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment
    MIME_HTML_ONLY 0.1 Message only has text/html MIME parts
    SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record
    SPF_PASS -0.001 SPF: sender matches SPF record
    T_REMOTE_IMAGE 0.01 Message contains an external image

Viewing 2 replies - 1 through 2 (of 2 total)
  • Hey @pexlechris,

    Can you please run a scan with Wordfence and share a screenshot of the results? This is a legitimate indication of malware. Not all scanners share the same malware signatures, so the results can be different.

    Please let me know.

    Thanks,

    Gerroald

    Thread Starter Pexle Chris

    (@pexlechris)

    I get this message, when I try to do a scan:

    Scan Failed
    The current scan looks like it has failed. Its last status update was more than 2 hours 59 mins ago. You may continue to wait in case it resumes or stop and restart the scan. Some sites may need adjustments to run scans reliably. Click here for steps you can try.

Viewing 2 replies - 1 through 2 (of 2 total)
  • The topic ‘worfence virus(?) email’ is closed to new replies.