mirror of
https://github.com/community-scripts/ProxmoxVE.git
synced 2026-02-05 00:29:55 +03:00
Site being erroneously reported as malware as the analytics.community-scripts.org domain resolves to a blacklisted IP #1216
Closed
opened 2026-02-04 23:42:40 +03:00 by OVERLORD
·
32 comments
No Branch/Tag Specified
main
github-action-update-changelog
pr-update-app-files
docker_deb13
feat/cloudinit-sshkeys
feat/sqlserver2025
automated/update-github-versions
add-script-opencloud-1770212555
add-script-openclaw-1770212634
github-action-archive-changelog
update_apps_tool
add-script-wishlist-1770193085
MickLesk-patch-2
add-script-writefreely-1770188758
add-script-wealthfolio-1770143943
fix/vaultwarden-update-script
remove_memos
disable_npm
feature/codeberg-functions-forgejo-readeck
add-script-rustypaste-1770019426
add-script-kitchenowl-1770017260
fix/2fauth-php-version
tools_func_addcodeberg
CrazyWolf13-patch-2
add-script-shelfmark-1769790178
CrazyWolf13-patch-1
add-script-ampache-1769790139
add-script-languagetool-1769790155
remove_php_deps
ref_koilection
fix/php-module-improvements
tremor021-patch-1
fix/open-archiver-meilisearch-migration
cloudflare_dns
MickLesk-patch-1
michelroegl-brunner-patch-2
fix/version-display
fix/debian13-root-ownership
feat/interactive_prompts
feature/smart-error-recovery
core_stable
update_docs
refactor/tools-func-stability
certbot_npm
2026-02-03
2026-02-02
2026-02-01
2026-01-31
2026-01-30
2026-01-29
2026-01-28
2026-01-27
2026-01-26
2026-01-25
2026-01-24
2026-01-23
2026-01-22
2026-01-21
2026-01-20
2026-01-19
2026-01-18
2026-01-17
2026-01-16
2026-01-15
2026-01-14
2026-01-13
2026-01-12
2026-01-11
2026-01-10
2026-01-09
2026-01-08
2026-01-07
2026-01-06
2026-01-05
2026-01-04
2026-01-03
2026-01-02
2026-01-01
2025-12-31
2025-12-30
2025-12-29
2025-12-28
2025-12-27
2025-12-26
2025-12-25
2025-12-24
2025-12-23
2025-12-22
2025-12-21
2025-12-20
2025-12-19
2025-12-18
2025-12-17
2025-12-16
2025-12-15
2025-12-14
2025-12-13
2025-12-12
2025-12-11
2025-12-10
2025-12-09
2025-12-08
2025-12-07
2025-12-06
2025-12-05
2025-12-04
2025-12-03
2025-12-02
2025-12-01
2025-11-30
2025-11-29
2025-11-28
2025-11-27
2025-11-26
2025-11-25
2025-11-24
2025-11-23
2025-11-22
2025-11-21
2025-11-20
2025-11-19
2025-11-18
2025-11-17
2025-11-16
2025-11-15
2025-11-14
2025-11-13
2025-11-12
2025-11-11
2025-11-10
2025-11-09
2025-11-08
2025-11-07
2025-11-06
2025-11-05
2025-11-04
2025-11-03
2025-11-02
2025-11-01
2025-10-31
2025-10-30
2025-10-29
2025-10-28
2025-10-27
2025-10-26
2025-10-25
2025-10-24
2025-10-23
2025-10-22
2025-10-21
2025-10-20
2025-10-19
2025-10-18
2025-10-17
2025-10-16
2025-10-15
2025-10-14
2025-10-13
2025-10-12
2025-10-11
2025-10-10
2025-10-09
2025-10-08
2025-10-07
2025-10-06
2025-10-05
2025-10-04
2025-10-03
2025-10-02
2025-10-01
2025-09-30
2025-09-29
2025-09-28
2025-09-27
2025-09-26
2025-09-25
2025-09-24
2025-09-23
2025-09-22
2025-09-21
2025-09-20
2025-09-19
2025-09-18
2025-09-17
2025-09-16
2025-09-15
2025-09-14
2025-09-13
2025-09-12
2025-09-11
2025-09-10
2025-09-09
2025-09-08
2025-09-07
2025-09-06
2025-09-05
2025-09-04
2025-09-03
2025-09-02
2025-09-01
2025-08-31
2025-08-30
2025-08-29
2025-08-28
2025-08-27
2025-08-26
2025-08-25
2025-08-24
2025-08-23
2025-08-22
2025-08-21
2025-08-20
2025-08-19
2025-08-18
2025-08-17
2025-08-16
2025-08-15
2025-08-14
2025-08-13
2025-08-12
2025-08-11
2025-08-10
2025-08-09
2025-08-08
2025-08-07
2025-08-06
2025-08-05
2025-08-04
2025-08-03
2025-08-02
2025-08-01
2025-07-31
2025-07-30
2025-07-29
2025-07-28
2025-07-27
2025-07-26
2025-07-25
2025-07-24
2025-07-23
2025-07-22
2025-07-21
2025-07-20
2025-07-19
2025-07-18
2025-07-17
2025-07-16
2025-07-15
2025-07-14
2025-07-11
2025-07-10
2025-07-09
2025-07-08
2025-07-07
2025-07-06
2025-07-05
2025-07-04
2025-07-03
2025-07-02
2025-07-01
2025-06-30
2025-06-29
2025-06-28
2025-06-27
2025-06-26
2025-06-25
2025-06-24
2025-06-23
2025-06-22
2025-06-21
2025-06-20
2025-06-19
2025-06-18
2025-06-17
2025-06-16
2025-06-15
2025-06-14
2025-06-13
2025-06-12
2025-06-11
2025-06-10
2025-06-09
2025-06-08
2025-06-07
2025-06-06
2025-06-05
2025-06-04
2025-06-03
2025-06-02
2025-06-01
2025-05-31
2025-05-30
2025-05-29
2025-05-28
2025-05-27
2025-05-26
2025-05-25
2025-05-24
2025-05-23
2025-05-22
2025-05-21
2025-05-20
2025-05-19
2025-05-18
2025-05-17
2025-05-16
2025-05-15
2025-05-14
2025-05-13
2025-05-12
2025-05-11
2025-05-10
2025-05-09
2025-05-08
2025-05-07
2025-05-06
2025-05-05
2025-05-04
2025-05-03
2025-05-02
2025-05-01
2025-04-30
2025-04-29
2025-04-28
2025-04-27
2025-04-26
2025-04-25
2025-04-24
2025-04-23
2025-04-22
2025-04-20
2025-04-21
2025-04-19
2025-04-18
2025-04-17
2025-04-15
2025-04-16
2025-04-14
2025-04-13
2025-04-12
2025-04-11
2025-04-10
2025-04-09
2025-04-08
2025-04-07
2025-04-06
2025-04-05
2025-04-04
2025-04-03
2025-04-02
2025-04-01
2025-03-31
2025-03-30
2025-03-29
2025-03-28
2025-03-27
2025-03-26
2025-03-25
2025-03-24
2025-03-23
2025-03-22
2025-03-21
2025-03-20
2025-03-19
2025-03-18
2025-03-17
2025-03-16
2025-03-15
2025-03-14
2025-03-13
2025-03-12
2025-03-11
2025-03-10
2025-03-09
2025-03-08
2025-03-07
2025-03-06
2025-03-05
2025-03-04
2025-03-03
2025-03-02
2025-03-01
2025-02-28
2025-02-27
2025-02-26
2025-02-25
2025-02-24
2025-02-23
2025-02-21
2025-02-20
2025-02-19
2025-02-18
2025-02-17
2025-02-16
2025-02-15
2025-02-14
2025-02-13
2025-02-12
2025-02-11
2025-02-10
2025-02-09
2025-02-08
2025-02-07
2025-02-06
2025-02-05
2025-02-04
2025-02-03
2025-02-02
2025-02-01
2025-01-31
2025-01-30
2025-01-29
2025-01-28
2025-01-27
2025-01-26
2025-01-24
2025-01-23
2025-01-22
2025-01-21
2025-01-20
2025-01-19
2025-01-18
2025-01-17
2025-01-16
2025-01-15
2025-01-14
2025-01-13
2025-01-11
2025-01-10
2025-01-09
2025-01-08
2025-01-07
2025-01-06
2025-01-05
2025-01-04
2025-01-03
2025-01-02
2025-01-01
2024-12-31
2024-12-30
2024-12-29
2024-12-28
2024-12-27
2024-12-26
2024-12-25
2024-12-23
2024-12-21
2024-12-20
2024-12-19
2024-12-18
2024-12-17
2024-12-16
2024-12-13
2024-12-12
2024-12-09
2024-12-08
2024-12-07
2024-12-06
2024-12-05
2024-12-04
2024-12-03
2024-12-02
2024-11-30
2024-11-29
2024-11-28
2024-11-27
2024-11-26
2024-11-25
2024-11-24
2024-11-23
Labels
Clear labels
Implemented in VED waiting push to Main
breaking change
bug
bug
bugfix
deferred
delete script
dependencies
enhancement
external
feature
github
help wanted
in project pipeline
invalid
investigation
json
maintenance
needs triage
new script
new script
nice to have
not a script issue
not planned
organization
pull-request
question
refactor
rename script
security
update script
website
wontdo
🛑 Failure to comply with the guidelines
Mirrored from GitHub Pull Request
No Label
website
Milestone
No items
No Milestone
Projects
Clear projects
No project
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: starred/ProxmoxVE#1216
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @ciaranj on GitHub (Jul 3, 2025).
Please verify that you have read and understood the guidelines.
yes
What type of issue is this?
Bug
A clear and concise description of the issue.
The website appears to be being flagged by AVG as malware containing currently? (the domain is blacklisted?)
This tool appears to agree: https://sitecheck.sucuri.net/results/https/community-scripts.github.io/ProxmoxVE/
Which browser are you using?
Chrome
If relevant, including screenshots or a code block can be helpful in clarifying the issue.
No response
Please provide detailed steps to reproduce the issue.
No response
@MickLesk commented on GitHub (Jul 3, 2025):
yeah, but we dont know why. its the analytics website page (umami default). Its secured with SSL Wildcard and an simple umami install
@ciaranj commented on GitHub (Jul 3, 2025):
It's because analytics.community-scripts.org is blacklisted by Zen SpamHaus (or at least the IP 77.165.18.225 is.) Were you sending mails from this IP ?
@tremor021 commented on GitHub (Jul 3, 2025):
i don't think thats it
@ciaranj commented on GitHub (Jul 3, 2025):
k. I mean, it looks like it /may/ be it:
The Domain Name isn't blacklisted, but the IP it currently points to, does appear to be blacklisted?
@MickLesk commented on GitHub (Jul 3, 2025):
its just the static umami site. I personally have no influence on this, it is secured with Caddy and is a DNS forwarding from my IONOS domain (community-scripts.org) - only @BramSuurdje can say whether anything happens to mails.
Otherwise we might have to move the Analytic to another server (where our Gitea is running)
@BramSuurdje commented on GitHub (Jul 3, 2025):
i mean it was working perfectly fine when it was on other domains before. no clue what happened here. like you said we might have to move it to another server
@MickLesk commented on GitHub (Jul 3, 2025):
@michelroegl-brunner your part, do you still have resources for an additional system besides gitea? because the git. / .docs / .api subdomain working fine with this server
@BramSuurdje commented on GitHub (Jul 3, 2025):
umami doesnt take alot of resources
@michelroegl-brunner commented on GitHub (Jul 3, 2025):
Heaps of space left. @BramSuurdje can you shoot me a quick dm on discord how i can set it up on my node?
@dddanny79 commented on GitHub (Jul 3, 2025):
Same for me with Norton :
Maybe the information helps.
@MickLesk commented on GitHub (Jul 3, 2025):
We migrate the Umami Analytics in next days to another Host, we dont know why its Blacklisted. All other Subdomain work fine and the Script (Umami) is up-to-date. Maybe this solves it
@ciaranj commented on GitHub (Jul 3, 2025):
The other subdomains point to other (non) blacklisted IPs. Moving it to that same IP will resolve your woes. I’d guess you’re trying to use a residential IP or a shared machine that someone else has used for sending a high volume of mail (spam) so you’re really being affected by ‘side effect’.
@tremor021 commented on GitHub (Jul 3, 2025):
Yea, hazards of shared hosting, lol
@webmogul1 commented on GitHub (Jul 4, 2025):
It is working now.
@ciaranj commented on GitHub (Jul 4, 2025):
I agree, even though the domain is still resolving to an apparently blacklisted IP. (https://check.spamhaus.org/results/?query=77.165.18.225) What-the-heck?!.
@michelroegl-brunner commented on GitHub (Jul 4, 2025):
Nothing has changed yet. I will do it Monday.
@MickLesk commented on GitHub (Jul 4, 2025):
I reported the incorrect classification to Google yesterday (safebrowsing)
@BramSuurdje commented on GitHub (Jul 6, 2025):
they all run to the same IP
pretty weird though, this umami is running from my VPS instance and i have never had a mail server on there
@ciaranj commented on GitHub (Jul 6, 2025):
not for me they don’t, and I’d expect my resolution experience to be pretty common.
As I guessed at earlier and you just confirmed you’re likely in some sort of shared hosting environment. So either you’re being NATd and there’s a bunch of other servers sharing that public IP or there was a previous server on that VPS provider who had that IP and did some spammy bulk mailing that got that IP blacklisted (this is a very common problem.)
@MickLesk commented on GitHub (Jul 6, 2025):
Should be done next week, we will move it to the same server as the other subdomains
@webmogul1 commented on GitHub (Jul 6, 2025):
Just so you know, norton shows two "threats" now.
@tremor021 commented on GitHub (Jul 6, 2025):
yea, it contains "scripts" :) no shit sherlock :) norton at its best :)
@Aerodrummer commented on GitHub (Jul 9, 2025):
Virustotal.com just some minutes ago.
@tremor021 commented on GitHub (Jul 9, 2025):
I just want them to post somewhere how the hell they figured out its a "phishing" site. I just wanna see the technique they use to fail so hard... wtf
@mon5termatt commented on GitHub (Jul 13, 2025):
Alright, so this is according the malwarebytes staff.
@ciaranj commented on GitHub (Jul 13, 2025):
This continues to be an issue because the domain continues to resolve to a blacklisted IP. Whilst there may be problems within the scripts, I'd be more inclined to assume the malware checkers are just flagging the far more clear-cut problem. The existence of that IP on the spamhaus blacklist, which again, is likely nothing to do with this particular server instance, but a prior or shared owner of that public IP.
You can see that it is unlikely to be the script itself by comparing the results for
https://www.virustotal.com/gui/url/12adef258c1ffc2dbfc64b64fb4bff5a3385638ba2aa6a1b1040d110c52be1aa/detection
with those for
https://www.virustotal.com/gui/url/5f1dff1b5268b51263e26723560d2d995e7c30c931557d867fe761fba5074dea
The content of both is the same, it's the hosting location that differs....
@tremor021 commented on GitHub (Jul 13, 2025):
@mon5termatt
Infected with what?
@ciaranj commented on GitHub (Jul 13, 2025):
I’m not saying it is, quite the opposite, it’s being flagged because of where it’s being served from :( does anyone know if you can transfer ownership of issues so I can leave this thread and not have to say it again 😂
@tremor021 commented on GitHub (Jul 13, 2025):
@ciaranj i'm replying to @mon5termatt because his screenshot says malwarebytes people say its a infected script. I pasted the source code of it so if anyone pinpoint what is infected.
@mon5termatt commented on GitHub (Jul 13, 2025):
I'm just forwarding what I saw them reply to me with. So I genuinely have no idea. I think that their assessment is wrong, but they're the staff and so I can't mess with them.
@mon5termatt commented on GitHub (Jul 13, 2025):
https://forums.malwarebytes.com/topic/327667-community-scriptsorg/#comment-1707619
@MickLesk commented on GitHub (Jul 15, 2025):
https://forums.malwarebytes.com/topic/327667-community-scriptsorg/#comment-1707647
Classic. Support prefers to delete the request and refers to any rules but gives no feedback about the standard script which is incorrectly recognized by them. Very professional guys 😄
I have now removed the IP forwarding for Umami, which means that we no longer have any website data, but it should not block anything until we have moved the server