Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
Try EnsoVPN - Reliable VPN - 1-Day Free Trial
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Try EnsoVPN - Fast & Private VPN - 1-Day Free Trial
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

VSYS permanently suspended my VPS without any technical explanation

2»

Comments

  • stevekelalstevekelal Member
    edited August 8

    @tzuli said:

    @stevekelal said: I've also contacted Spamhaus directly regarding the SBL699484 listing and my IP to ask for clarification about what activity caused the listing and whether my specific IP was involved.

    This seems odd. You've already screenshotted and linked the page that shows which IPs were flagged. Is your specific IP listed or not?

    Yes, my IP is listed. It’s the second-to-last entry on the list..

    Thanked by 1tzuli
  • Update: I checked the Spamhaus listing again today, and the SBL listing that previously contained my IP and the entire IP range has now been removed.

    Interestingly, there are still other older SBL listings visible on the same page, but the specific listing that contained my IP/range is gone. The original page where the listing was shown is:

    Spamhaus SBL listing page : https://check.spamhaus.org/sbl/listings/v-sys.org

    I don't know why this specific listing was removed. It could mean that the issue was resolved,or that the listing was removed after being reviewed. I don't want to speculate or claim that Spamhaus confirmed it was a false positive.

    However, the important point is that the listing that was being used as the apparent reason for my suspension is no longer there. I still have screenshots showing the original SBL listing, including my IP and the range, so I am keeping those as evidence.

    For me, this makes the lack of a proper explanation from the provider even more concerning. I still have not been given any logs, timestamps, screenshots, or specific evidence showing that activity originated from my VPS.

    I will keep this thread updated if I receive any meaningful explanation or new information.

    Note: All screenshots are hosted on ibb.co, which is the official image hosting domain of imgbb.com, in case anyone is unfamiliar with the links.

  • dedigoddedigod Member

    Another scammer provider on here

  • VoidVoid Member

    @yoursunny you got any lists to add providers like this ?

  • Another interesting finding: Ransomware ?

    I started looking further into the IPs that were previously included in the Spamhaus SBL listing. Some of those IPs are in the same IP range as mine and appear to be associated with the same infrastructure/network.

    I checked two of them, 213.111.150.189 and 213.111.150.190, and found that they are currently responding on port 80. When accessing them, they redirect to a page displaying what appears to be a WannaCry ransomware-related screen.

    Video proof: https://streamable.com/ofz5lg

    Considering that these IPs were previously part of the same Spamhaus listing, this raises a serious question: could there have been a security incident or compromise somewhere within the affected infrastructure?

    I am not claiming that this proves VSYS itself was hacked, nor am I claiming that these IPs are necessarily infected. However, the fact that these IPs are in the same range and are showing this behavior makes me question whether the situation was really as simple as activity originating from my VPS.

    If there was a security incident affecting the infrastructure, that could potentially explain why an entire IP range was listed and why customers may have been affected.

    At this point, I believe this deserves a proper technical explanation rather than another generic suspension message. I will continue documenting the evidence and updating this thread as I find more information.

    Thanked by 2forest khalequzzaman
  • @stevekelal said:
    @vsys_host

    I have a simple question.

    Spamhaus lists the entire 213.111.150.0/24 subnet under SBL699484.

    Do I own that entire /24 range? Of course not. I only had one VPS with one IP.

    So how was it determined that my VPS was the source? Were all the IPs in that subnet sending spam at the same time? Or was there something specific about my IP?

    I'm asking because this doesn't make sense to me.

    If the activity really originated from my VPS, then there should be at least one log, one timestamp, one abuse report, or any technical evidence proving it.

    That's all I'm asking for.

    You got scammed by VSYS, it is that simple.

  • forestforest Member

    @vsys_host You really should take another look at this thread...

    Thanked by 1stevekelal
  • conceptconcept Member

    Time for a new provider. If provider was reasonable, they would've just done their job, investigate it. If there is no evidence to support you caused Spamhaus listing, they should've just moved you off of that subnet.

    VSYS is one of those hosts that attract a certain group of clientele that attracts abuse and it gets picked up by LEA or a series of lawsuits in court. Then a client like you gets looped into the mess.

    Thanked by 1stevekelal
  • forestforest Member

    @concept said: Time for a new provider. If provider was reasonable, they would've just done their job, investigate it. If there is no evidence to support you caused Spamhaus listing, they should've just moved you off of that subnet.

    Good thing UrDN is returning. It'll be nice to have a decent host with a Ukrainian network.

    Thanked by 1OpaqueRegistrant
  • conceptconcept Member

    @forest said:

    @concept said: Time for a new provider. If provider was reasonable, they would've just done their job, investigate it. If there is no evidence to support you caused Spamhaus listing, they should've just moved you off of that subnet.

    Good thing UrDN is returning. It'll be nice to have a decent host with a Ukrainian network.

    idk.. they spin operations back up and then they are gone again.

  • forestforest Member

    @concept said:

    @forest said:

    @concept said: Time for a new provider. If provider was reasonable, they would've just done their job, investigate it. If there is no evidence to support you caused Spamhaus listing, they should've just moved you off of that subnet.

    Good thing UrDN is returning. It'll be nice to have a decent host with a Ukrainian network.

    idk.. they spin operations back up and then they are gone again.

    They only disappeared because all their hardware was seized. I suspect they'll do things a little differently now and won't disappear willingly.

  • conceptconcept Member

    @forest said:

    @concept said:

    @forest said:

    @concept said: Time for a new provider. If provider was reasonable, they would've just done their job, investigate it. If there is no evidence to support you caused Spamhaus listing, they should've just moved you off of that subnet.

    Good thing UrDN is returning. It'll be nice to have a decent host with a Ukrainian network.

    idk.. they spin operations back up and then they are gone again.

    They only disappeared because all their hardware was seized. I suspect they'll do things a little differently now and won't disappear willingly.

    I believe this is the second time it was seized by Ukrainian authorities so, don't have high hopes.
    https://lowendtalk.com/discussion/comment/1357847/#Comment_1357847
    https://lowendtalk.com/discussion/202749/urdn-seized-by-ukranian-government

    Thanked by 1tentor
  • forestforest Member

    @concept said:

    @forest said:

    @concept said:

    @forest said:

    @concept said: Time for a new provider. If provider was reasonable, they would've just done their job, investigate it. If there is no evidence to support you caused Spamhaus listing, they should've just moved you off of that subnet.

    Good thing UrDN is returning. It'll be nice to have a decent host with a Ukrainian network.

    idk.. they spin operations back up and then they are gone again.

    They only disappeared because all their hardware was seized. I suspect they'll do things a little differently now and won't disappear willingly.

    I believe this is the second time it was seized by Ukrainian authorities so, don't have high hopes.
    https://lowendtalk.com/discussion/comment/1357847/#Comment_1357847
    https://lowendtalk.com/discussion/202749/urdn-seized-by-ukranian-government

    https://www.urdn.com.ua/manage/static/feb13.txt

    The motivation of the attackers is unclear, however we understand that
    this may be a vengeful act as a result of our refusal to have informal
    channels with them. In Ukraine it is very common for employees of state
    agencies to try to establish informal channels with directors of
    companies so as to be able to bypass legal proceedings.

    Interesting.

  • rpqurpqu Member

    @forest said:

    @concept said:

    @forest said:

    @concept said:

    @forest said:

    @concept said: Time for a new provider. If provider was reasonable, they would've just done their job, investigate it. If there is no evidence to support you caused Spamhaus listing, they should've just moved you off of that subnet.

    Good thing UrDN is returning. It'll be nice to have a decent host with a Ukrainian network.

    idk.. they spin operations back up and then they are gone again.

    They only disappeared because all their hardware was seized. I suspect they'll do things a little differently now and won't disappear willingly.

    I believe this is the second time it was seized by Ukrainian authorities so, don't have high hopes.
    https://lowendtalk.com/discussion/comment/1357847/#Comment_1357847
    https://lowendtalk.com/discussion/202749/urdn-seized-by-ukranian-government

    https://www.urdn.com.ua/manage/static/feb13.txt

    The motivation of the attackers is unclear, however we understand that
    this may be a vengeful act as a result of our refusal to have informal
    channels with them. In Ukraine it is very common for employees of state
    agencies to try to establish informal channels with directors of
    companies so as to be able to bypass legal proceedings.

    Interesting.

    Maybe they didn't pay the bribe

  • @stevekelal said:
    Hello everyone,

    I'm sharing my experience with VSYS because I honestly don't know what else I could have done.

    I was a VSYS customer for almost 2 years, and I still had around 4 months remaining on my VPS when it was suddenly and permanently suspended.

    The only explanation I received was:

    "During a security review, our system detected activity originating from your account that violates our Terms of Service."

    No logs, no evidence, no timestamps, and no technical explanation were ever provided.

    My VPS was hosting my WordPress websites and development Docker containers. I never intentionally used it to send spam, and I never used it as a mail server. My email services are hosted with a completely different provider.

    After trying to understand what happened, I checked my VPS IP and found it listed on Spamhaus for suspicious email-related activity. I immediately contacted VSYS, explained that I genuinely had no idea what had happened, and asked them to review my case.

    Unfortunately, every reply was exactly the same template response saying the suspension was final, the case was closed, there would be no refund, and no further communication would be provided.

    I even contacted live chat hoping someone could at least ask the compliance team to review my case. Instead, I was told that abuse cases are not discussed via chat and was eventually asked to stop contacting their team.

    What disappointed me the most wasn't that they enforce abuse policies. I fully understand that every hosting provider has to protect its infrastructure.

    What disappointed me was the complete lack of transparency and the fact that I was never given a meaningful opportunity to explain my side or appeal the decision. It felt like I was judged, punished, and the door was immediately closed.

    I genuinely feel that I was treated unfairly. If I had knowingly violated their Terms of Service, I wouldn't have spent hours trying to understand what happened and asking them to review my case.

    Has anyone else experienced something similar with VSYS or another hosting provider?

    Stay well away from them. Before buying a VPS, make sure it’s a .com domain and that their website has some traffic; those small companies lose their server and the easiest solution for them is to block their customers.
    Then they change their name and start again. Don’t build your projects with companies that lack a reputation – stay well away from them.

  • @vsys_host said:
    @stevekelal

    Your service has been suspended due to a Spamhaus listing associated with activity originating from your VPS in accordance with our Terms of Service.

    As Spamhaus listings negatively affect the stability and reputation of our network, we are unable to restore the service.

    Virtual Systems may suspend a service without prior notice where continued provision of the service may conflict with applicable law, regulatory obligations, or our internal policies.

    In what fucking world would you find it acceptable for your services to be cancelled without refund without evidence? Put yourself in the customer's shoes.

    Incompetence and malice.

    Thanked by 3forest stevekelal tzuli
  • @vsys_host said:
    @stevekelal

    Your service has been suspended due to a Spamhaus listing associated with activity originating from your VPS in accordance with our Terms of Service.

    As Spamhaus listings negatively affect the stability and reputation of our network, we are unable to restore the service.

    Virtual Systems may suspend a service without prior notice where continued provision of the service may conflict with applicable law, regulatory obligations, or our internal policies.

    When I bought a VPS from chicagovps, they gave me an IP address on that list, but I wasn’t even bothered as I use Cloudflare to hide my IP and SMTP (fresh, clean IPs to ensure I always reach the customer’s inbox). Did you really scrap a project just because an IPv4 address was on a spam list? Unbelievable – these days, with so many free CDNs available, nobody cares whether an IP address is on a spam list or not; nobody uses their own IP to send emails – that’s what outsourced services (SMTP) are for.

    Thanked by 1stevekelal
  • edited August 9

    @vsys_host said:
    @stevekelal

    Your service has been suspended due to a Spamhaus listing associated with activity originating from your VPS in accordance with our Terms of Service.

    As Spamhaus listings negatively affect the stability and reputation of our network, we are unable to restore the service.

    Virtual Systems may suspend a service without prior notice where continued provision of the service may conflict with applicable law, regulatory obligations, or our internal policies.

    Wow. I was considering vsys.host. Now I'm not.

    You realize Spamhaus makes mistakes, right?

    Then yet another "higher-up" stepped in and said they weren't allowed, and so sorry but you can't get a refund because you paid with crypto and that's non-negotiable.

    Wow. That's probably illegal, if they hadn't changed their mind. Maybe they assume crypto-paying customers are shady people who wouldn't dare to expose their identity by suing, so they get to steal their money without any consequences.

    Thanked by 2stevekelal forest
  • @OpaqueRegistrant said: You realize Spamhaus makes mistakes, right?

    Yes... Spamhaus actually removed the listing for the entire range shortly afterwards, and from what I can see, most of the IPs in that range are now working again. My IP is still the one affected because VSYS suspended my VPS and refuses to give me access to investigate or recover my data.

    There was also another IP in the same range, 213.111.150.190, which appeared to be associated with WannaCry-related activity. That makes me wonder whether the listing may have been triggered by activity elsewhere in the range rather than specifically from my VPS.

    I only had WordPress websites on my VPS and no mail server at all. So I still don't understand what activity supposedly originated from my server.

    The fact that the entire range was listed and then removed relatively quickly makes me question whether this was a false positive or a wider range-level issue. I can't confirm the exact cause because VSYS won't give me access to investigate or provide the technical evidence I requested.

    At this point, I'm basically the one paying the price for a situation :s I still can't properly investigate. I just want access to my data and a clear explanation of what actually happened.

  • tentortentor Member, Host Rep

    @stevekelal said:
    from what I can see, most of the IPs in that range are now working again

    Tbf it might be new servers, are you sure e.g. SSH public key did not change?

  • @tentor said:

    @stevekelal said:
    from what I can see, most of the IPs in that range are now working again

    Tbf it might be new servers, are you sure e.g. SSH public key did not change?

    I was referring to the entire range I mentioned, not just my individual IP. There are other IPs from the Spamhaus listing that are working again, which is why I found it worth mentioning.

    I'm still confident that I didn't do anything that could explain the activity they attributed to my VPS. I had no mail server or anything similar running on it.

    At this point, I'm simply waiting for VSYS to provide the logs or technical evidence showing exactly what happened and what activity they detected from my VPS. Without that, I can't really investigate or understand what I'm supposedly responsible for.

  • tentortentor Member, Host Rep

    @stevekelal said:

    @tentor said:

    @stevekelal said:
    from what I can see, most of the IPs in that range are now working again

    Tbf it might be new servers, are you sure e.g. SSH public key did not change?

    I was referring to the entire range I mentioned, not just my individual IP. There are other IPs from the Spamhaus listing that are working again, which is why I found it worth mentioning.

    And I asked if you have evidence that these IP addresses were not reassigned to new customers/servers.

  • And I asked if you have evidence that these IP addresses were not reassigned to new customers/servers.

    That's exactly my point. I can't know whether those IPs were reassigned, and I never claimed that I had evidence that they weren't.

    What I do know is that Spamhaus listed the range, and shortly afterwards the listing for the range was removed. I also did not submit any removal request myself. That suggests there was something unusual going on at the range level, although I obviously can't say exactly what happened.

    I also don't believe that every IP in the range was necessarily responsible for the same activity at the same time. There could have been one or a few affected IPs, while other customers were completely unrelated.

    But my main point is still about my VPS specifically. I'm still waiting for VSYS to provide even one piece of technical evidence showing that my VPS actually generated the activity they used as the basis for the suspension.

    If they suspended my VPS solely because my IP appeared on a Spamhaus listing, without investigating or providing any evidence that I was responsible, then I don't consider that a fair or sufficient justification for permanently suspending my server and denying me access to my data.

  • forestforest Member

    @OpaqueRegistrant said: Wow. That's probably illegal, if they hadn't changed their mind. Maybe they assume crypto-paying customers are shady people who wouldn't dare to expose their identity by suing, so they get to steal their money without any consequences.

    I think they were afraid of running afoul of AML laws. It's pretty common to disallow refunds over cryptocurrency, but this was a special case because I only purchased it after being explicitly given the wrong information.

Sign In or Register to comment.