Here is what the host of the website wrote minus the domain.
“xcloner 3.0.9 was exploited.
Someone from the Ukraine got in through {domain omitted}’s xcloner’s PHP files and uploaded their own bad php script which sent out over 9,000 spams non-stop.
I caught it after that happened, and removed the plug-in from the site.
I highly suggest you don’t put it back, and even though there is an upgrade
available, the reason you might need an upgrade is because the backup
program is letting hackers in… ”