uBlockOrigin / uAssets

Resources for uBlock Origin, uMatrix: static filter lists, ready-to-use rulesets, etc.
GNU General Public License v3.0
4.12k stars 767 forks source link

meltedpleasandtws.shop: Malware #24107

Closed ghost closed 4 months ago

ghost commented 4 months ago

Prerequisites

URL(s) where the issue occurs.

meltedpleasandtws.shop
meltedpleasandtws.shop/api

Description

It's a malicious website that Stealer malware connects to

Other extensions used

none

Screenshot(s)

Screenshot(s)

Configuration

Details ```yaml ```
JobcenterTycoon commented 4 months ago

What can uBO do against this? uBO only blocks network requests in the browser. Blocking sites which perform outside of the browser would just bloat uBOs lists.

ghost commented 4 months ago

I've been told that uAssets is for malware and phishing reports as well, under "Badware". I've reported dozens of them in the past, and it all went well. Has uBO's policy changed? Because I'm unaware.

JobcenterTycoon commented 4 months ago

Yes malware and phishing which perform in the browser. uBlock filters – Badware risks is designed for uBO, not for DNS blockers and its not a antivirus.

ghost commented 4 months ago

This website has multiple subdomains, some of which contain content. For example, the /api+ (not just /api) subdomain hosts Russian content and shows the highest malware positives on VirusTotal compared to the other subdomains I've found so far. Malware connecting to this domain is one possibility, which uBlock Origin can't protect against, yes, but users could also be vulnerable through their browsers if another website redirects them to these subdomains, which may contain malware.

JobcenterTycoon commented 4 months ago

Ok malicious content which can harm browser users is a case for uBO.

To make it more clear: