uBlockOrigin / uAssets

Resources for uBlock Origin, uMatrix: static filter lists, ready-to-use rulesets, etc.
GNU General Public License v3.0
4.07k stars 764 forks source link

getkmspico.com: Badware #24187

Closed ghost closed 3 months ago

ghost commented 3 months ago

Prerequisites

URL(s) where the issue occurs.

http://getkmspico.com/

Description

This website is a total nightmare. It is filled with malicious and phishing ads and pop-ups. Clicking anywhere results in a random malicious website appearing. I recommend blocking this domain entirely, as there are multiple associated malicious domains. Something might slip past uBO, potentially leading to users being scammed or worse.

Here are a few of the many malicious/phishing/adware domains it connects to:

download.artificusbrowser.com
poperblocker.com
ak.itponytaa.com
ad.install-adblockers.com
veepteero.com
rnofor4ht.top
ads.download-adblockers.com
file.fan
file.fan/38131da0f904a05
baldappetizingun.com
tracking.trackingrouter.com
app-rush.com
ak.oneegrou.net

Other extensions used

none

Screenshot(s)

Screenshot(s)

Configuration

Details ```yaml ```
stephenhawk8054 commented 3 months ago

I can't reproduce the popup despite clicking many places on the page.

ghajini commented 3 months ago

there's nothing malicious ads on this site its just activator which iam pretty sure all av softwares will block

ghost commented 3 months ago

uBO does a good job of blocking popups, however, there is always a chance it could miss a future malicious ad or popup. Try visiting the website with uBO turned off, and you'll understand what I mean. Wouldn't it be better if this domain were blocked altogether? It's not a legitimate website anyway, and even the activator it offers is malware, as seen here: https://www.youtube.com/watch?v=mDyODRZq1GA

ghajini commented 3 months ago

yeah pretty sure every illegal software patchers are malware

JobcenterTycoon commented 3 months ago

https://www.virustotal.com/gui/file/67547d29f8cb79697566a4446c617ffca59dc0bdc982afbf64cd7de189999098?nocache=1

Most AV vendors flagging the download as a "HackTool", "Crack" or "AutoKMS" so its not malware. Same for the downloads on many sites you reported in https://github.com/uBlockOrigin/uAssets/issues/24193

"I get popups with uBO off" is not a reason to hard block a site. When we would start to block sites with this reason we would block the half internet...

"Maybe it spreading malware in the future" is not a reason to block a site.

ghost commented 3 months ago

Okay, I understand.

However, most of these websites distribute software that, after installation, contact other malicious domains, download InfoStealers from them, and send users' data without their knowledge.

They're (the websites I reported) sources of malware and offer no benefit to users, only harmful software. Thats why I reported them.

JobcenterTycoon commented 3 months ago
pic
ghost commented 3 months ago

Interesting. From what I saw on one sample, it connects to rnofor4ht.top and mofor4ht.top for example.

Also, the downloaded file from kms-full.com is obfuscating its files to avoid analysis, is avoiding being run in a VM and is using delayed execution, which is suspicious. VirusTotal

![image](https://github.com/uBlockOrigin/uAssets/assets/123986260/a253dfa9-b157-473c-8de4-925ad1f74648)
JobcenterTycoon commented 3 months ago

kms-full.com got added 10 hours ago already https://github.com/uBlockOrigin/uAssets/commit/5dc64eed2e6876a9e9e34ba290522614c4a0f128

ghost commented 3 months ago

Anyways, I will test them analytically and report again if I find anything new and specific beyond what was already blocked earlier.