uBlockOrigin / uAssets

Resources for uBlock Origin, uMatrix: static filter lists, ready-to-use rulesets, etc.
GNU General Public License v3.0
4.2k stars 776 forks source link

Dangerous fake KMS activation websites #24189

Closed ghost closed 4 months ago

ghost commented 4 months ago

Prerequisites

URL(s) where the issue occurs.

kms-full.com
kmspico.ws
kmspico.io

Description

These websites deceives users into downloading malware by making them believe they are installing a legitimate Windows activator.

Other extensions used

none

Screenshot(s)

Screenshot(s)

Configuration

Details ```yaml ```
MasterKia commented 4 months ago

https://github.com/uBlockOrigin/uAssets/issues/24193#issue-2364500987

JobcenterTycoon commented 4 months ago

Most files are detected as a "HackTool" on virustotal.

ghost commented 4 months ago

I also found yasir-252.net, which appears to be more malicious than yasir252.com.

MIOGMIOG commented 4 months ago

(This comment will be talking primarly about KMSpico, but it applies to 99% of other windows/office "activators" as well) Hello, this is kinda like fitgirl repacks situation, where there are many fake websites pretending to be the original. (but KMSpico doesn’t have any website in the first place, the original is a forum post from 2013 on Mydigitallife forums), so I suggest adding wildcard filters, that can be added to Badware risks filter (not just for kmspico, but for other fake activator websites) (there is also malwarebytes blog post about fake kmspico websites if someone is interested I guess: https://www.threatdown.com/blog/kmspico-explained-no-kms-is-not-kill-microsoft/)