uBlockOrigin / uAssets

Resources for uBlock Origin, uMatrix: static filter lists, ready-to-use rulesets, etc.
GNU General Public License v3.0
4.09k stars 763 forks source link

zqvee2re50mr.com: badware #25537

Closed ExtRIELICi closed 5 days ago

ExtRIELICi commented 5 days ago

Prerequisites

URL(s) where the issue occurs.

https://zqvee2re50mr.com/yu932ns0?key=c8efb1f92002fe49f29900703554cfb6

Description

This is a malicious domain that hides within search bars and other places in some websites. It doesn't seem to be blocked by uBlock Origin.

Other extensions used

none

Screenshot(s)

Screenshot(s)

Configuration

Details ```yaml ```
JobcenterTycoon commented 5 days ago

the redirect is blocked by .com/api/users*^pii=&in=false^$document

Please report the sites which using this crap instead of just reporting the unstable badware domain.

ExtRIELICi commented 5 days ago

I found it in gamatotv.info, which is quite a popular website in Greece and Cyprus.

JobcenterTycoon commented 5 days ago

The javascript popup coming from https://gamatotv.info/fbb53bfb0e7dad3e75ca078edbe1cf98.js but there is also a <a> tag with https://zqvee2re50mr.com/yu932ns0?key=c8efb1f92002fe49f29900703554cfb6 (both popups blocked with generic rules already).

Maybe also the link itself can be blocked if its stable:

simplest filter to hide: ###ads5 (EL contains ###ads50) link target: gamatotv.info##a[rel="noopener"][onclick^="javascript:window.open('https://"][onclick*="?key="]

@Yuki2718 something known here?

ghajini commented 5 days ago

download links on site also has popups

gmtcloud.best###ads5
||gamatotv.info^$script,3p
Yuki2718 commented 4 days ago

something known here?

I don't, the best I know is that those Apate web/VexTrio links with key= are also spread via email. If it is globally seen in the web too, maybe worth considering generic cosmetic filters.