Skip to content

sites.google.com: badware #31424

@burger110

Description

@burger110

Prerequisites

  • This is NOT a YouTube, Facebook, Twitch or a shortener/hosting site report. These sites MUST be reported by clicking their respective links.
  • I read and understand the policy about what is a valid filter issue.
  • I verified that this issue is not a duplicate. (Use this button to find out.). Comment in the old issue threads even when they are closed or even if you have a different problem.
  • I did not remove any of the default filter lists, or I have verified that the issue was not caused by removing any of the default lists.
  • I did not enable additional or non-default filter lists, or I have identified which specific stock list is causing the issue.
  • I do not have custom filters/rules, or I have verified that the issue still occurs without custom filters/rules.
  • I have verified that the web browser's built-in content blocker/tracking protection, network wide/DNS blocking, or my VPN is not causing the issue.
  • I have turned off all other extensions and the issue still persists. (exception "Firefox Multi-Account Containers").
  • If this is about a breakage or detection, I have verified that it is caused by uBlock Origin and isn't a site or browser issue.
  • I have verified that the browser I am using is up to date with no pending updates.
  • I did not answer truthfully to ALL the above checkboxes.

URL address of the web page

https://sites.google.com/view/newext

Category

badware

Description

This website leads to malware downloads, specifically infostealer malware called "MaskGramStealer".
Sample of the malware: https://www.virustotal.com/gui/file/53e8715272957c3c72d079088691bc6149dbdabc7b923bcd41b13a7edbc6f086

Browser name and version

Firefox 146.0.1

Other extensions used

none

Country

No response

Screenshot(s)

https://github.com/user-attachments/assets/7d6a58fb-9943-484a-954d-322c1c35f864
https://github.com/user-attachments/assets/df5324af-f946-4a8c-aef1-fc311bd7f92b
https://github.com/user-attachments/assets/2e30d6f6-8c11-4721-ab26-f077735c4382

Screenshot(s)

Configuration

Details
uBlock Origin: 1.68.0
Firefox: 146
filterset (summary):
 network: 420307
 cosmetic: 268842
 scriptlet: 61361
 html: 3122
listset (total-discarded, last-updated):
 removed:
  urlhaus-1: null
 added:
  https://filters.adtidy.org/extension/ublock/filters/3.txt: 81140-1087, now
  https://malware-filter.gitlab.io/malware-filter/urlhaus-filter.txt: 50875-0, 1h.52m
  adguard-generic: 91551-529, now
  adguard-mobile: 11961-71, now
  adguard-spyware-url: 2408-136, now
  block-lan: 89-0, now
  curben-phishing: 132966-70, 1h.52m
  adguard-cookies: 36487-93, now
  ublock-cookies-adguard: 5266-75, now
  fanboy-cookiemonster: 45026-3650, now
  ublock-cookies-easylist: 5266-5266, now
  adguard-social: 25519-48, now
  [13 lists not shown]: [too many]
 default:
  user-filters: 11-0, never
  ublock-filters: 44055-4988, 1h.52m Δ
  ublock-badware: 11083-163, 1h.52m Δ
  ublock-privacy: 3562-481, 1h.52m Δ
  ublock-unbreak: 2777-155, 1h.52m Δ
  ublock-quick-fixes: 373-54, 1h.52m Δ
  easylist: 85537-1250, 1h.52m Δ
  easyprivacy: 55123-21627, 1h.52m Δ
  plowe-0: 3501-1496, now
filterset (user): [array of 11 redacted]
trustedset:
 added: [array of 93 redacted]
userSettings: [none]
hiddenSettings: [none]
supportStats:
 allReadyAfter: 265 ms (selfie)
 maxAssetCacheWait: 197 ms
 cacheBackend: indexedDB
popupPanel:
 blocked: 12
 network:
  google.com: 11
  csp.withgoogle.com: 1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions