Page 2 of 2

Re: gorillavid.in / movpod.in / daclips.in

Posted: Fri Jul 14, 2017 10:25 pm
by gotitbro
Yes, the above filters do work.

As I said in my post above (don't know why it was edited) the redirections are part of the RoughTed malvertising campaign especially directed towards adblock users and the uBO solution seems better as it will also block browser fingerprinting.

I am just trying to make users aware of this malware campaign, please do tell if I posted anything wrong.

Re: gorillavid.in / movpod.in / daclips.in

Posted: Sat Jul 15, 2017 7:53 am
by logi007
That clears it up. However, I was still on the video page. Only the URL changed and remained on the daclips.com domain.

The filters worked to fix THAT, however, the video still has an X over it.

With this underneath:

The video could not be loaded, either because the server or network failed or because the format is not supported.

Re: gorillavid.in / movpod.in / daclips.in

Posted: Sat Jul 15, 2017 8:00 am
by intense
I get no "X" over the video (using any set of filters)

Re: gorillavid.in / movpod.in / daclips.in

Posted: Sat Jul 15, 2017 8:06 am
by logi007
No idea what to tell you. All I know is I've been using the site through Vivaldi for over a year, never a problem until a few weeks ago. I dumped my entire filter set and imported the ones from Firefox. It works in Chrome, Comodo Dragon, Chrome Canary. Vivaldi just won't work. I even updated it earlier and I still don't get anything. This is all I get.

http://i.imgur.com/E8AWPfV.png

Re: gorillavid.in / movpod.in / daclips.in

Posted: Sat Jul 15, 2017 8:09 am
by logi007
Err never mind. JFC I'm a moron for not having noticed. Audio extension Audio EQ for Chromium based browsers somehow messes up video feeds. I recall this happening on Chrome stable two years ago until I removed it for the time being. I typically use it for Youtube videos that are way too quiet. Sorry.

But thank you for the forwarding filter!

Re: gorillavid.in / movpod.in / daclips.in

Posted: Sat Jul 15, 2017 8:11 am
by intense
Oh, good to know.

Re: gorillavid.in / movpod.in / daclips.in

Posted: Sat Jul 15, 2017 6:27 pm
by gotitbro
I was still on the video page. Only the URL changed and remained on the daclips.com domain.
[mention]logi007[/mention] As I mentioned in a post earlier (viewtopic.php?p=120875#p120875) the RoughTed domains redirect you to their own websites with an iframe of the URL you originally visited.

They probably do this to stop domain specific filters from working on such domains. The website owners (such as daclips.com) which have implemented such a dangerous and malware ridden technology on their domains do not care about the visitors, I would stay away from such websites unless really necessary.

Here is a list of some of the domains part of the RoughTed campaign.

If you want to read more about RoughTed, the original Malwarebytes report:
https://blog.malwarebytes.com/cybercrim ... lvertiser/

daclips.in

Posted: Mon Oct 02, 2017 12:25 am
by rc123
In shahneman.info ads are not blocked.

Example link:

Code: Select all

http://shahneman.info/Ulk1OEozO0ZMdScrWQUiJi1FHXkTfAd+b2AfUVkpPjBFS2Q7NxAKDDltBlo9My9RCy1qNA
 ! Message from: smed79
Removed your link links

Re: gorillavid.in / movpod.in / daclips.in

Posted: Mon Oct 02, 2017 1:28 am
by smed79
@rc123 You have been redirected from http://daclips.in/k43bwavd3g8m to http://shahneman.info/...
(Read about the anti adblock RoughTed malvertising campaign https://blog.malwarebytes.com/cybercrim ... lvertiser/)

Try

@@||acknowinge.info^$image,ping,xmlhttprequest,domain=daclips.in
or
@@.info^$image,ping,xmlhttprequest,domain=daclips.in

daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 6:55 pm
by aldiener
Hi,
Just starting today from http://ewatchseries.to/episode/queen_sugar_s1_e2.html,
I can choose any of the above referenced links and the same issue occurs.

For example, I choose http://ewatchseries.to/cale.html?r=aHR0cDovL2RhY2xpcHMuaW4vaG4weXAzaDR3Y2Zy and after CLICK HERE TO PLAY, CONTINUE, I end up here http://daclips.in/hn0yp3h4wcfr with a big X on the screen instead of a play button.

It has been a while since I have posted here so I hope what I have shared is helpful.

Thank you for your time and effort to resolve my issue.

Warmly,
Amy

I am currently using
UBO 1.14.12
Chrome Version 61.0.3163.100 (Official Build) (64-bit)

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:17 pm
by intense
It seems the file was missing in your example.

I tried this episode http://gorillavid.in/ynhl7pcx0bt4 and (after a delay of 15 - 30 seconds with sound starting first) the video started as well

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:28 pm
by aldiener
Thank you for your quick response @[mention]intense[/mention]
Are you saying that when I get an X it means the file is missing?

I appreciate your time and clarity.

Warmly,
Amy

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:31 pm
by aldiener
On this page http://ewatchseries.to/episode/queen_sugar_s1_e3.html, if I choose either gorillavid.in link,
(http://gorillavid.in/pd3onguxc33m or http://gorillavid.in/xeaqgk5ohb97), I get an X.

Any thoughts?

Warmly,
Amy

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:32 pm
by intense
Another thing in chrome: you should check if flash player is enabled for that page / domain.
See the address bar , click that i you see there (on the left of the address), flash, click "ask..." and choose "always allow for this site"

https://i.imgur.com/OhndciL.png

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:36 pm
by intense
the first link should load this video (mp4 file)
http://50.7.164.202:8182/wkorrl7wqwu4tqukw253hsbvkl4j2szpwuwhne5nfzctsv5cjvqjkq2fmu/video.mp4

even disabling completely uBo the result is: No File

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:47 pm
by aldiener
Thank you [mention]intense[/mention]. I made the change to flash. I did not get the first link to load anything but I believe you.

I appreciate your help.

Warmly,
Amy

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:49 pm
by intense
Did you test the link I posted above ?
http://gorillavid.in/ynhl7pcx0bt4

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:53 pm
by aldiener
No, I tried mine. Now I tried yours and it worked perfectly. I regret the confusion and appreciate your patience.

Warmly,
Amy

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Oct 19, 2017 7:57 pm
by intense
Well, from now you'll have to do the same maneuver (enabling flash) for all the video sites still using flash. It's due to the new chrome version (62) arrived yesterday (and google who wants to dismiss this type of crappy player)

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Nov 15, 2018 6:47 pm
by aldiener
Hi,
I am having new issues on the above referenced websites.

An example is https://movpod.in/bh01zx5ziekq The media plays for a second
and then I get an X on the screen. I am not sure if this is an EasyList Forum issue
but I thought I would check.

This seems to occur on the gorillavid.in and daclips.in as well.

Thank you for your time and support in this matter.

Sincerely,
Amy Diener

UbO ver 1.17.0
Google Chrome Version 70.0.3538.77 (Official Build) (64-bit)

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Nov 15, 2018 8:57 pm
by smed79
Hi,
aldiener wrote:I am not sure if this is an EasyList Forum issue
Disable EasyList or your adblock then test.

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Nov 15, 2018 9:32 pm
by aldiener
Thank you for your response @smed79 .

I have disabled UbO and I am still getting the same result :-)

Any other advice and support would be appreciated.

Sincerely,
Amy

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Nov 15, 2018 9:47 pm
by intense
No issue with your example @aldiener https://movpod.in/bh01zx5ziekq
FF / chrome => working fine

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Nov 15, 2018 10:48 pm
by smed79
Not working for me. The video stop after 3 seconds https://i.imgur.com/MOBlTt4.png

@aldiener You can play the video in VLC, just drag-and-drop the media link to the video player https://imgur.com/a/WgHdhs9

Re: daclips.in / gorillavid.in / movpod.in

Posted: Thu Nov 15, 2018 11:50 pm
by aldiener
Thank you @intense and @smed79 for your responses.

@intense if you have suggestions on how I can make this work in Chrome, I would be grateful.

@smed79 , I can't figure out how to display the web page in a format that I can drag to VLC. Can you tell me how
you accomplished that? I hope this makes sense :-)

Sincerely,
Amy

Re: daclips.in / gorillavid.in / movpod.in

Posted: Fri Nov 16, 2018 1:58 am
by smed79
aldiener wrote: Thu Nov 15, 2018 11:50 pm I can't figure out how to display the web page in a format that I can drag to VLC. Can you tell me how
you accomplished that?
:idea:
ABP
- right click on page, click inspect (or press Ctrl-Shift-I)
- click on the new "Adblock Plus" tab and filter the media file
- refresh the page, press F5 (or Ctrl-R)
- drag-and-drop the media link to VLC (or right click to copy then Ctrl-v to past the link in VLC)

uBo
- use the logger to filter media request
- copy the full media url then past it in VLC
- demo https://imgur.com/a/vxByjHs

Re: daclips.in / gorillavid.in / movpod.in

Posted: Fri Nov 16, 2018 7:57 am
by intense
right, after 3 seconds stops again.

It's a site issue, even disabling my adblocker it's the same issue.

Even running directly the media file:
https://uranium.gorillavid.in:8182/7gorxtc4rcu4tqukwydlhdlbiebh7pw4qof4d2cfplnmm55fjoe4snaeoa/video.mp4

So, nothing to do.

Re: daclips.in / gorillavid.in / movpod.in

Posted: Fri Nov 16, 2018 9:29 am
by aldiener
Thank you @smed79 and @intense for your ongoing efforts!

I am especially grateful @smed79 for your demos :-)

Sincerely,
Amy

Re: daclips.in / gorillavid.in / movpod.in

Posted: Fri Nov 16, 2018 11:37 am
by smed79
intense wrote: Fri Nov 16, 2018 7:57 amSo, nothing to do.
Tested again the media file url in VLC ==> 25 minutes non stop https://i.imgur.com/v21nZEH.png