openload.co trojan detected on some vids

Everything about using Adblock Plus on Mozilla Firefox, Thunderbird and SeaMonkey
Locked
mariusica77
Posts: 14
Joined: Fri Nov 25, 2016 8:21 am

openload.co trojan detected on some vids

Post by mariusica77 »

Since a couple of weeks ago, some openload vids open a trojan (as far as Avast is concerned).
Recent example: openload.co/f/YMbbHpD8YsI/Mom.S04E05.720p.HDTV.X264-DIMENSION.mkv
Subscriptions (updated today): EasyList, EasyPrivacy, Malware Domains, Adblock Warning Removal List, Fanboy's Social Blocking List
ABP version: 2.8.2

I search before and no filter posted here for openload in the last weeks helped.
Thanks in advance.
User avatar
mapx
Posts: 21940
Joined: Thu Jan 06, 2011 2:01 pm

Re: openload.co trojan detected on some vids

Post by mapx »

add

Code: Select all

||openload.co/*license
||openload.co/*packed
@@|https://5*.net/*.js|$domain=openload.co
@@|https://4*.net/*.js|$domain=openload.co
Katarina
Posts: 1
Joined: Fri Nov 25, 2016 9:09 am
Contact:

Re: openload.co trojan detected on some vids

Post by Katarina »

yeah, openload seems to use quite nasty popups. shame really, as i like the quality of their videos.
mariusica77
Posts: 14
Joined: Fri Nov 25, 2016 8:21 am

Re: openload.co trojan detected on some vids

Post by mariusica77 »

Thanks so much, mapx!
That did the trick.
mariusica77
Posts: 14
Joined: Fri Nov 25, 2016 8:21 am

Re: openload.co trojan detected on some vids

Post by mariusica77 »

Unfortunately it didn't work for all.
New example:

Code: Select all

https://openload.co/f/kMNUXR1ixm4/walliams.and.friend.s01e01.720p.hdtv.x264-moritz.mkv
How can I debug those that still trigger the antivirus and adapt the filter?
User avatar
smed79
Posts: 1224
Joined: Thu Jan 14, 2010 11:51 pm
Location: EasyList Forum
Contact:

Re: openload.co trojan detected on some vids

Post by smed79 »

mariusica77 wrote:Unfortunately it didn't work for all.
keep only Adblock Plus enabled then test again.
User avatar
mapx
Posts: 21940
Joined: Thu Jan 06, 2011 2:01 pm

Re: openload.co trojan detected on some vids

Post by mapx »

You have to keep only 1 blocking addon: / extension: ABP. Disable / remove ghostery, disconnect, antivirus plugin in firefox, anti banner, etc.
mariusica77
Posts: 14
Joined: Fri Nov 25, 2016 8:21 am

Re: openload.co trojan detected on some vids

Post by mariusica77 »

With just ABP (I disabled Disconnect, uBlock Origin, then on further attempts also Adblock Plus Pop-up Addon) it's incredibly bad on clicking play on last video: popup/new ad window, Avast warning.
User avatar
mapx
Posts: 21940
Joined: Thu Jan 06, 2011 2:01 pm

Re: openload.co trojan detected on some vids

Post by mapx »

Disable also avast web shields or avast plugin in firefox, it interferes with ABP.
mariusica77
Posts: 14
Joined: Fri Nov 25, 2016 8:21 am

Re: openload.co trojan detected on some vids

Post by mariusica77 »

Having the issue again, this time Malwarebytes (trial mode) announces a trojan on most vids on openload.co (but not every day, just some times), blocked IP 104.16.168.50
Example openload.co/f/zczUs4KhTAQ/Engineering.Catastrophes.S02E02.Skyscraper.vs.Sinkhole.WEBRip.x264-CAFFEiNE.mkv
Anything I can block on the page to not do this ? Or it's the whole domain that is considered a Trojan-Miner ?
User avatar
mapx
Posts: 21940
Joined: Thu Jan 06, 2011 2:01 pm

Re: openload.co trojan detected on some vids

Post by mapx »

Malwarebytes and any other antivirus utility will detect way faster the threats, so you cannot do something using an adblocker.

For such sites just disable your security software and use a stronger adblocker (uBo - ublock origin).
User avatar
smed79
Posts: 1224
Joined: Thu Jan 14, 2010 11:51 pm
Location: EasyList Forum
Contact:

Re: openload.co trojan detected on some vids

Post by smed79 »

@mariusica77 Without disabling your security software you can add an exclusion to Malwarebytes

read
https://blog.malwarebytes.com/detections/openload-co/
https://support.malwarebytes.com/docs/DOC-1130

For for crypto-mining, subscribe to EasyPrivacy and NoCoin filter list from subscriptions
Locked