HOW TO PREVENT RECENT Sup Forums MALWARE SCRIPTS!

All you can do now is update uBlock's filter lists.

>What do we know so far
Variant of the Nemucod ransomware, Ukrainian URL of the new advertising that broke CSS on boards with it has a history of hosting it.
reverse.it/sample/b9a80ddbaf41d303b0ed9abb0f6aabf5f851dd39909aaead3cb3257474fd7dc4?environmentId=100
SAME. EXACT. HOST. SAME. EXACT. OBFUSCATION (minus the xoring)

>what can I do?

Wait until somebody finds out whether or not this has infected users.

>are you serious?

Yes, we have no idea what payload the scripts have installed on our systems.

FACT: If your uBlock doesn't look like pic related right now, you being affected as you read this.

Other urls found in this thread:

pastebin.com/raw/4Jm6G4gJ
pastebin.com/raw/28Lcd7KR
twitter.com/SFWRedditImages

bump original thread has a lot of content in it too
>inb4
>its harmless goyim
>oy bylat dont look into it goyim
>stop blocking it reeeeeeee

Adblock f/a/g here, i have zero to no Sup Forums knowledge. is it time to panic?

Bringing my post over:

I'm going to try and master post this to do some explaining. Hopefully this can serve as a "Read this" post.

Why things are fucked:
For reasons unknown, gookmoot adding 3 new domains to 4chans script list. We aren't sure what those domains are currently doing, but we think they are related to the serving of ads. It might be more, but that's all we know.

Gookmoot also implemented a script in Sup Forums that checks for script/adblocking addons and causes the CSS (the code that makes Sup Forums look like Sup Forums) to break. This is just cuntery.

Tools Affected:
uBlock Origin
Was updated to get rid of the CSS fucking script. Works well, but also causes ViolentMonkey and (maybe) TamperMonkey to break with Sup Forums-x. If your CSS is still fucked, go to the uBlock dashboard, filters and select purge and then update. Reload Sup Forums and it should work.

Sup Forums-x
The developer implemented some methods to unfuck the catalogue and work around some issues with Violent/TamperMonkey. If you're having issues, ensure you're running the latest version of Sup Forums-x.

GreaseMonkey
Continues to have issues injecting into iFrames. This means that captcha may not load for you if you're forcing V1 captcha and have google scripts blocked.

NoScript/uMatrix
Both are working fine. Simply set amgload.net, piguiproxy.com and smcheck.org to untrusted/blocked. This will kill those sites off. Then uBlock Origin will fix the breaking CSS script or Sup Forums-x will. You just need to pick which one you want.

We are reaching lostboy.exe levels of panic

replace adblock with ublock, that's the least you should do

I thought you couldn't post with disabled 3rd party scripts/frames?

yes
hiroshima added some new tracking scripts, google botnet is pretty much avoidable but site literally breaks if you block the new botnet

There's no "payload", stupid. It's just some shitty ukrainian ads.

you forgot admixer.net

lmao wut

I feel this will truly be the death of the website, how can anyone trust hiro or anyone else who works for this website again after this

I'm using this fix on chrome without 4chanX
pastebin.com/raw/4Jm6G4gJ
Is it outdated? Anything new/better that fixes everything without breaking the catalog?

>I thought you couldn't post with disabled 3rd party scripts/frames?

I am doing it right now. Nobody ever said this.

I'm using TamperMonkey, uBlock Origin and Sup Forums-X, I didn't update anything and didn't have any problem

I put a few URLs I got off an old OP in uBlock's filters. How do I do to block scripts and get on your page? I'm new to uBlock, I used AdBlock till I had to delete it because I couldn't browse some boards

I added a userscript to my google and another script to my UBlock and now there is no ad or no connection to any of these sites. Am I safe?

Using Greasemonkey, Sup Forums-x and Origin but themes are still not working unless s.4cdn.org Scrips are allowed via matrix.
Anyone have a work around to this? Obviously I could allow it but I'm unsure what else is going to come with it.

That is complete bullshit. Currently we have no idea whatsoever what has been loaded.

I haven't been able to replicate any of that bullshit on my system. It might be the case, but saying we know it so far is crap. Not a single one of my machines (VM or otherwise) is showing any symptoms or data leakage in the last 10 hours. I haven't had a single blip on my IDS/EDS and frankly, you shouldn't be spreading FUD.

No. See Probably this, but keep an eye on shit.

I haven't seen it as part of this issue, but can't hurt you to add it.

Sup Forums-x is a better solution imo, but your call.

Excellent to hear. This means you came on after your uBlock install had updated it's blocklist/configurations. Those of us that loaded up before we worked out what was going on were exposed to some stuff (maybe). You're in the clear.

Have a look at uMatrix addon. It's where you should start if you want to block scripts.

I don't see slav shit, only google spying on me as usual
I am fine.
My uMatrix chage basically everytime i open a thread and had to keep doing tinfoil changes, got bit tired of that

>Currently we have no idea whatsoever what has been loaded.

That's what the OP is saying. We have literally no idea if we have been compromised by these new scripts.

>Common sense is the best answer. You should be fine, just keep an eye out of unusual activity.
I was just curious. I have 40 tabs of chrome open which take about 8 GB of memory.
It's probably because I have half a dozen extensions in addition to the bloat of Chrome and uBO/uMatrix.

so this is what happens when net neutrality gets repealed in united states.

Yes!

lr2n to noop rule

a man buys Sup Forums
keeps trying to find ways for the site to pay its money
has google botnet no one bats an eye
has another third party botnet PEOPLE RIOTS

i mean eventually you gonna have to accept that this site NEEDS income and money doesnt come from unicorns and none of you will accept monero running so...

shit I screwed up this meme

Install gentoo

Install Sup Forums-x. That's why people are telling you that you don't need s.4cdn.org scripts. I have themes without it, and the less shit I get from Sup Forums, the better.

He starts off saying What we know, then mentions the ransomware. If that's what he's trying to say, he's fucked it right up.

Sounds pretty light for that many tabs. If in doubt, restart your PC and check memory usage when you re-open Chrome.

No.

I suspect we'd be more accepting if it wasn't heavily obfuscated, out of the blue with no communication and some dodgy behaviour. You're not wrong though..

Yeah you did.

for guhnoo slash loonix users who want to block the traffic directly:
>install dnsmasq
>edit /etc/dnsmasq.conf
>add entries for domains to be blocked
>address=/amgload.net/127.0.0.1
>address=/piguiqproxy.com/127.0.0.1
>address=/smcheck.org/127.0.0.1
>save
>restart network manager or computer
>all traffic to those domains now directed to localhost
doing it through the hosts file does not handle wildcard subdomains so this method will take care of it

>Install Sup Forums-x
I have Sup Forums-x.

No nemu code found so far but stuff that wasn't here yesterday.

Well then, you've got something else screwy, because pic related and I'm posting just fine.

Guys please have pity on a clueless retard, I've done everything I've read on here and my Sup Forums still looks like pic related, I've reinstalled all the programs, I've got tampermonkey running the Sup Forums anti cancer script, ublock has the 3 sites filtered and 4chanx is updated, Ibut it's still broken unless ublock is disabled, I jut want my home back

There are other sources of income rather than ads which serve malware. Which have been effecting mobile users for some months now.

Suddenly domains known to serve malware infested ads are added to Sup Forums? And gookmoot intentionally breaks the CSS for anyone running an adblocker making the site basically unusable unless disabled? Yeh nah. While there may be "nothing" yet, the gook is setting shit up.

Are there any confirmed encrypted machines yet?

Cancer averted !!

Thanks Sup Forums for that script and making me live longer.

that and the massive amount of posters saying there's nothing to worry about

I choose not to load tracking scripts and malvertising scripts on my browser, Jew.

>ublock settings
>"My Filters"
>add Sup Forums.org##script:inject(abort-current-inline-script.js, String.fromCharCode)
>save
youre welcome

>Which have been effecting mobile users

who even cares

>tfw thought I was about as tech-savvy as a dead bonobo but I see all these people in these threads casually using the Internet without uBlock or uMatrix or even fucking knowing that they exist

I am late to this. Should i be concerned or i am already too late? Using Ublock origin with most filter enabled. Not using any specific dns filtering though.

It's not showing up for me even if I disable everything, it's not coming from Sup Forums. All of the screenshots I see showing it are using Firefox.

i dont understand the "break CSS" shit

i am running adblocker eversince and never had problems with the display

then again i'm dumbanon

Nice Mokou

this breaks 4chanx

Haha, I use Clover App :>)

yeah please tell me who is going to give its ad on Sup Forums after being publicly assosiated with neo nazi shit from the media?

the site is pretty much dead there arent many alternatives to bring income

>Disable everything
But why? Why are you doing this for us?

you can blame clueless retards like OP saying RANSOMWARE PAYLOAD!!! for that

Tuns out theres a varient of nemucod that clicks on ads. Fucker is adbotting

>using windows
Sage hide report get fucked and aids.

Can somebody help me? My uBlock filters are not properly updating, even after purging caches and reinstalling the extension. I had to add the line to my filters manually.

I'm using the uBlock 1.14.22 on FF 52 ESR on Win7, but it updated fine on my Debian laptop with the same browser and uBlock version. I've had NoScript running all the time and I've never allowed the cancer scripts to run. Any ideas?

ENOUGH
Oy bylat goyim, there is absolutely nothing to worry about, you are just running state sponsored foxacid.

There's definitely a fair amount of data being sent to and received from those shady domains through XHR. Because both the data and the script itself are obfuscated as fuck, we don't really know what it is exactly, but it's that level of obfuscation that makes me suspect something highly cancerous. Even if it were "just some shitty ukrainian ads" sent to the client, there still a question of what is sent from it.

I repeat my question from the earlier thread: does anyone work on reverse-engineering this shit?

Maybe they're from other boards but there's also a dumbass who thinks using ublock makes you a redditor.

Phone user don't have any problem

>Have a look at uMatrix addon. It's where you should start if you want to block scripts.
uMatrix really got on my nerves. Couldn't post or aggrandize images probably because it blocked even the friendly 4ch scripts. Is it necessary to have it like OP's image?

May your road lead you to warm sands my friend

Why not just start a fucking patreon? I'd donate $5 a month if it meant I had a place to spend my neet hours

a gentleman's settings

this solves nothing, it even breaks shit for people that as much as partially have a better solution. stop posting this.

close tabs, clear browser data, purge ublock caches, enable all filters, update manually

i dont use it. i know the solution i gave works fine the old fashioned way though

>Who would want to advertise on a website that sees more traffic than most social media outlets

Its definitely coming from FireFox.

Should i really use Umatrix? I thought Ublock medium mode is enough?

Go to uBlock Dashboard -> Filters -> Purge + Update.

Clear your browser cache. Restart, re-open. Should all be fine desu.

If that doesn't work, do what this guy said None that I've seen. Hasn't hit any of my testing machines either.

I fucking know.. It's "I don't know so I want even fucking try" bullshit..

You're probably fine. If your Sup Forums isn't looking fucked, you're probably fine.

Seeing it on Chrome too.

It's that you came in late. There are other people who were on earlier prior to the tools updating to fix it.

Only with ViolentMonkey and some TamperMonkey versions. But yes.

This. Motherfucking tards.

There are a couple of us, but it takes time and a lot of it is wait and watch currently.

No it's not, but it's safer. Go into uBlock and enable Advanced mode. Restart your browser.

Thanks.

Still no.

>>Who would want to advertise on a website that sees more traffic than most social media outlets

>who would want its company being assosiated with neo nazi shit from Sup Forums ?

>i dont understand the "break CSS" shit

Page loads.
Inline-script runs.
Inline-script tries to communicate with random domains.
[My] umatrix blocks it.
Inline-script says fu and changes the page css to give you a white background, black text and no images. (You know it's done this because the page has normal styling for a third of a second before the style is changed.)

Thanks, it werked for me. Not a Sup Forums-x user, tho

I just used and it's fixed it for me, and I'm using 4chanx, before the pages wouldn't load normally at all, now everything seems to be back to normal

It's not uBlock, it's uMatrix.

is this cause my battery laptop deplete quickly? I use adblock.

I added these to my uBlock and Tampermonkey, am I good?

pastebin.com/raw/28Lcd7KR

pastebin.com/raw/4Jm6G4gJ

click on requests blocked
if you want to block all scripts and shit, go to dashboard and activate advaced settings

do we know which script does it?

I just replaced adblock with ublock and now the ads at the bottom are gone. Am I safe?

Nigger I see Amazon adds on fucking Pornhub, where ads get served is not necessarily who they get served by.

Even then, we've had that JShop shit down there for years.

this is ublock though

Everything looks the same to me. i did not notice anything/ads. I am just using ublock origin easy mode not even medium. What is this about?

These threads are some granny-tier shit, Gen Z fags out.

When I open a thread in another tab it just shows a white page or maybe it'll have just the board listing, but when I load it while I am actually tabbed into the page then it loads okay. What gives?

clearing your browser cache resets the ublock filters because they are saved in localstorage, so you can't do it in that order.

Is Sup Forums this tech-illiterate these days?

Every script you run on Windows will touch wscipt files

Also if you take a look at argon.js report, you'll see that it crashes on line 1 character 1. It literally doesn't run.

I did this too and I'm not seeing more these ads. Are we good?

This is really weird though
Maybe someone hacked into Sup Forums again?

fuck off back to Sup Forums and stay there forever

Stop posting this filter, it was superseded. gorhill fixed 4chanx breakage.

Remove every manual Sup Forums related filter you entered and just purge and update ublock filters.

Mmm xmr

>There is nothing to worry about
>It's all just a larp
>melting into acid

I was using Adblock Plus and Sup Forums without https when I used the site today. I deleted a week of cookies and had a good virus scan on Malwarebytes, I should be safe right?

you miss the point and thats why you dont understand shit

not a single company wants to assosiate their brand with Sup Forums because the society is a literall sjw
and since money always talks no seriously or nonshady companies will ever get their names here
fact is its either another botnet to track us or monero intergrated on the framework or Sup Forums dies

Why the fuck is everyone doing so much shit
Isn't uBlock and it's latest filters enough?

>using ublock makes you a redditor

>using windows and not ubuntu, you're a redditor
>using firefox and not chromium, you must be a redditor
>i'm such an oldfag i was there when moot hacked the site with little hats on each posts
>you make spaces between your paragraphs, you must be a redditor
Not kidding, I got all of those answered to me at one time or the other.

"Tech journalists" here say pretty much the same thing.
One cunt went on a TV documentary about Internet culture and said -and I quote -
>"i am such an oldfag i was here for the pewdiepie scandal"

Holier than thou, ib version.

Under settings, enable advanced mode.

Dude..

Yeah, depending on which of your addons are up to date/lists are up to date, you can have varying outcomes. That's the biggest problem, it's why we are all pushing people to update everything.

We do, per what he said, it's inline (delivered as part of the HTML markup. That's why you need addons to fix it.

You should be.

It is, that guys a tard.. Just need advanced mode enabled.

Well, we all saw the issue, contacted the uBlock/List maintainers, and they pushed fixes out. So in the 10 hours or whatever since this started, the updates wen tlive and you never saw it. That's literally it.

I did not know that. I'll amend in future instructions. Cheers.

No, there are a lot of people spilling in from other boards with the same issues.

You should be.

No, this was definitely by management..

I didn't post it. I just said if he's still fucked to try it. That would be because he isn't on the latest uBlock yet. So, thanks I think..

If I put my settings like that then it breaks even more for me.
I do however have the anti-cancer script from last night. Not sure that will do anything to the themes though.

ublock already updated the filter list. If you want to be sure, check the logger or dynamic filtering pane.

>or Sup Forums dies
Sup Forums died a long time ago and you know that m80.
This place was downhill post 2009

howdio i gopen ch4an,.]\\\\,,,,,

thanks

faggots look add this to your ublock

people shouldn't have manually added filters after gorhill curbstomped chinkmoot's nigger script