Skip to content

douban.com: popups #34456

Description

@crazytan

URL(s) where the issue occurs

https://www.douban.com/

Category

Malvertising popup/popunder; request to block upstream redirect/TDS domains.

Description

On 2026-09-10 at 23:42:20 America/Los_Angeles (UTC-7), approximately five seconds after loading and logging into the Douban home page, a separate tab opened without an intentional external navigation. Firefox history records this chain over about two seconds:

https://erro.club/s/index/<uuid>
  -> https://diiep.io/f/index/<same-uuid>
  -> https://mercu-wgp.com/zokvisitor/<visit-id>/<id>?campaignid=<campaign-id>
  -> https://mercu-wgp.com/zokredirect?visitid=<visit-id>&type=js&browserWidth=...&browserHeight=...&iframeDetected=false&webdriverDetected=false&gpu=...&timezone=...&timezoneName=America/Los_Angeles
  -> https://cf.post-court.site/middle.html?impId=<id>&ct=<token>
  -> https://cf.post-court.site/api/v1/px2?ct=<token>&minfo=<base64-browser-fingerprint>
  -> http://xml-v4.riseskydove.online/click?i=<id>&seat=<id>

uBO strict-blocked the final URL with the existing uBlock filters - Badware risks filter:

://xml-v4.*.online/click?$document

The existing filter protects the final hop, but the preceding redirectors have already loaded and collected browser-fingerprinting fields by then.

This was not isolated. Firefox history records the same stable upstream pair on 2026-06-11 at 19:24:47 America/Los_Angeles, again approximately five seconds after reloading https://www.douban.com/:

https://erro.club/s/index/<different-uuid>
  -> https://diiep.io/f/index/<same-uuid>
  -> https://berht-shv.com/zokvisitor/<visit-id>/<id>?campaignid=<campaign-id>

The repeated erro.club -> diiep.io entry chain on two independent dates, followed by rotating zokvisitor infrastructure, looks like an intermittent malicious ad creative or compromised programmatic-ad path on Douban.

I searched the current uAssets tree, EasyList repository, and open/closed uAssets issues. None of these exact upstream domains are currently present or previously reported. Only the generic final-hop pattern above is covered.

Suggested Badware filters for maintainer review:

||erro.club^$all
||diiep.io^$all
||mercu-wgp.com^$all
||berht-shv.com^$all
||post-court.site^$all

riseskydove.online currently does not resolve and is already covered at the observed path by the generic xml-v4.*.online/click rule, so I am not proposing a redundant domain filter for it.

I did not deliberately replay the malicious chain with protections or other extensions disabled. The event is intermittent, and reproducing it would require removing the newly added local blocks and waiting for a potentially malicious ad. The report is based on Firefox's persisted visit graph and the uBO strict-block page. I can provide the full unredacted redirect URLs privately if a maintainer needs the campaign/visit identifiers.

Browser and extensions

  • Firefox 155.0.1 on macOS
  • uBlock Origin 1.74.0
  • Other enabled extensions at the time: ClearURLs 1.27.3, KeePassXC-Browser 1.10.3, Greasemonkey 4.14 (no installed userscripts)
  • Firefox Enhanced Tracking Protection: Strict
  • uBO default lists were enabled; no lists were removed

Screenshot

A screenshot exists, but the initial capture included unrelated private browsing-history entries, so it has not been uploaded publicly. The essential blocked-page details are transcribed above. A sanitized screenshot can be supplied if required.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions