URL(s) where the issue occurs
Category
Malvertising popup/popunder; request to block upstream redirect/TDS domains.
Description
On 2026-09-10 at 23:42:20 America/Los_Angeles (UTC-7), approximately five seconds after loading and logging into the Douban home page, a separate tab opened without an intentional external navigation. Firefox history records this chain over about two seconds:
https://erro.club/s/index/<uuid>
-> https://diiep.io/f/index/<same-uuid>
-> https://mercu-wgp.com/zokvisitor/<visit-id>/<id>?campaignid=<campaign-id>
-> https://mercu-wgp.com/zokredirect?visitid=<visit-id>&type=js&browserWidth=...&browserHeight=...&iframeDetected=false&webdriverDetected=false&gpu=...&timezone=...&timezoneName=America/Los_Angeles
-> https://cf.post-court.site/middle.html?impId=<id>&ct=<token>
-> https://cf.post-court.site/api/v1/px2?ct=<token>&minfo=<base64-browser-fingerprint>
-> http://xml-v4.riseskydove.online/click?i=<id>&seat=<id>
uBO strict-blocked the final URL with the existing uBlock filters - Badware risks filter:
://xml-v4.*.online/click?$document
The existing filter protects the final hop, but the preceding redirectors have already loaded and collected browser-fingerprinting fields by then.
This was not isolated. Firefox history records the same stable upstream pair on 2026-06-11 at 19:24:47 America/Los_Angeles, again approximately five seconds after reloading https://www.douban.com/:
https://erro.club/s/index/<different-uuid>
-> https://diiep.io/f/index/<same-uuid>
-> https://berht-shv.com/zokvisitor/<visit-id>/<id>?campaignid=<campaign-id>
The repeated erro.club -> diiep.io entry chain on two independent dates, followed by rotating zokvisitor infrastructure, looks like an intermittent malicious ad creative or compromised programmatic-ad path on Douban.
I searched the current uAssets tree, EasyList repository, and open/closed uAssets issues. None of these exact upstream domains are currently present or previously reported. Only the generic final-hop pattern above is covered.
Suggested Badware filters for maintainer review:
||erro.club^$all
||diiep.io^$all
||mercu-wgp.com^$all
||berht-shv.com^$all
||post-court.site^$all
riseskydove.online currently does not resolve and is already covered at the observed path by the generic xml-v4.*.online/click rule, so I am not proposing a redundant domain filter for it.
I did not deliberately replay the malicious chain with protections or other extensions disabled. The event is intermittent, and reproducing it would require removing the newly added local blocks and waiting for a potentially malicious ad. The report is based on Firefox's persisted visit graph and the uBO strict-block page. I can provide the full unredacted redirect URLs privately if a maintainer needs the campaign/visit identifiers.
Browser and extensions
- Firefox 155.0.1 on macOS
- uBlock Origin 1.74.0
- Other enabled extensions at the time: ClearURLs 1.27.3, KeePassXC-Browser 1.10.3, Greasemonkey 4.14 (no installed userscripts)
- Firefox Enhanced Tracking Protection: Strict
- uBO default lists were enabled; no lists were removed
Screenshot
A screenshot exists, but the initial capture included unrelated private browsing-history entries, so it has not been uploaded publicly. The essential blocked-page details are transcribed above. A sanitized screenshot can be supplied if required.
URL(s) where the issue occurs
https://www.douban.com/Category
Malvertising popup/popunder; request to block upstream redirect/TDS domains.
Description
On 2026-09-10 at 23:42:20 America/Los_Angeles (UTC-7), approximately five seconds after loading and logging into the Douban home page, a separate tab opened without an intentional external navigation. Firefox history records this chain over about two seconds:
uBO strict-blocked the final URL with the existing
uBlock filters - Badware risksfilter:The existing filter protects the final hop, but the preceding redirectors have already loaded and collected browser-fingerprinting fields by then.
This was not isolated. Firefox history records the same stable upstream pair on 2026-06-11 at 19:24:47 America/Los_Angeles, again approximately five seconds after reloading
https://www.douban.com/:The repeated
erro.club -> diiep.ioentry chain on two independent dates, followed by rotatingzokvisitorinfrastructure, looks like an intermittent malicious ad creative or compromised programmatic-ad path on Douban.I searched the current uAssets tree, EasyList repository, and open/closed uAssets issues. None of these exact upstream domains are currently present or previously reported. Only the generic final-hop pattern above is covered.
Suggested Badware filters for maintainer review:
riseskydove.onlinecurrently does not resolve and is already covered at the observed path by the genericxml-v4.*.online/clickrule, so I am not proposing a redundant domain filter for it.I did not deliberately replay the malicious chain with protections or other extensions disabled. The event is intermittent, and reproducing it would require removing the newly added local blocks and waiting for a potentially malicious ad. The report is based on Firefox's persisted visit graph and the uBO strict-block page. I can provide the full unredacted redirect URLs privately if a maintainer needs the campaign/visit identifiers.
Browser and extensions
Screenshot
A screenshot exists, but the initial capture included unrelated private browsing-history entries, so it has not been uploaded publicly. The essential blocked-page details are transcribed above. A sanitized screenshot can be supplied if required.