Reporting popup/scam ads on mobile devices

Help Discussion in 'BeerAdvocate Talk' started by pagriley, Dec 31, 2015.

Thread Status:
Not open for further replies.
  1. pagriley

    pagriley Pooh-Bah (2,382) Oct 27, 2014 Illinois
    Pooh-Bah Trader

    I tend to use the site on my android phone (not the ap) and have been getting a "congratulatuons-lottery-2016" pop up that also buzzes my phone. It seems to only happen on BA, and the suggestion from a techy buddy was it might be the advertising package on BA causing it.

    Anyone else getting this? Only started in the last 24 hours. I have cleared the cache, run a virus scan etc... And it doesn't seem to be something on my phone, but it could well be.
     
    machalel and HectorB like this.
  2. pagriley

    pagriley Pooh-Bah (2,382) Oct 27, 2014 Illinois
    Pooh-Bah Trader

    [​IMG]

    This is what I am getting. Comes up every 5 or so minutes so it is super annoying
     
  3. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    Nasty 3rd party ads that don't obey our ruleset happens. I'll see if I can add the domain to our blocked list. Thanks.
     
  4. pagriley

    pagriley Pooh-Bah (2,382) Oct 27, 2014 Illinois
    Pooh-Bah Trader

    Cool, thanks!
     
  5. HopBroker

    HopBroker Savant (1,158) Jun 5, 2015 Washington
    Trader

    I get this all the time! Not the exact same website but very very similar. Opens a new tab with a pop up. Never even considered it could be BA. Still convinced it could be the sketchy mp3 downloaded I have so...
     
  6. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    It's not BA, per se, but a 3rd party ad being loaded when viewing the site. And they keep on changing their base URL, making them hard to track.
     
  7. pagriley

    pagriley Pooh-Bah (2,382) Oct 27, 2014 Illinois
    Pooh-Bah Trader

    Thanks for looking into it. It is still happening, so I guess they are being super sneaky douche bags with their URL - appreciate you guys trying to fix!
     
  8. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    I've finally managed to get screenshots of the ad, link and redirected links. I've also added the domains to our block filters and sent a report to our ad server techs. Updates to follow.
     
  9. stakem

    stakem Grand Pooh-Bah (4,070) Feb 20, 2009 Pennsylvania
    Pooh-Bah Trader

    Posting some links and screen caps that ive been getting lately too.

    [​IMG]

    when I try to click the "X" to close the popup, it redirects me to the app store to download what i assume is something malicious

    this is the link i copied from the browser when it popped up, looks kinda worthless to me but maybe someone more in the know can make sense of it:

    data:text/html;base64,PCFET0NUWVBFIGh0bWw+PGh0bWw+PGhlYWQ+PGxpbmsgaHJlZj0iaHR0cDovL2Nkbi5yYXdnaXQuY29tL25vZWxib3NzL2ZlYXRoZXJsaWdodC8xLjMuNC9yZWxlYXNlL2ZlYXRoZXJsaWdodC5taW4uY3NzIiB0eXBlPSJ0ZXh0L2NzcyIgcmVsPSJzdHlsZXNoZWV0Ii8+PHN0eWxlIHR5cGU9InRleHQvY3NzIj4uZml4d2lkdGggLmZlYXRoZXJsaWdodC1jb250ZW50e21pbi13aWR0aDogODAlO30uZml4d2lkdGggLmZlYXRoZXJsaWdodC1jbG9zZS1pY29ue3JpZ2h0OiA5MHB4OyBiYWNrZ3JvdW5kLWNvbG9yOiB0cmFuc3BhcmVudDt9PC9zdHlsZT48L2hlYWQ+PGJvZHk+IDxzY3JpcHQgdHlwZT0iYXBwbGljYXRpb24vamF2YXNjcmlwdCIgc3JjPSJodHRwOi8vY29kZS5qcXVlcnkuY29tL2pxdWVyeS0xLjEwLjIubWluLmpzIj48L3NjcmlwdD4gPHNjcmlwdCB0eXBlPSJhcHBsaWNhdGlvbi9qYXZhc2NyaXB0IiBzcmM9Imh0dHA6Ly9mdGxhYnMuZ2l0aHViLmlvL2Zhc3RjbGljay9saWIvZmFzdGNsaWNrLmpzIj48L3NjcmlwdD4gPHNjcmlwdCBzcmM9Imh0dHA6Ly9jZG4ucmF3Z2l0LmNvbS9ub2VsYm9zcy9mZWF0aGVybGlnaHQvMS4zLjQvcmVsZWFzZS9mZWF0aGVybGlnaHQubWluLmpzIiB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiIGNoYXJzZXQ9InV0Zi04Ij48L3NjcmlwdD4gPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPiQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCl7dmFyIGV4ZWN1dGVkPWZhbHNlOyAkKGZ1bmN0aW9uKCl7RmFzdENsaWNrLmF0dGFjaChkb2N1bWVudC5ib2R5KTt9KTsgZG9jdW1lbnQuYWRkRXZlbnRMaXN0ZW5lcignY2xpY2snLCBmdW5jdGlvbihlKXtpZiAoIWV4ZWN1dGVkKXt3aW5kb3cub3BlbigiaHR0cDovL3RyYWNraW5nLnBhZHNydi5jb20vZjg1ZDdkY2MtZDhiOC00NGRkLWFjNzgtOTljYmRjZTFkOTNlP2FmZl9zdWIyPTQ5YjFhYzc3LTQyNGYtNDRiYi1iYjZjLWNkMzM3ZjQyNDRlZiZhZmZfc3ViMz1QT0NLRVRNQVRILU9QRU5YJmFmZl9zdWI0PTcyOHg5MCIpOyBzZXRUaW1lb3V0KGZ1bmN0aW9uKCl7d2luZG93Lmhpc3RvcnkuYmFjaygpO30sIDMwMDApOyBleGVjdXRlZD10cnVlO313aW5kb3cub250b3VjaG1vdmU9bnVsbDt9LCBmYWxzZSk7IHdpbmRvdy5vbnRvdWNobW92ZT1wcmV2ZW50RGVmYXVsdDsgc2V0VGltZW91dChmdW5jdGlvbigpe3dpbmRvdy5vbnRvdWNobW92ZT1udWxsO30sIDE1MDAwKTsgJC5mZWF0aGVybGlnaHQoJ2h0dHA6Ly9jZG4uYWRzZXJ2ZXJ0ci5jb20vVlpfMzIweDQ4MC5qcGVnJyx7Y2xvc2VPbkVzYzogZmFsc2UsIG9wZW5TcGVlZDogNzAwLCB2YXJpYW50OiAnZml4d2lkdGgnLCBjbG9zZUljb246ICc8aW1nIHNyYz0iaHR0cDovL2RhdGEuc3VwbG94LmluZm8vZGVmYXVsdC9jbG9zZU1hcC5wbmciIHN0eWxlPSJXSURUSDo1MDAlOyBIRUlHSFQ6NTAwJSI+PC9pbWc+J30pO30pOyBmdW5jdGlvbiBwcmV2ZW50RGVmYXVsdChlKXtlPWUgfHwgd2luZG93LmV2ZW50OyBpZiAoZS5wcmV2ZW50RGVmYXVsdCkgZS5wcmV2ZW50RGVmYXVsdCgpOyBlLnJldHVyblZhbHVlPWZhbHNlO308L3NjcmlwdD48L2JvZHk+PC9odG1sPiI=
     
  10. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    @stakem Without a standard link / domain it'll be impossible to look into this.
     
  11. stakem

    stakem Grand Pooh-Bah (4,070) Feb 20, 2009 Pennsylvania
    Pooh-Bah Trader

    Gotcha.

    It just happened again when I went to view someone's beer want list. Instead of closing it immediately, I let it load and copied this other link. Sorry if its no help but its slightly different from what I posted earlier.

    Words With Friends by Zynga Inc. https://appsto.re/us/kWD8V.i
     
  12. stakem

    stakem Grand Pooh-Bah (4,070) Feb 20, 2009 Pennsylvania
    Pooh-Bah Trader

    Another this morning with a different url that actually displayed a prompt asking if it was ok to open in the app store:
    qhrzj.redirectvoluum.com
     
  13. stakem

    stakem Grand Pooh-Bah (4,070) Feb 20, 2009 Pennsylvania
    Pooh-Bah Trader

    got a different image popup this morning. when i clicked to close it, i saw this url before it redirected to the app store:

    23980.api-03.com


    @Todd if none of this is helpful, please tell me and ill stop posting
     
  14. StoutSnob40

    StoutSnob40 Grand Pooh-Bah (4,611) Jan 4, 2013 California
    Society Pooh-Bah Trader

    I've been getting them all morning. I'll screenshot when I can.
     
  15. stakem

    stakem Grand Pooh-Bah (4,070) Feb 20, 2009 Pennsylvania
    Pooh-Bah Trader

    2 different ones popping up this morning:

    ads.glispa.com
    control.kochava.com
     
  16. StoutSnob40

    StoutSnob40 Grand Pooh-Bah (4,611) Jan 4, 2013 California
    Society Pooh-Bah Trader

    This is still happening, btw.
    [​IMG]
     
  17. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    @dwagner003 As previously mentioned, we can't do anything about it if you don't provide us the originating domain.
     
  18. StoutSnob40

    StoutSnob40 Grand Pooh-Bah (4,611) Jan 4, 2013 California
    Society Pooh-Bah Trader

    Not sure what that means, but here is the link..?
    data:text/html;base64,PCFET0NUWVBFIGh0bWw+PGh0bWw+PGhlYWQ+PGxpbmsgaHJlZj0iaHR0cDovL2Nkbi5yYXdnaXQuY29tL25vZWxib3NzL2ZlYXRoZXJsaWdodC8xLjMuNC9yZWxlYXNlL2ZlYXRoZXJsaWdodC5taW4uY3NzIiB0eXBlPSJ0ZXh0L2NzcyIgcmVsPSJzdHlsZXNoZWV0Ii8+PHN0eWxlIHR5cGU9InRleHQvY3NzIj4uZml4d2lkdGggLmZlYXRoZXJsaWdodC1jb250ZW50e21pbi13aWR0aDogODAlO30uZml4d2lkdGggLmZlYXRoZXJsaWdodC1jbG9zZS1pY29ue3JpZ2h0OiA5MHB4OyBiYWNrZ3JvdW5kLWNvbG9yOiB0cmFuc3BhcmVudDt9PC9zdHlsZT48L2hlYWQ+PGJvZHk+IDxzY3JpcHQgdHlwZT0iYXBwbGljYXRpb24vamF2YXNjcmlwdCIgc3JjPSJodHRwOi8vY29kZS5qcXVlcnkuY29tL2pxdWVyeS0xLjEwLjIubWluLmpzIj48L3NjcmlwdD4gPHNjcmlwdCB0eXBlPSJhcHBsaWNhdGlvbi9qYXZhc2NyaXB0IiBzcmM9Imh0dHA6Ly9mdGxhYnMuZ2l0aHViLmlvL2Zhc3RjbGljay9saWIvZmFzdGNsaWNrLmpzIj48L3NjcmlwdD4gPHNjcmlwdCBzcmM9Imh0dHA6Ly9jZG4ucmF3Z2l0LmNvbS9ub2VsYm9zcy9mZWF0aGVybGlnaHQvMS4zLjQvcmVsZWFzZS9mZWF0aGVybGlnaHQubWluLmpzIiB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiIGNoYXJzZXQ9InV0Zi04Ij48L3NjcmlwdD4gPHNjcmlwdCB0eXBlPSJ0ZXh0L2phdmFzY3JpcHQiPiQoZG9jdW1lbnQpLnJlYWR5KGZ1bmN0aW9uKCl7dmFyIGV4ZWN1dGVkPWZhbHNlOyAkKGZ1bmN0aW9uKCl7RmFzdENsaWNrLmF0dGFjaChkb2N1bWVudC5ib2R5KTt9KTsgZG9jdW1lbnQuYWRkRXZlbnRMaXN0ZW5lcignY2xpY2snLCBmdW5jdGlvbihlKXtpZiAoIWV4ZWN1dGVkKXt3aW5kb3cub3BlbigiaHR0cDovL3RyYWNraW5nLnBhZHNydi5jb20vZjg1ZDdkY2MtZDhiOC00NGRkLWFjNzgtOTljYmRjZTFkOTNlP2FmZl9zdWIyPTZiMjA4ZWY5LTVmYmYtNGJmZS04ODU4LTFjNmM1NjAyMDExOCZhZmZfc3ViMz1QT0NLRVRNQVRILU9QRU5YJmFmZl9zdWI0PTcyOHg5MCIpOyBzZXRUaW1lb3V0KGZ1bmN0aW9uKCl7d2luZG93Lmhpc3RvcnkuYmFjaygpO30sIDMwMDApOyBleGVjdXRlZD10cnVlO313aW5kb3cub250b3VjaG1vdmU9bnVsbDt9LCBmYWxzZSk7IHdpbmRvdy5vbnRvdWNobW92ZT1wcmV2ZW50RGVmYXVsdDsgc2V0VGltZW91dChmdW5jdGlvbigpe3dpbmRvdy5vbnRvdWNobW92ZT1udWxsO30sIDE1MDAwKTsgJC5mZWF0aGVybGlnaHQoJ2h0dHA6Ly9jZG4uYWRzZXJ2ZXJ0ci5jb20vTUNDXzMyMHg0ODAuanBnJyx7Y2xvc2VPbkVzYzogZmFsc2UsIG9wZW5TcGVlZDogNzAwLCB2YXJpYW50OiAnZml4d2lkdGgnLCBjbG9zZUljb246ICc8aW1nIHNyYz0iaHR0cDovL2RhdGEuc3VwbG94LmluZm8vZGVmYXVsdC9jbG9zZU1hcC5wbmciIHN0eWxlPSJXSURUSDo1MDAlOyBIRUlHSFQ6NTAwJSI+PC9pbWc+J30pO30pOyBmdW5jdGlvbiBwcmV2ZW50RGVmYXVsdChlKXtlPWUgfHwgd2luZG93LmV2ZW50OyBpZiAoZS5wcmV2ZW50RGVmYXVsdCkgZS5wcmV2ZW50RGVmYXVsdCgpOyBlLnJldHVyblZhbHVlPWZhbHNlO308L3NjcmlwdD48L2JvZHk+PC9odG1sPiI=
     
  19. Todd

    Todd Founder (13,518) Aug 23, 1996 Finland
    STAFF Mod Team Society Pooh-Bah

    @dwagner003 Nope. We're looking for the originating domain. See other replies for examples.
     
  20. Adrena1ine

    Adrena1ine Zealot (748) Nov 22, 2014 Pennsylvania
    Trader

    I was having similar issues for the past few weeks. Even when I didnt visit BA I would have pop ups appear out of no where (even when I was at the home screen of my phone). I finally broke down and did a "factory reset" on my phone and havent had an issue since.
     
Thread Status:
Not open for further replies.