Archive.today/.is/.ph/etc malware

I have long been suspicious of archive[.]today: if it’s too good to be true, it probably isn’t. Or: if it’s free, you’re the product. My suspicions have been confirmed once again.

This Lemmyverse post explains that by calling one of their sites

  • you supply, from your own device, a botnet that does a targeted DDOS attack at a Finnish blogger who did some research into the people behind this 1000 TB and growing project.
  • 3rd party Russian analytics javascript from mail[.]ru is called

To mitigate this, you can use other archive services like ghostarchive.org or archive.org.
You can also add these to uBlock Origin’s My Filters tab:

archive.today
archive.is
archive.ph
archive.fo
archive.li
archive.vn

If you already use my SFOS ad- and malware blocking software you can add the following domains to blacklist.txt:

archive.today
archive.is
archive.ph
archive.fo
archive.li
archive.vn
www.archive.today
www.archive.is
www.archive.ph
www.archive.fo
www.archive.li
www.archive.vn

Or, execute this shell command:

mkdir -p ~/.config/hosts-block
for tld in today is ph fo li vn; do \
printf '%s\n' archive.$tld www.archive.$tld \
>> ~/.config/hosts-block/blacklist.txt \
done

Disclaimer
This is a public service announcement, nothing more. The malware exploit is a fact, or at least was at the time of writing, and to my knowledge none of the usual adblockers have picked up on it yet.
And sorry for tooting my own horn a little. :innocent:

11 Likes

Forgive me, i’m pre-dinner… what is the relevance to SFOS?

1 Like