On each of my browsers, I've an must-have extension/addon
overlay remover - look above, on the post #55.
It's indispensable I think, to defend from malwares that use overlay popup - look on this MT topic:
Malware Alert - AUTOIT SCRIPTING USED BY OVERLAY MALWARE TO BYPASS AV DETECTION
On threatpost.com we read:
“The malware’s operator remotely initiates a fraudulent transaction from the victim’s endpoint and may prompt the user to provide additional details by using the fake overlay screen,” researchers said.
X-Force researchers said Brazil has become a hotbed for financial malware and that recent uses of overlay malware highlights a trend of more sophisticated malicious code used in the region.
“In the past year, we have observed the rise of malware, such as Client Maximus and similar codes, that uses remote access with overlay screens for bank fraud operations in Brazil. Recently, we detected a remote access Trojan (RAT) malware that uses the same overall technique, but with an added twist to its antivirus evasion method,” according to X-Force.
The RAT does not have a name and its code is written in Delphi, a programming language common among hackers targeting Brazil. “These Delphi-based codes attacking in Brazil see so much code re-use there, that the malware is not defined into ‘families’ like the ones we know from the module Trojan world (Zeus, Ursnif, Dridex, etc),” said Kessem in an interview with Threatpost.
AutoIt has been leveraged several times in the past by attackers as a way to circumvent AV.
Cisco Talos noted in 2015 a group of hackers had used the tool in conjunction with phishing attacks to install a RAT designed to maintain persistence on the target’s system by mimicking normal sys admin activity.
In 2013,
researchers noted an uptick in malware utilizing AutoIt as a scripting language and instances of keyloggers and RATs builders developed with AutoIt being uploaded to the text storage and sharing sites such as Pastebin.
In Brazil, X-Force researchers said, overlay malware remains the preferred way to carry out attacks against banks. “As long as those types of attacks continue to serve them, threat actors are unlikely to see a need for change,” researchers wrote."
_____________________________________________
Behind The Overlay (Moon Edition) :
Pale Moon - Add-ons - Behind The Overlay (Moon Edition)
JustOff wrote on github page:
GitHub - JustOff/behind-the-overlay-me: Behind The Overlay (Moon Edition)
What's it all about?
Some websites will use an overlay to mask its content with a transparent background to force you to read a message before you can see the actual content.
This is very annoying as every site will have a different way to close that overlay popup.
This extension solves this problem by offering
one button to close any overlay on any website you may ever encounter.
Does it work everywhere ?
The extension should work on most sites that have overlays. Here is a list of some of the websites that the extension is know to work:
WORKS_ON.md.
Features
- Requires no special permissions.
- Extremely lightweight, relies on little known document.elementFromPoint browser's function to find elements that are in front with the highest z-index.
- Non-intrusive. The extension activates only when you click its button, thereby it has no impact on navigation performance when you don't use the extension. Doesn't inject tons of CSS rules as AdBlock extension is doing for example.
- Supports hiding of multiple DOM overlay elements.
- Enables overflow auto of the body when overlay script hides it to disable the scroll of the page.
_____________________________________________
Firefox link to
Behind The Overlay Revival by Iván Ruvalcaba: Behind The Overlay Revival – Add-ons for Firefox
_____________________________________________
Test page with overlay popup:
pbs.org: FRONTLINE | PBS | Official Site | Documentary Series
kakaku.com: 価格.com