  1. (Firefox, S10) Hi, sorry for bothering everyone again but I have a few concerns I recently went to the site clinic.meijer.com (posted straight from the Blokada log) which was the first result on Google and I have noscript installed so I allowed the sites script. It ended up not working and I close the site. I then noticed on Blokada that even minutes after closing the site and even revoking the script priveleges I saw that something was still trying to access the site. Once again the sites tab was completely closed. I then thought I had just went to the site again and forgot about it, so I made sure to block the domain in Blokada and not visit the site, and it once again showed up a few minutes later, this time blocked. I have no Meijer apps installed, and this is for sure the first time I've ever seen the domain in Blokada logs (I survey the log like a hawk). I'm just wondering how the site can access itself even without scripts or human input, cookies? I have MB Premium and it hasnt detected anything, nor has Ublock Origin or Noscript, not even my own Firefox history shown anything since I originally visited the site. It's as if visiting the site affected something on the phone itself, and not the browser. And to be honest, this might sound pretty pathetic but I'm incredebly anxious and having near panic attacks about this, I've got various anxiety disorder, ocd etc. and online security is a big factor in them. Any help would be very appreciated
  2. Hi @mbam_mtbr thank you for replying, I whitelisted the domain in Blokada and I saw it go through and connect, but nothing happened. After I let it connect I unwhitelisted it and it stayed away for a while, but later came back. I guess I'm just confused why it tries to connect while I have those apps open, and why it just comes and goes seeminly randomly. I guess I just panicked, seeing as it seemingly does nothing I guess I'll just have to ignore it. I apologize, thank you again for replying and I'm sorry if I wasted your time.
  3. (Sprint S10 Android) Hello sorry for bothering you all again but it seems I have a different problem now too, Recently I've noticed googleads . g . doublclick . net showing up recently on my Blokada logs, I know this is a legitimate Google ad server but it just showing up from time to time isn't the problem. I've noticed it in multiple apps that either have their own ad domains or app that are opensource and I can guarantee do not have ads of any kind, yet when open spam that adress. When I dont have those apps open it tries to reach googleads about every hour despite not doing anything, and when those apps are open it spams it every few seconds. The apps I've noticed start this spam are as follows: Samsung Notes Tachiyomi ( An open source app that I can guarantee has no ads) Ebay Amazon shopping Pixiv Reddit Apps I've noticed that don't set it off: Google Play (ironically enough) Gmail Malwarebytes Blokada Newpipe Firefox VLC Media Player Medisafe FFXIV Companion I originally thought it was the apps themselves but after whitelisting them to not block ads in those apps Blokada still blocks googleads so its not the apps causing this, I dont belive. I also went to my settings and restricted background data and forced stopped all my apps except system apps and the safe apps that don't set it off. It stopped for a little bit after turning Blokada's Adguard DNS on and off (then it only tried to reach the server every hour or so) but then it came back, I tried turning it on and off again and it didn't work, it was still being spammed in those apps. I tried again right as I was righting this and it seems to have stopped again for some weird reason. Malwarebytes doesn't detect anything at all. I haven't turned off Blokada or whitelisted that adress, I'm afraid of anything happening. I'm sorry if this is too long winded or hard to understand, this is making me incredibly stressed and with the pandemic and social distancing this is the only thing I have to think about. Any help would be very appreciated, Thank You.
  4. Hi @mbam_mtbr thank you for replying, Blokada and the host list I use, Energized Basic and Adguard dns only blocked the c00161-dl domain by default. I then put the other two domains in the blacklist My first thought was to check to see if a new app was causing these, but when they started no new apps were installed, none even were updated to my knowledge I checked with both the settings app going through all my apps, and then with the Malwarebytes log to see the newest installations and there were no new apps that really correlate. It seems it appeared out of nowhere, and I looked into Airship and could find nothing about those specific subdomains except device-api, which is the only one that I could find with any documentation or web presence at all. I guess that it just appeared one day randomly and the fact I can't find anything about those domains at all is what is troubling me. And I haven't recieved any threatening emails at all. Those people may have a different problem. Any help would be appreciated, thank you.
  5. (Sprint S10 Android 9, own full Malwarebytes with all protection options enabled) Recently I've noticed a few suspicious domains in Blokada, and they first started out while using and after stopping the Sprint Mobile Hotspot but have recently just been spammed regardless of any factor. They are c00161-dl. urbanairship . com remote-data. urbanairship . com device-api. urbanairship . com I tried using theNet Monitor app, but once I turned that on the domains basically dissapeared until I stopped the app, then came back. While using the Net Monitor I didn't see anything other than the system being tracked, aside from my internet browser while I was looking things up. After blocking the remote-data and device-api domains(c00161-dl was already blocked by blokada without me having to do anything) these two domains now appear nearly constantly, moreso than any other domain in Blokada, and it seems those two are prerequisites for c00161-dl, because I haven't seen that since blocking them. I also went back through the Blokada log and I found that the domains had appeared before, but it was between every few thousand entries and it was only one of the three each time, never two or three at once and never spammed like it is now and never the c00161-dl domain. I've also stopped using the Sprint mobile hotspot for fear of those domains I guess, leaking out of the hotspot and I wouldn't know about it. I've run multiple malwarebytes scans and they've all turned out clean, and all I could find is that they seem to be harmless middleware, but I haven't noticed those domains until just now, and the thing that makes me really anxious is that I can't find ANYthing about c00161-dl, anywhere at all. I apologize if this is rambly or hard to read, I have been stressed out about this almost all the time since it happened. Am I right to be worried, or am I just being overly paranoid? Any help at all would be very apreciated.
