Getting a suspicious download prompt while browsing all

CarlsIII@kbin.social to /kbin meta@kbin.social – 1 points –
5

Humm. Well I've not seen it but...
Do you have auto media preview turned on?
...and if so I suspect it would be helpful if you can establish which post caused it because that really shouldn't happen.

I do (because I prefer it to the squished thumbnails,) but I can’t tell you which post triggered this or how I would know.

Edit: So it looks like it might be this post, as it seemed to pop up again as I was scrolling by, and it popped again when I clicked on the post (but not the link, obviously).

https://kbin.social/m/football@lemmy.world/t/342339/Atletico-Madrid-2-1-Granada-Memphis-Depay-great-goal-67

I will be blocking that community anyway since I have no interest in football.

I'm glad you could figure it out!

I followed the link and I see that network request too. I downloaded the file and it is the video.

I concur. I also navigated to the site and can see the .mp4 file with that name.
However the video file is 13.5Mb, not 30b. It also has a valid .mp4 extension.
I still can't reproduce the pop-up.

My best theory this point is OP's browser is cropping the URL for some reason, which means the ".mp4" part isn't seen. The browser is then trying to save the 404 response to the request for a file which didn't exist, and had no extension.

Sorry OP, but at this point it looks like something your end.
Out of curiousity, it is an unusual browser, or any scripts/ extensions running which might have corrupted the videos's URL?

My best theory this point is OP's browser is cropping the URL for some reason, which means the ".mp4" part isn't seen. The browser is then trying to save the 404 response to the request for a file which didn't exist, and had no extension.

I looked at the actual web request url it's doing for me.

https://downloader.disk.yandex.ru/disk/dfc79ab0f88295834385d89e14b27d1f687e201bf8074f21e0d0d9972096319a/64dc8782/MuDSbA9z5TnczT15nZM5t\_fipdB2eZIesleov6SiJ-7hJ1g7sSwJpQ0\_lNHok396G53tTWxxKw4e4Gu\_L\_UmFQ%3D%3D?uid=465360380&filename=7fed06c9.mp4&disposition=attachment&hash=&limit=0&content\_type=video%2Fmp4&owner\_uid=465360380&fsize=14161986&hid=9d62d8b95cb1158833293fffdf4deada&media\_type=video&tknv=v2&etag=a5f932a629c3d365ed6d74bd3ac546e6&expires=1692173809

I don't know why they're getting a download offered in the first place for such a scam looking url, but the display on OP's image is clearly separating the url into its components and only displaying some of them (the domain and file name). The file extension isn't part of the url itself here but rather the parameters which aren't displayed here because there's usually no need to and they would take up way too much screen space on mobile.

I think hiding the parameters is a good idea. While comments suggest this is a real video file, this could have easily been a virus disguised as a video. By hiding the parameters, you're preventing unsuspecting users from putting too much trust into those parameters.

Edit: reworded the comment