In a sneaky bit of social engineering scareware pushers are registering convincing sounding monikers as Skype user names and attempting to lead people to rogue anti-malware sites.

 

Skyp_Rogue_AV

Skype Rogue AV lure

 

The user name that is displayed in the Skype chat window is “Online Notification” and the associated user names appear on many variations of that theme; online.notification.america9, online.notification.america10 etc. This tactic lends this attack a veneer of credibility that is missing from the usual “Hi, I’m a sexy lady” or “Hi, buy my Chinese kitchen equipment” scams that are more familiar over Skype.

 

To the unwary, because of the well chosen user name, these messages appear to be something other than a stranger sending you a message, they appear to be some kind of real online notification.

 

The full text of the Skype message is

“******************************************

URGENT SYSTEM SCAN NOTIFICATION ! PLEASE READ CAREFULLY !!

http://www. {rogueAV domain}.net/

For the link to become active, please click on ‘Add to contacts’ skype button or type it in manually into your web browser !

FULL DETAILS OF SCAN RESULT BELOW

******************************************

WINDOWS REQUIRES IMMEDIATE ATTENTION

ATTENTION ! Security Center has detected malware on your computer !

Affected Software:

Microsoft Windows Vista

Microsoft Windows XP

Microsoft Windows 2000

Microsoft Windows Server 2003

Impact of Vulnerability: Remote Code Execution / Virus Infection / Unexpected shutdowns

Recommendation: Users running vulnerable version should install a repair utility immediately

Your system IS affected, download the patch from the address below !

Failure to do so may result in severe computer malfunction.

http://www. {rogueAV domain}.net/

For the link to become active, please click on ‘Add to contacts’ skype button or type it in manually into your web browser !”

 

The modus operandi is annoyingly familiar, just the medium and method are slightly novel. As I’m sure you have already guessed, these messages lead to fake anti-virus programs designed to extort cash from the victim. The same message appears with several different destination URLs, the advice in every case remains the same.

 

1 – Ignore the message

 
2 – Block the user (and check the “Report abuse from this person” box when you do so).
 
3 – Sit back and sip your cup of tea knowing you have done your bit in the fight against cybercrime today.

Related posts:

  1. New York Times pushes Fake AV malvertisement.
  2. Rogue Facebook application leads to phishing
  3. Patch Tuesday is a-comin’
  4. New malicious tweet run on Twitter
  5. Twitter Trends Lead to Rogue AV

This entry was posted on Thursday, 1. October 2009 and is filed under "malware, Web 2.0". You can follow any responses to this entry with RSS 2.0. You can leave a response here, or send a trackback from your own site.

12 Comments to "Skype “Online Notification” leads to Fake AV"

Tweets that mention Skype “Online Notification” leads to Fake AV » CounterMeasures -- Topsy.com:
Thursday, 1. October 2009 um 6:57 pm

[...] This post was mentioned on Twitter by Christen Rice. Christen Rice said: RT @rik_ferguson: New blog: Skype "Online Notification" leads to Fake AV – http://bit.ly/1j8wPg [...]

fixer:
Friday, 2. October 2009 um 7:13 am

great stuff

Nep-virusscanners verspreid via Skype | PC Web Plus - ICT nieuws blog:
Friday, 2. October 2009 um 4:11 pm

[...] volgens de waarschuwing ernstig ontregeld. “Een doortrapt stukje social engineering”, zegt Rik Ferguson van Trend [...]

Chaim Haas:
Friday, 2. October 2009 um 5:10 pm

Skype posted about this type of attack on its Security blog in November of 2007 – see http://share.skype.com/sites/security/2007/11/fake_malware_alert.html).

Rik Ferguson:
Friday, 2. October 2009 um 8:07 pm

Thanks Chaim, reminds me of a favourite Tyla lyric of mine “Nothing’s new, only forgotten”.

Andrew:
Friday, 9. October 2009 um 9:02 pm

Thanks for posting this — just got the phishing scam myself and was very happy to be able to Google it and validate it’s scam-iness.

Natalya P:
Thursday, 22. October 2009 um 6:52 am

I’ve got the same message and it looked very fake to me. Thank you for posting this message, which helps us to stay safe.

check in online:
Friday, 1. January 2010 um 10:01 am

I don’t remember the site name, I found it on google, it said that I have 160 worms in my C drive, 20 Trojans in My Documents and all, then it tried to install something with fake names, I just navigate away from that.

Pam:
Wednesday, 23. February 2011 um 2:05 pm

More than a year later, I just received much the same: I clicked (on my Mac screen) to answer an incoming Skype call and the thing talked to me, in computer-generated alarmist American tones. It said “a virus has been detected on your computer”, that my system HAS been infected and affected,and that I must “request professional maintenance at http://www.sos.nbc.com“. This last phrase was repeated until I disconnected the call.
I haven’t gone anywhere near the website, of course. The associated Skype user is: “o.notification.am16″ but the incoming Skype call appears in my call record as just “Online Notification”. Grrr.
Grateful to the rest of you for confirming my assumption (always a bit unsettling) that this IS a scam.

jlm1354:
Saturday, 24. September 2011 um 2:06 am

I blocked one of these numbers and checked the report abuse box, but they are still calling me over and over again. The blocking didn’t work and Skype support was not supportive.

Caitlin:
Friday, 28. October 2011 um 5:35 pm

I’m getting sick of being harassed by these guys. I report them, I flag them for abuse, and Skype refuses to do anything. I get a call from them at the exact same time every day, even when I am invisible or set as offline. They will contact me even when my laptop is turned off.

Skype, deal with this or you’re going to wind up losing a lot of customers.

The one that keeps contacting me over and over is usa.urgent.sys-notice.b3.

Marla:
Friday, 11. November 2011 um 6:31 am

I noticed the one time I accepted the call, just by accepting the call my OWN personal anti-virus and spyware program went haywire. That set off bells in my head and ever since i just report abuse and block it.


Name:

E-Mail (not published)

Website:


Spam protection


© Copyright 2010 Trend Micro Inc. All rights reserved.
Legal Notice | Disclaimer