Categorized | GFI Software

His fake AV phonecall tactics need a little work…


There’s falling on your sword, and there’s using Skype to call security researcher Adam Thomas then trying to sell him some fake AV.

This is an example of the latter.

The site involved was sosdl(dot)com (currently offline) and here’s a screenshot:


Click to Enlarge

The payment account is still live:


Click to Enlarge

Not sure I’d pay $ 19.95 for “instant repair”, but I’m sure somebody will find it tempting.

Read more about the fun people are having with rogue AV phonecalls over on the Brian Krebs blog., and keep an eye out for random URLs being thrown around Skype with “sos” in them.

Christopher Boyd (Thanks Adam).

Related Posts
  • ZoneAlarm caught using fake antivirus scare tactics
    Check Point, a security company that offers various products to protect consumers and businesses, is imitating the tactics of fake antimalware programs. Over the last few days,...
  • How blackhat SEO and Fake Anti-Virus work – Sophos demo
    Sophos Senior Security Advisor Chester Wisniewski shows how a major web threat works, step by step. This video walks you through how malware authors use blackhat SEO to...
  • Malicious Spam on the increase again
    Malware distribution via email is far from dead.  While we had a distinctly quiet period from October 2010 to March 2011, our stats show the bot herders are gearing up again with the proportion o...
  • The Royal Wedding and The Fake Antivirus
    The Royal Wedding of Prince William and Catherine Middleton that will be held tomorrow, on April 29, will attract the attention of many people around the world, and has become a trending topic on vari...
  • Fake AV for mobile platform
    We have seen countless number of rogue security products for Windows platform however this one is targeted to trick mobile users.The sample masquerades itself as a certain AV for mobile and ...
  • Hundreds of College and Government websites still redirecting to fake stores
    In January, I talked about high-profile websites, which had been hacked to redirect users to fake online stores. One unique aspect of the hack was the fact that the attackers had set up additional web...
  • Fake Certificate in Malware – with Message
    The malware authors every now and then send us virus researchers some messages. For example in the compiled binary itself, or as debug output. Now we found a Zbot Trojan variant which tries to evade d...
  • Fake AV served up by phony NACHA emails
    A little while ago, phishing mails claiming to be from NACHA were in circulation - it seems the phishers have had enough of that, deciding to send out malicious files instead. The mail claims an att...
  • Fake AV vs. Zscaler
    I've been monitoring Blackhat spam SEO for more than a year now. I frequently have to modify the scripts used to retrieve the fake AV pages in order to deal with obfuscation and other obstacles t...
  • Make your old add-ons work with Firefox 4.0
    Every major release of Firefox brings the joy of great new features, along with the frustration of having plenty of add-ons that no longer work. Fortunately, it's quite easy to get most add-ons to wor...

Comments are closed.

Security Status

Beware Facebook "Timeline" scams http://t.co/W5EW0cVv
4 months ago
Nigerian government (unknowingly) hosts phishing website http://t.co/uQd42ENw
4 months ago
PCMag Awards McAfee All Access its Editors’ Choice: SANTA CLARA, Calif.--(BUSINESS WIRE)--McAfee today announced... http://t.co/FakV7Vd8
4 months ago
RT @mikko: I hadn't noticed Google Maps has added 3D models of buildings. Here's a (very accurate) view of F-Secure HQ in Helsinki http://t.co/IKfAZlak
4 months ago
North Koreans aren't known for their online presence. But others may be lured into clicking Kim Jong-Il 'videos' too http://t.co/yQOon6YT
4 months ago
How to Protect Your Professional Reputation on Facebook Timeline http://t.co/I4bcR2VN
4 months ago
This is pretty impressive from @Softpedia: Facebook scans 2 trillion link clicks and blocks 220 million posts each day http://t.co/vKsn9gNl
4 months ago
Need for integrated approach to security in industrial control systems - http://t.co/tPBCNOow with @PikeResearch
4 months ago
Some free-based music we play at work http://t.co/xu5agZfc
4 months ago
Japan’s cyber defense weapon: a virus. It includes quotes by @Luis_Corrons via @InfosecurityMag
4 months ago