
No announcement yet.

Unusual Attack

  • Filter
  • Time
  • Show
Clear All
new posts

  • Unusual Attack

    My wife has been sent a message from a fake Skype account, 4am local time, made with my name and surname. I only have a business skype account with this combo, did not send the message. Business Skype seems to work normally otherwise this morning.

    The message was only a link to a website - not listed in Google, someone put some effort to create it though, looks like a regular wired/whatever site. Don't open/search for it.

    The article is "normal" just some advertising crap about a super pill endorsed by Stephen Hawking no less. Regular ads, etc.

    She was not asked for any details, ie log in, password details etc, again appears to be just a regular webpage.

    First question is - what can be picked up on when opening such a webpage, assuming that it is designed for a phishing attack?

    Webpage was opened in Chrome on Android 4.4.

    I did not find anything like this in general in google search, and it is a bit unusual to be targeted directly in this manner.

    Another curiosity, even though I am married close to 20 years, we do not share the same surname, so somebody had to read something to connect us. I have minimal web presence in my name, no FB account, only on LinkedIn and not connected to her etc and will be really surprised that some bot picked this relationship up so nicely.

    So either someone is actually bothering to waste time to target us, which would be kind of worrying, or there is some list of names out there, and all my contacts could be getting BS sent to them pretending that it's me.

    I did lose an android phone with a long list of contacts about 2 years ago. Business Skype with details was not loaded there.

    Any ideas?

    #1 - A bot or an actual human?
    #2 - What can be loaded to android/is a known possibility when only opening a fake webpage? It did not appear to have asked to install anything.
    #3 - Any reason for the attacker to use Skype specifically?
    Socrates: "Good is That at which all things aim, If one knows what the good is, one will always do what is good." Brian: "Romanes eunt domus"
    GW 2013: "and juistin bieber is gay with me and we have 10 kids we live in u.s.a in the white house with obama"

  • #2
    A quick update.

    Got a notice from several contacts that they also received dodgy links sent with my name to them, so there is a contact list out there somewhere.

    The link shared was not the same, so that would indicate that it is a bot sending out crap, which is nice, that it's not an actual human behind it.

    I told them to block it, and well - that is the best that can be done.

    Last point - contacting Microsoft/Skype to alert them about this/ask them to close the account, is not exactly the easiest thing in the world, perhaps that is the reason for selection of Skype as a method of contact.

    The main question left open is:

    #2 - What can be loaded to android/is a known possibility when only opening a fake webpage? It did not appear to have asked to install anything.
    Socrates: "Good is That at which all things aim, If one knows what the good is, one will always do what is good." Brian: "Romanes eunt domus"
    GW 2013: "and juistin bieber is gay with me and we have 10 kids we live in u.s.a in the white house with obama"


    • #3
      On android check if you have disabled the option to install from 3rd sources.

      Normally, all android phones come with the option to install ONLY from google play.

      If you have't changed this, I think you're perfectly ok.


      • #4
        Thanks, I don't think this option was changed.
        Socrates: "Good is That at which all things aim, If one knows what the good is, one will always do what is good." Brian: "Romanes eunt domus"
        GW 2013: "and juistin bieber is gay with me and we have 10 kids we live in u.s.a in the white house with obama"


        • #5
          Was your skype account in your wives address book (i.e. on Outlook or the like)?

          Serveral years ago I had a case where a friend from university sent me a mail from his workplace (which was strange as he never had mailked me from his workplace before).
          Even more strange was, that the text of the mail was something about a keyboard (for music) ... fitting to said friend as he was musician, but strange thing to send to me ... I think a hyperlink was also incoluded, but dunno for sure anymore as this was ~1.5 decades ago.

          Well, it was obvious that he had a virus on his computer and this virus used his outlook address book and also texts from past mails her sent or received.
          (He didn't believe me at first, considering that it was his workplace computer ... but the admin he contacted afterwards confirmed my suspicion)
          Tamsin (Lost Girl): "I am the Harbinger of Death. I arrive on winds of blessed air. Air that you no longer deserve."
          Tamsin (Lost Girl): "He has fallen in battle and I must take him to the Einherjar in Valhalla"


          • #6
            I think that I got to the bottom of this in the meantime.

            I totally forgot that ages ago (like a decade or so), I had a private Skype account, with a number of contacts there. It was locked out due to me forgetting the password, trying to log in after a few years of inactivity. Skype blocked me. That was all a long time ago, including the block, so I just let it be.

            It seems that a third party gained access to this account, and is using it to send spam messages to contacts on the list.

            I guess, it is not exactly serious, as it was really weird when I heard about this in the morning. I have no idea who I had as contacts back there, but those few people who confirmed that they got stuff from me must have been there.

            All in all it's good, the only mystery that remains is how could someone else get access to allegedly blocked Skype account which was inactive for years.

            Whatever the way, the issue does not seem too serious & thanks Paik + Proteus for the tips.

            btw - I cannot gain access to that account as the e-mail used is closed, and that automated MSFT bot service is saying that I am using wrong details to reset, which is not exactly a surprise.

            I will try chat later from my wife's account.
            Last edited by OneFootInTheGrave; November 17, 2016, 08:53.
            Socrates: "Good is That at which all things aim, If one knows what the good is, one will always do what is good." Brian: "Romanes eunt domus"
            GW 2013: "and juistin bieber is gay with me and we have 10 kids we live in u.s.a in the white house with obama"


            • #7
              Two points oneFoot:

              1. Lists actually are bought and sold by scammers and criminals. Some of those organisations are very large, rich and well organised.

              2. It might be a phish however maybe they were simply trying to sell you a useless pill at a high price.


              • #8
                I hope that's all there is.

                Did not manage to disable the account , it's hard to prove authenticity, and I use no other MSFT services to prove who I am so...
                Socrates: "Good is That at which all things aim, If one knows what the good is, one will always do what is good." Brian: "Romanes eunt domus"
                GW 2013: "and juistin bieber is gay with me and we have 10 kids we live in u.s.a in the white house with obama"

