Ranking: 1,431
Threat Level: 20 % (Normal)
Infected Computers: 16,097
First Seen: June 10, 2022
Last Seen: September 25, 2023
OS(es) Affected: Windows appears to exist to propagate a popular browser-based tactic solely. It is extremely rare for users to land on such deceptive pages intentionally. Instead, they are taken there predominantly through forced redirects caused by previously visited pages with rogue advertising networks or due to a PUP (Potentially Unwanted Program) lurking inside their device.

When is opened, it will try to lure visitors into pressing the displayed 'Allow' button. However, the page will not reveal that doing so will subscribe the user to its push notification services. The website will try to hide this fact under various false scenarios. The most commonly encountered one consists of the deceptive page pretending to be doing a CAPTCHA check. Other variants include showing a video window and claiming that pressing the button will allow users to watch it or that a file will become available for download. The exact text of these clickbait messages could be similar to:

'Click Allow if you are not a robot'

'Click Allow to play the video''

'Press Allow to download'

The goal of is to abuse the browser permissions granted by the push notification feature to run an intrusive advertising campaign. Unfortunately, the advertisements associated with such questionable sources are likely to be promoting additional hoax pages, shady adult websites or even platforms spreading more PUPs.

URLs may call the following URLs:


