www.help87.com tech support scam (01245785847)

A cold call came into a land line in a plant room while I happened to be in there.

The line being called is not published anywhere and is only there to host broadband. There is no “leak” of info here, just some spammy autodialler.

Initially an Indian lady claimed she was calling from BT and that the connection was sending viruses. Then when she was sure I was “hooked” as a victim she transferred me to an Indian guy.

Sadly as I was in a plant room and on a standard land line phone I couldn’t record the call. I did have access to a virtual machine.

They initially attempted to get me to go to help87.com (which for some reason on the connection I was on would not load).

Then when that failed they got me to use the SupRemo remote software. Again, as I was on-site at a job I spent about 50 minutes trolling them along but had to give up in the end. We didn’t get to the payment stage.

Once the scammer got connected he tried to use the W3C validator (again, a site that wasn’t loading for some reason) and when that failed he used the “tree” command in dos to claim that the system was scanning and cleaning viruses.

The only things I have to go on are the initial domain he tried to use:

help87.com

and the phone caller ID: 01245785847 (aka. +441245785847 or “01245 785 847” / “01245 785847”) in the UK. (Possibly also related “02059837401”)

The phone number doesn’t lead anywhere other than a few other people complaining about scam calls.

Let’s focus on the domain. There are two references to threatexpert reports. Sadly it looks like Symantec have eaten threatexpert and have taken down their free public reports.

The only remaining thing I can go on is the IP, 107.180.9.83, which resolves to a GoDaddy IP “ip-107-180-9-83.ip.secureserver.net”.

I don’t think this is a shared server. It looks like a private dedicated or virtual dedicated. The SSL certificate on it references, “softwaretweak.co” “akick.com” and “akickoptimizer.com”. This domain seems to sell lots of badly written software including “PC Booster” type software.

If you go to buy the software on that site it takes you to a non-secure form that asks for credit card details!

akick not pci compliant.png

They also claim to me Microsoft Gold partners but the link to verify doesn’t work.

Upon digging around some more it seems there may be a reason why they are no longer a Microsoft Gold partner!
1) Their PC Doctor software is listed as malware by Microsoft: https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Rogue:MSIL/Rustliver&ThreatID=223709

The Microsoft page above ties it all together too. They reference gattsupport.com (hosted on a different server within the same IP range) which has the same domain registration of technocaretechnology.com!
abhishek.semm@technocaretechnology.com
H-68, Sector-63
City Noida
State Uttar Pradesh
Postal 201307
Country INDIA
Phone 919654796904

The original IP once had a domain gattsupportcom.com pointing at it.

2) They’ve been posting on the Microsoft forums on how to “get [their antivirus] listed in windows security center”: here and here.

Another likely link to them being the same people is another domain on the IP, technocaretechnology.com and gatechnocaretechnology.com, who seem to do outsourced phone support and other business processes.

Other domains on the same server that have no content:

kristechllc.com

In summary: It is my opinion that this company is a scam and, in their downtime, cold call people to attempt to get them to pay for services or products that they don’t need. Certainly they do the standard event viewer “scare” tactics and lie about the reason for the call.

This entry was posted in Uncategorized. Bookmark the permalink.

2 Responses to www.help87.com tech support scam (01245785847)

  1. nigella4 says:

    They at located in Noida, India. GA Technocare Technology Pvt Ltd
    Address: H 73, Sector 63, Noida, Uttar Pradesh 201307, India
    Phone: +91 120 650 0582
    technocare.technology
    (they almost always connect as “web expert” in remote connect session
    one Indian job applicant’s comment:
    …company will say you in training that they’re dealing with software called akick but actually what they’re doing up there is scamming there is no software they sell up there called akick they target people of age above 60 of USA UK and Australia and make them fool that they’re calling from their email maintenance company and show them fake viruses by their own made coding programmes and charge them from 200-1000$ really a big scam is going on their and no one is lokking over that they don’t even pay new guys make them work for atleast 1and a half month and hold their payment for 60-90 days worst company don’t go for it it’s a SCAM!!!

  2. Support admin says:

    Help87.com is free domain which created for everyone where you can find all usefull software.

    Also on this web page all software are from third party which only there respected owners can sell.

    We are a software company and yes we use Microsoft platform to develop our software as we are there gold partner and you will not find any bad reviews about our company akick and ga technocare.

    Someone used our name to make bad reviews.

    However we will block this domain asap so no one can use it for wrong business.

Comment on this topic

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out /  Change )

Twitter picture

You are commenting using your Twitter account. Log Out /  Change )

Facebook photo

You are commenting using your Facebook account. Log Out /  Change )

Connecting to %s