EGlobalSoft Solutions, Tek-Wire, Fegon, PrinterTales, AntivirusTales, Fake Cricut, WinDriver Tool

Original thread title: Phishing/tech support scam for 3d printing device (?) 609-710-4069, 786-946-2540

I have changed the title of my thread to better reflect what I have found and posted here about this apparent scam organization.

Scam Number: 609-710-4069, 786-946-2540
Scammer’s Website or Email: https://sites.google.com/cricutusetup.com/cricutcomsetup

which links to

https://cricutdesignspace.online/en_us/setup.php

Additional information about this scam: This seems to be a similar process to the banking/crypto impersonation scams I’ve been tracking here, not sure if it is actually the same criminal group. They are impersonating https://cricut.com/ , which seems to be some consumer-grade fabrication robotics device for arts & crafts stuff?

Anyway I complied with their phishing and got two callbacks from “Zacob” (or Jacob?) whose favorite color is black.

The phishing site does prompt you to download a Windows executable file. I am working on sifting through its text strings for any clues but would not recommend running it obviously.

Tawk.to text chat: https://tawk.to/chat/64900e4acc26a871b023620c/1h39bfl6t .

2 Likes

Mike called from 609-710-4069 after the chat, above. His favorite color is black.

Edit: checked on 786-946-2540 today reached “Marcus” whose favorite color is “dark yellowish brown,” (burnt umber perhaps? does Marcus enjoy the fall foliage season?).

Answers a generic “Thanks for calling how may I help you,” so I suspect the call center runs many similar scams and relies on the victim to tell them which way he/she wants to be scammed.

Edit 2: 786-946-2540 “Kelvin Morrow” says this is “printer support.” Says he is “not here to talk about” his favorite color.

2 Likes

I know this guy is a scammer so I scared the s*** out of him
why my buddies gave me all his information
he gave me pictures of where he’s located

2 Likes

Update: got an email on my honeypot address:

which links to the phishing domain cricut ,

which guides the victim to the very cute error page here: Cricut Error

Phone number from the contact page: 786-866-5932 .

I called and reached Dan D-A-N, Howmahalpyou who said that his favorite color is black (and that Cricut is pronounced like the insect, cricket. Thanks Dan D-A-N!)

1 Like

hmm, same U.S. and UK phone numbers, links to a lot of SEO “content” featuring the phone numbers – quite an elaborate production for one product.

Edit: some accounts of this scam going back at least a year

https://www.reddit.com/r/cricut/comments/zs6rl2/the_scammers_are_back_at_it_as_tech_support_for/

1 Like

On the same IP address as mannymaker.com and cricutdesignmachine.com , we find the very cleverly named phishing website

https://canňon.com/ , which uses a similar wordpress template. This may all be a coincidence – there are hundreds of domain names that point to that IP address, or it might not.

This page links to Canon : Official Manuals : Welcome!

which inevitably leads the victim to the “error” page

Does it have a tawk.to web chat widget? Of course it does!

https://tawk.to/chat/6544f507f2439e1631eb6185/1healq9oi

Update: I’m chatting with Jack.

2 Likes

Mikey from Canon Printer Support: 508-501-4138.
And “Grampus” (?) whose favorite color is yellow: 617-545-0933.

2 Likes

Another number: Marcus from Cricut 716-419-9456. His favorite color is “dark black.”

2 Likes

This is the same tawk.to account as a McAfee scam:

2 Likes

New websites:

Featured in a “google snippet.”

Links to Cricut New Machine Setup | Cricut Design Space Login .

Collects contact info, and includes a tawk.to web chat widget

https://tawk.to/chat/64900e4acc26a871b023620c/1h39bfl6t

Also: https://cricut-set.com/

2 Likes

So, the executable is “Windrivertool,” and its basically a scare-ware tool that advertises a toll-free number: 866-542-9565

I talked to Kelvin Mam. His favorite color is navy blue.

A spam seo “blog” that seems to be linked to TekWire LLC:

https://medium.com/@merrywilson/what-is-windriver-tool-c59d4f6bb543

2 Likes

812-489-7230: Kelvin from Canon Support. He says his favorite color “depends” but that today, he is color blind. He says that he does not want to help me with my printer because we are not friends.

I think he sounds like he needs new friends so kindly call on his number to be his friend, thank you.

469-864-6329: Ryan from Canon printer support’s favorite color is blue.

Update 19 April: 812-489-7230 still active, just called me. Claims his name is “I don’t know, Canon?” Please call this poor man and help him to remember his name.

2 Likes

oty.com for remote support.

2 Likes

Number is still active, “Kathy Wood” (not the famous Wall Street hedge fund manager, I presume?) is still spamming Linkedin: LinkedIn Login, Sign in | LinkedIn

Update: still active as of 1 June 2024, another Linkedin spammer is here:
https://www.linkedin.com/company/cricutdesigncut/about/

1 Like

Trolling the fake cricut site again, I got a call from 877-469-0297, “Charles Smith” from “Cricut Support.”

I was not able to call the number back. However, it has been reported here before,

And it is also advertised on these scammy-looking websites:

and

On the same IP address as printerdriver.support, we find

and on the same IP address as printertales.com, we find

Interesting!

2 Likes

I just called the number, and the Technical Support Executive (assistant to the) who answered claimed to be from “Printer Tales.” But he would not say his name, and hung up. Sounded like a busy office environment in the background.

2 Likes

So I am quite certain that this is the long-running eglobalsoft solutions/AOI tech/Fegon Group/Tek-Wire/Windriver scam organization, as the cricut and printer scams all involve downloading the “WinDriver Tool” scareware.

On 192.185.129.222 there are many, many website domains that all lead to either the fake cricut setup or the fake canon printer setup. Edit: also fake Brother: https://support-brotherr.com/ links to https://setup-brother.com/drivers/ .

For a different point of view, check out this spammer IT consultant blogger:

https://medium.com/@merrywilson/is-the-tekwire-llc-legit-company-honest-review-2023-a26dfcf8a66c

Well I guess that settles it! It says right there that it is an honest review! 100% legit certified.

1 Like

Claiming the same Miami address as “Printer Tales” is “Antivirus Tales”

857-557-6826 (Busy signal for me.)

On the same IP address:

https://a2softadvisor.com/ – antivirus reseller that only offers “cash on delivery” payment?

https://bestsoftwareplanet.com/ – a clone of the above.

https://bestsoftwaresbuy.com/ – ditto.

https://buytrustedantivirus.com/ – again.

https://consumerstales.com/ – a review site that features: Printer Tales, Antivirus Tales, Manny Maker, etc!

https://goantivirusmart.com/ – same antivirus “store”

https://gosoftwaremart.com/ – ditto

https://greenstarsoftware.com/ – guess what?

https://helpbest2buy.com/ – antivirus, MS office, no credit cards.

https://helpemailtales.com/ – email support, same number as Antivirus Tales

https://keybest2buy.com/ – another software reseller same as above

https://martcricut.com/ – another fake Cricut page that directs people to the WinDriverTool.

https://mycomputeradvisor.com/ – another antivirus/MS Office store

https://safebest2buy.com/ – and another

https://softbest2buy.com/ – and another

https://softwareexcellent.com/ – and another

https://softwaresdiary.com/ – supposedly Quickbooks support, toll free number is one digit off the Cricut/Printer fake support number

https://softwaresspot.com/ – another antivirus storefront

https://softwarestaples.com/ – and another

https://talkbest2buy.com/ – and another

https://valuessoftware.com/ – and one more!

2 Likes

866-542-9565 answering on a Sunday morning. Says “no this is not the printer support, this is uh like my personal number, do not call on here.” Says his name is “uh like uh.”

2 Likes

Some Xitter accounts for the scam group:

2 Likes