The Malware that doesn’t take “No” for an answer.

Thursday morning, the day after Christmas 2013 I received a call from someone who needed help. “Fred” callously clicked on an attachment from a phising email purporting from Amazon.com.

After that, he kept seing Windows User Account Control (UAC) asking for confirmation to load some executable file.

Clicking “No” did not really help because UCA kept popping up subsequently.

IMG_0456

I booted Windows 7 into “Safe Mode with Command Prompt” and launched Registry Editor (regedit.exe).

I located load command in the registry.

ComputerHKEY_CURRENT_USERSoftwareMicrosoftWindows NTCurrentVersionWindows”

delete the content from the “Load” key.

This is going to take a while

It’s a computer running Windows 7 with tons of services failed to load. I suspected that there was something wrong with the file system. So I scheduled a Check Disk.

chkdsk

iMac sans LCD and Hard Drive

One of the things I did earlier today at “work” was taking apart a late 2009 aluminum iMac to replace the hard drive. You can see an orange suction cup on the shelf on the top right of the picture.

Aluminum-iMac-sans-LCD-Screen-and-Hard-Drive

Spammer Alert: x-celerated.com

UPDATE 4:
This spammer also related to wreese2013@hotmail.com.
The first spam reported to us is coming from ldirect.us domain
Definitely related to thegrapekiwi@gmail.com.
The phone number given as administrative contact 1.5037469135 seems to be used a lot for spam domain names.

UPDATE 3:
This spammer is also related to thegrapekiwi@gmail.com which is in the Register of Known Spam Operation (ROKSO).
Source: The Spamhaus Project

UPDATE 2:
Also related with Xcelerate

cherwo.co.uk (Registered on: 21-Mar-2013)

Domain name:
cherwo.co.uk

Registrant:
EvoMedia

Registrant type:
Non-UK Corporation

Registrant’s address:
PO Box 025250 #52990
Miami
FL
33102
United States

Registrar:
eNom, Inc. [Tag = ENOM]
URL: http://www.enom.com

UPDATE:
Based on recent findings, tslater@x-celerated.com spammer is related to admin@sevenquest.com spammer.

We’ve been getting requests to investigate a particular round of spam emails a few weeks ago. The spam seems to be using domain names with the same registration information.

Administrative Contact:
Xcelerate
Tom Slater (tslater@x-celerated.com)
+1.7733288013
Fax: +1.5555555555
1608 S. Ashland Ave
Chicago, IL 60608
US

Partial list of domains registered with email tslater@x-celerated.com through enom.com / namecheap.com:

  • abovearrange.co.uk (Registered on: 27-Dec-2012)
  • acceptgrand.com (creation date: 06-mar-2013)
  • acceptjust.com (creation date: 14-mar-2013)
  • acceptmatter.com (creation date: 14-mar-2013)
  • alongsidethrough.co.uk (registered on: 18-Mar-2013)
  • appledefine.co.uk (Registered on: 27-Dec-2012)
  • behindbelow.co.uk (registered on 18-Mar-2013)
  • buyseem.com (creation date: 21-feb-2013)
  • consideringplus.co.uk (registered on: 18-Mar-2013)
  • dowould.com (creation date: 15-mar-2013)
  • fixuntil.com (creation date: 14-mar-2013)
  • drawnegotiate.co.uk (Registered on: 27-Dec-2012)
  • eitherthose.co.uk (Registered on: 07-Mar-2013)
  • excludingdown.co.uk (registered on 18-Mar-2013)
  • explainlist.com (creation date: 18-mar-2013)
  • findgive.com (creation date: 14-mar-2013) *BLOCKED DUE TO SPAM*
  • fixuntil.com (creation date: 14-mar-2013)
  • insuredegree.net (creation date: 11-mar-2013)
  • measureease.co.uk (registered on: 16-mar-2013)
  • mindget.net (creation date: 11-dec-2012)
  • needwith.com (creation date: 13-mar-2013)
  • organiseevent.us (Domain Registration Date: Oct-10-2012)
  • readeach.com (creation date: 15-mar-2013)
  • sandez.co.uk (registered on: 21-mar-2013)
  • sellstill.com (creation date: 13-mar-2013) *BLOCKED DUE TO SPAM*
  • startenough.co.uk ( Registered on: 09-Mar-2013)
  • studybehind.co.uk (Registered on: 30-Dec-2012)
  • succeedthe.co.uk (Registered on: 03-Mar-2013)
  • talkterm.com (creation date: 15-mar-2013)
  • teachthree.com (creation date: 13-mar-2013)
  • telloffice.com (creation date: 06-mar-2013)
  • usealways.co.uk  (Registered on: 03-Mar-2013)
  • userepeat.co.uk (Registered on: 30-Dec-2012)
  • yourher.co.uk (Registered on: 07-Mar-2013)
  • returning-home.info (expired)
  • iseaadapt.com (expired)
  • actrevise.com (expired)
  • adaptpoint.com (expired)

The domain x-celerated.com was registered through DreamHost:

Registrant Contact:
x-celerated.com Private Registrant x-celerated.com@proxy.dreamhost.com
A Happy DreamHost Customer
417 Associated Rd #324
Brea, CA 92821
US
+1.7147064182

x-celerated

We informed DreamHost of our findings on x-celerated.com, and we received a reply:

Unfortunately, we provide neither hosting services, nor email services, for any of these domains. The same is true for x-celerated.com, for which we are only the
registrar.

We looked into the address of Xcelerate’s Tom Slater. It is a mailbox service by Earth Class Mail in Chicago.

A Virtual Presence In Chicago
Street and PO Box addresses available:

Street Address
1608 S Ashland Ave.
Chicago, Illinois 60608-2013
Just $14.95 per month in addition to Monthly subscription fees
Will-call pickup not available

PO Box
PO Box 803338
Chicago, IL 60680-3338
Included in your monthly subscription fee

We cross referenced the phone number 773-328-8013 and the addresses from Earth Class Mail. We found a domain using Earth Class Mail service and the phone number 773-328-8013.

Administrative Contact:
TruTech
Mike Young (admin@techtru.com)
+1.7733288013
Fax: +1.7733288013
PO Box 803338
Chicago, IL 60680
US

The domain techtru.com was registered through enom.com / namecheap.com on August 27, 2012.

We called the number 773-328-8013 and we got the automated voicemail:

You’ve been forwarded to the voicemail for *text to speech voice* “xcelerate”.

It seems that Xcelerate is a shell company for the spammer to hide behind.

Spoofing the sender’s email address can be done. In this case Xcelerate / x-celerated.com is highly likely to be involved. Consider the following patterns:

  • The Domain Names are registered through enom.com / namecheap.com
  • Each Domain Name is composed of two English dictionary words that seemed to be randomly chosen
  • Registration info of the Domain Names are the same
  • The Domain Names are recently registered / created
  • The voicemail for 773-328-8013 mentions “Xcelerate”

If you would like to fight these spammer, use services like SpamCop.net and report them. SpamCop.net provides free service; we encourage you to subscribe to their service for a nominal fee. After all, they are providing a great service.

——-

Disclaimer:
We use SpamCop.net service.