"BroVPN" TROJAN

Link (Dangerous): Free VPN service from BroVPN - VPN for Windows

Registered via NameCheap on May 8, 2022 - Whois brovpn.store

VirusTotal - VirusTotal - File - d5f72d32ec032c1a1dd0f54072077bf93950f8def53e43b0628cf866a2f0b6db

image

Any.Run - https://brovpn.store/BroVPN.iso - Interactive analysis - ANY.RUN

image

Program is downloaded as an iso file, and contains several trojans such as Artemis, Cryptor, Generik, Wacatac. In order to run this program, users must create accounts on Free VPN service from BroVPN - VPN for Windows

Registered in New Providence, Bahamas via TLD Registrar Solutions Ltd. on October 3, 2018 (Updated March 21, 2022) - Whois brovpn.io

Associated Telegram Server - Telegram: Contact @brovpn_support_bot

Associated Email Address - [email protected]

Associated IP Addresses:
185.234.247.231

193.23.50.106

The VPN only has six servers: Canada, France, Germany, Netherlands, Poland and the United Kingdom.