"Dr.Fone Root" TROJAN

Link (Dangerous): Dr.Fone Root | Free Android Root: Root Your Android Phone with One Click (drfoneroot.me)

Registered via NameCheap on February 10, 2022 - Whois drfoneroot.me

image

VirusTotal - VirusTotal - File - e9e2c22bf27cbe72cfc2e1cdc2a23781f7a72f7a161a2fe73b9dcd80a2d954bc

Any.Run - https://dl.dropboxusercontent.com/s/p8h7gwbbvqz1631/dr.fone-setup-1.8.3.78-x64_x86.rar - Interactive analysis - ANY.RUN

image

Program contains Trojan-Spy.Win32.Stealer.bmty

Associated Facebook Account - Dr.Fone

Worst part, the domain was originally designed to impersonate WonderShare