AmarS
August 30, 2021, 2:31pm
1
Domains used: High-Speed, Secure & Anonymous VPN Service | ExpressVPN (expresvpn.site)
A WhoIs lookup reveals the domain was registered in United States via Beget LLC on August 28, 2021 - Whois expresvpn.site
Download link: ExpressVPN.exe
VirusTotal: VirusTotal
1 Like
Jer123
August 30, 2021, 4:14pm
2
The malware installer is hosted on the official discord servers. I reported it to them.
Also contacted the host and Expressvpn. The site for sure looks legit.
I saw this one coming. Thanks for reporting it. Site seems to be blocked by the hosting/registrar already.
Jer123
August 30, 2021, 8:49pm
4
The hosting provider of the site has blocked the page.
Lurker
August 30, 2021, 10:24pm
5
Is there really no way to report the malware to Discord?
Jer123
September 1, 2021, 8:16am
6