Fake Windscribe TROJAN - (981) 845-69-92

Link (Dangerous) - Windscribe - Free VPN and Ad Block (windwriter.net)

Registered by lynnwood12 in the Russian Federation via PublicDomainRegistry on June 22, 2022 - Whois windwriter.net

image

VirusTotal - VirusTotal - File - 57b8fd59637bc31968e6dff87f8bc6c2c54c46cd763c8e9386c49d47eaeaee38

I am unable to perform an Any.Run as the program crashes

Program is downloaded from Discord and contains the AgentTesla trojan and an archive bomb.

Associated Facebook Account - Dire my (facebook.com)

Associated Phone Number (RUSSIA) - +7 (981) 845-69-92

image

Associated Email Address - [email protected]

Associated IP Address - 2a01:7a7:2:21c7:3eec:efff:fe23:29a

Other domains hosted on the IP address include

1 Like