"Hide.me VPN" TROJAN

[color=#FF00]Link (Dangerous): Download Our Free VPN Client for Windows | hide.me (hidemevpn.tech) [/color]

Registered in Leningradskaya, Russia via Reg.Ru on January 4, 2022 (updated January 9, 2022) - Whois hidemevpn.tech

image

VirusTotal - VirusTotal - File - 336b4e27125f4ea77206b3d50930ffc6d4fac34648d72bdc88662ad1687d3e58

Any.Run - Hide_me_vpn.zip (MD5: 0C1CA64149C67EF361D35ECB490C6D82) - Interactive analysis - ANY.RUN

image

Associated Facebook Account - Deya gaming | Facebook

Associated IP Addresses:
46.8.220.88

Program contains several trojans, including AgentTesla, Asprotect, Convagent, SusGen & a variant of the Redline Tracker.

Looking into the IP (46.8.220.88) reveals that it is a data center IP - contell.ru to be precise.

Running a port scan on the IP reveals that there are no open ports (unfiltered). Ports 111/tcp, 135/tcp, 136/tcp, 137/tcp, 138/tcp, & 139/tcp are filtered (firewall.)

The server is running Windows (Unable to determine the version but it is most likely Windows 10 - server edition)