"One-Stop Data Recovery Solution for 100+ Data Loss Situations." TROJAN

Link (Dangerous): What is Recover? How It Works

Registered in Texas via GoDaddy on April 26, 2022 - Whois digitalgoodsdealer.com

image

VirusTotal - VirusTotal - File - 86b5e6a2baa14e8c9079b40be896628c45d9ccf21a6678ddecae4e5e1d8c60f5

Any.Run - TonerRecover.zip (MD5: 866CC448C5D90271B61149BFB627430C) - Interactive analysis - ANY.RUN

image

Program contains an archive bomb, the Kryptik trojan and a variant of the Redline stealer.

Associated Twitter Account - https://twitter.com/@recoveramogi

Associated IP Addresses:
141.8.194.74

45.67.231.57