CrunchyRoll hack delivers malware
ID: e4ab406d-a681-55a5-a1f1-1478c0b3628e
STIX ID: report--e4ab406d-a681-55a5-a1f1-1478c0b3628e
Feed Name: Blaze's Security Blog
A reported Crunchyroll website compromise led visitors to download a fake “CrunchyViewer.exe” that unpacked a malicious svchost.exe into %AppData%\Roaming, established persistence via a HKCU\...\Run key named “Java,” and communicated with a C2 at 145.239.41.131:6969 after being served from 109.232.225.12; subsequent analysis showed it could download Meterpreter, enabling full remote control. The post outlines removal steps (delete the Run key and svchost.exe, scan with AV/Malwarebytes, change passwords) and recommends standard hardening measures, noting the issue was swiftly addressed but advising users to remain cautious.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
