logo

CrunchyRoll hack delivers malware

ID: e4ab406d-a681-55a5-a1f1-1478c0b3628e

STIX ID: report--e4ab406d-a681-55a5-a1f1-1478c0b3628e

Feed Name: Blaze's Security Blog

Threat Score
70/100

Date Published: 2017-11-04

Date Updated: 2026-04-19

Author: Bart

...
...

A reported Crunchyroll website compromise led visitors to download a fake “CrunchyViewer.exe” that unpacked a malicious svchost.exe into %AppData%\Roaming, established persistence via a HKCU\...\Run key named “Java,” and communicated with a C2 at 145.239.41.131:6969 after being served from 109.232.225.12; subsequent analysis showed it could download Meterpreter, enabling full remote control. The post outlines removal steps (delete the Run key and svchost.exe, scan with AV/Malwarebytes, change passwords) and recommends standard hardening measures, noting the issue was swiftly addressed but advising users to remain cautious.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.