CrunchyRoll.com is serving ransomware
reddit.com
reddit.com
It seems to be a very clearly targeted payload, named CrunchyViewer.exe. It could be served through a DNS hijack of some sort[8]. It's a modified version of Taiga[4], making it seem like a legitimate application and flying under many anti-malware programs' radars.
Apparently the exact malware strain is currently unknown. Most likely it is ransomware that activates on reboot[5]. Given there are traces of a command and control server[2] and the Lilith open source RAT[6], the ransomware payload may be supplied by the CnC server.
An overview can also be found at [7].
[1] https://www.virustotal.com/#/file/eae53d89d7add187dfe6f4498c...
[2] https://www.hybrid-analysis.com/sample/eae53d89d7add187dfe6f...
[3] https://www.reddit.com/r/anime/comments/7aq2s7/psa_dont_ente...
[4] http://taiga.moe
[5] https://twitter.com/Swaps4/status/926793261884125192
[6] https://twitter.com/GossiTheDog/status/926818116121841665
[7] https://doublepulsar.com/crunchyroll-serving-remote-access-m...
[8] https://twitter.com/Crunchyroll_de/status/926791185217269760
That looks like a very bad policy in this situation. Don't they have anyone on call for security/infrastructure? Or don't they have access to the social media accounts for these kind of situations? I know hindsight is 20/20 but really, whole Europe knows English and not even one person outside the Americas can access the official twitter account?
At least the banter on /a/ makes this tolerable
>>"don't torrent you will get virus!" >>"use CR instead!" >>use CR >>get hacked and virus
https://www.reddit.com/r/Crunchyroll/comments/5oug4a/apparen...
https://twitter.com/Crunchyroll_de/status/926782599460212736
And for our English-speaking audience
Please DO NOT access our website at the current time. We
are aware of the issues and are working on it
Update: We have NOT been hacked. At the moment, it appears to be DNS hijacking.A google search for "crunchyroll" returns as the first result an HTTP link. Had they used HTTPS, would it have prevented the attack (turning it into a denial-of-service instead), or would the DNS hijack be enough for the attacker to obtain a valid certificate?