Popular Anime Site Crunchyroll.com Hijacked to Distribute Malware

Discussion in 'malware problems & news' started by itman, Nov 6, 2017.

  1. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Appears to be a DNS hijack.
    https://www.bleepingcomputer.com/ne...unchyroll-com-hijacked-to-distribute-malware/
     
  2. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    I saw this malware at the beggining of the distribution, only Kaspersky of the traditional vendors detected it (static detection of course).
    I was disappointed at the speed of reaction from many vendors :thumbd:
     
    Last edited: Nov 6, 2017
  3. itman

    itman Registered Member

    Joined:
    Jun 22, 2010
    Posts:
    8,593
    Location:
    U.S.A.
    Problem with VT is they are only running the AV engines. For example, it could have been blacklisted in the AV rep scanner till a formal sig. issued.
     
  4. Nightwalker

    Nightwalker Registered Member

    Joined:
    Nov 7, 2008
    Posts:
    1,387
    Yes, I know that. ESET for example has a internal blacklist powered by the cloud (they reacted pretty quickly compared to the rest) and some other vendors could have protected their users with behavior block and more powerful local heuristics, but I am still disappointed.
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.