Date: 09/21/2026
Severity: Medium
Summary
Torrent trackers are frequently abused to distribute malware disguised as popular movies, games, and pirated software. Attackers use cracked software and malicious installers to infect large numbers of users. During the analysis, researchers discovered a new modular, multi-stage malware framework called MovieReaper. The campaign began by compromising torrent tracker storage to distribute malicious files to users. Hundreds of victims were identified across countries including Russia, Türkiye, Japan, Kenya, Uganda, Colombia, Spain, and the Netherlands.
Indicators of Compromise (IOC) List
Domain/URLs | deadhub.org |
IP Address | 193.23.118.155 208.64.33.90 208.94.246.53 |
Hash | 4334BBAEA8DE33BF9D45E9B4E4E3BC2
4843F9FAFCAE492F11E2D4D33DBB4CDD
5310CABAE3FBE6DB8742849B588093F9
A0B13781EDD7CFDAB13D79AFFF3C83C1
70060341CAF3338697A7DDFE0FB62875
AD4643EEA15AC286FA47D1131F9EF756
D0B967571AC8A3863C7F324BF5BDE99C
D88D550D0FB8E60CFFFF3EA61FF7A067
|
Filepath | %ProgramData%\Microsoft\Windows\Telemetry\msedge.exe |
Mutex | Global\E4AyDKzvEhe2hgAr Global\fnulSktzSqvVLXHU |
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "deadhub.org" or url like "deadhub.org" or siteurl like "deadhub.org" |
Detection Query 2 : | dstipaddress IN ("193.23.118.155","208.94.246.53","208.64.33.90") or srcipaddress IN ("193.23.118.155","208.94.246.53","208.64.33.90") |
Detection Query 3 : | md5hash IN ("4843F9FAFCAE492F11E2D4D33DBB4CDD","D0B967571AC8A3863C7F324BF5BDE99C","4334BBAEA8DE33BF9D45E9B4E4E3BC2","5310CABAE3FBE6DB8742849B588093F9","A0B13781EDD7CFDAB13D79AFFF3C83C1","70060341CAF3338697A7DDFE0FB62875","AD4643EEA15AC286FA47D1131F9EF756","D88D550D0FB8E60CFFFF3EA61FF7A067")
|
Detection Query 4 : | datasourcename = "Windows Security" and eventtype = "4663" and objectname like "%ProgramData%\Microsoft\Windows\Telemetry\msedge.exe" |
Detection Query 5 : | technologygroup = "EDR" and objectname like "%ProgramData%\Microsoft\Windows\Telemetry\msedge.exe" |
Reference:
https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/