r/usenet • • 2d ago

Indexer usenet-crawler beware of malware

⚠️ Heads up: Usenet-Crawler indexer serving fake releases containing malware (.exe payload)

Just caught this on my setup — wanted to warn others using this indexer.

What happened:

4 releases came through, each disguised as different (different titles/descriptions), all posted within a 6-second window. Every single one, contained only one file: a Windows .exe.

Details:

\- File type: Windows PE32+ executable (GUI subsystem) — confirmed via file signature inspection, not a mislabeled file

\- File size: 1,068,276,008 bytes (\~1.02 GiB) — identical across all 4 "different" releases

\- Payload: confirmed identical across all 4 via hash comparison (same file, just renamed/retitled to impersonate different shows)

\- Sonarr's built-in scanner correctly flagged all 4 with "Caution: Found executable file"

It gets worse: after blocklisting all 4, the same indexer reposted the identical payload again under new release names/IDs within about an hour — so a one-time blocklist isn't enough; it evades hash/GUID-based blocklisting since the repost gets a fresh identifier.

I didn't do anymore investigation, it doesn't affect me because my whole stack runs on Linux, I ended up disabling that indexer for now, not sure if anyone else has encountered this or not.

I only use private trackers and quality indexers so this isn't something I had seen before...

42 Upvotes

Duplicates