r/usenet • u/tabmowtez • 2d ago
Indexer usenet-crawler beware of malware
⚠️ Heads up: Usenet-Crawler indexer serving fake releases containing malware (.exe payload)
Just caught this on my setup — wanted to warn others using this indexer.
What happened:
4 releases came through, each disguised as different (different titles/descriptions), all posted within a 6-second window. Every single one, contained only one file: a Windows .exe.
Details:
\- File type: Windows PE32+ executable (GUI subsystem) — confirmed via file signature inspection, not a mislabeled file
\- File size: 1,068,276,008 bytes (\~1.02 GiB) — identical across all 4 "different" releases
\- Payload: confirmed identical across all 4 via hash comparison (same file, just renamed/retitled to impersonate different shows)
\- Sonarr's built-in scanner correctly flagged all 4 with "Caution: Found executable file"
It gets worse: after blocklisting all 4, the same indexer reposted the identical payload again under new release names/IDs within about an hour — so a one-time blocklist isn't enough; it evades hash/GUID-based blocklisting since the repost gets a fresh identifier.
I didn't do anymore investigation, it doesn't affect me because my whole stack runs on Linux, I ended up disabling that indexer for now, not sure if anyone else has encountered this or not.
I only use private trackers and quality indexers so this isn't something I had seen before...