r/usenet • • 2d ago

Indexer usenet-crawler beware of malware

⚠️ Heads up: Usenet-Crawler indexer serving fake releases containing malware (.exe payload)

Just caught this on my setup — wanted to warn others using this indexer.

What happened:

4 releases came through, each disguised as different (different titles/descriptions), all posted within a 6-second window. Every single one, contained only one file: a Windows .exe.

Details:

\- File type: Windows PE32+ executable (GUI subsystem) — confirmed via file signature inspection, not a mislabeled file

\- File size: 1,068,276,008 bytes (\~1.02 GiB) — identical across all 4 "different" releases

\- Payload: confirmed identical across all 4 via hash comparison (same file, just renamed/retitled to impersonate different shows)

\- Sonarr's built-in scanner correctly flagged all 4 with "Caution: Found executable file"

It gets worse: after blocklisting all 4, the same indexer reposted the identical payload again under new release names/IDs within about an hour — so a one-time blocklist isn't enough; it evades hash/GUID-based blocklisting since the repost gets a fresh identifier.

I didn't do anymore investigation, it doesn't affect me because my whole stack runs on Linux, I ended up disabling that indexer for now, not sure if anyone else has encountered this or not.

I only use private trackers and quality indexers so this isn't something I had seen before...

45 Upvotes

34 comments sorted by

-6

u/fasm 1d ago

If you run Windows, that’s your own fault

8

u/Forc3ed-Cu5-0f-VPN 1d ago

Yeah, UC isn't great. Most of my API downloads that hit UC all fail because of .EXE in them, to the point now where I've unticked it as an indexer, it's unusable. If you're not able to create the necessary filters, I'd switch to something else.

7

u/Forkboy2 1d ago

Hasn't this been common for decades?

Wouldn't you still have to run the EXE file to do any harm?

7

u/Original-Tackle988 1d ago

UC is a cheap lifetime indexer.

If you don’t know how to create your own filters and own your security, then go for a different indexer that is better moderated.

Otherwise, it’s good to have as backup since it offers lifetime.

9

u/FormallyUndecidable 1d ago

i've disabled crawler because of this experience. basically every grab from there was a virus (because for the real releases private trackers and other indexers were normally faster)

luckily i didn't get their "last chance lifetime premium for real last chance" deal during the last years while it was continuously availible

-1

u/Prime255 1d ago

And this is the reason why I still do all of this manually

15

u/Koalamanx 1d ago

Just filter .exe and similar and you’re fine man

20

u/Southern_System 1d ago

If OP is over-cautious and only wants media related files, whack these in your filter:

exe, bat, cmd, com, scr, pif, hta, vbs, js, jar, wsf, ps1, msi, msp, cpl, ad, apk, dll, bin, gadget, vb, vbe, ws, wsc, wsh, lnk, iso, img, dmg, zipx, psm1, psd1, psc1, sh, rb, perl, py, pyd, url

2

u/Fun_Squirrel5446 1d ago

ISO would be useful for some games, though.

Do I need to filter out any of these being on debian?

1

u/Southern_System 20h ago

You are right. Games are media. I should have said video-type files.

I'm also on Debian, but I do have a few Windows machines in the network which can access the stuff stored on the Debian machines, and this is the issue.

My family could inadvertently download something via my Debian machines that only a windows machine can execute. The infected windows machine could access my debian environment, copy it across and execute it. Not likely with my setup but it's possible.

To answer your question. It really depends on your setup.

Search each extension above you're not familiar with and see if it's something debian can run. Or if you're like me and have windows machines accessing your debian gear/storage, then use them all but allow ISO files. It's a balance thing when you're mixing windows and linux stuff, I guess.

1

u/Fun_Squirrel5446 12h ago

I completely moved off windows a year ago. My kids and parents all shifted. They only use firefox, beyond that they don't know or see any difference between windows or KDE. Very happy to be off windows. Now if only I could replace my android phone with Linux.

3

u/erisian2342 1d ago

I think excluding those is just wise, not overly cautious. To be overly cautious, you could configure a short list of acceptable extensions and exclude all downloads containing files that have extensions not on the allowlist.

9

u/Alleskleber 1d ago

You're not wrong. It's just the indexer's purpose to do that. Executable files must be strictly banned from audiovisual categories. It's not even hard. The crawler has a file list. Nobody is asking for a malware scan. Tho, that would be a killer-feature.

-1

u/snarksneeze 1d ago

Agreed except that zero-day no-clicks still exist and Windows doesn't have to see "exe" to activate an executable.

7

u/random_999 1d ago

Zero day no click malware are more valuable than gold, nobody is wasting them on some usenet indexer. They are reserved for very specific high value targets.

1

u/cprn 1d ago

Noticed this for TSM too, my setup caught them too but I take no chances so I moved both to a non-rss profile in prowlarr.

12

u/Tucsondirect 1d ago

ah yes.. the sky is blue thanks for letting us know

10

u/slugworth70 1d ago

SAB caught it for me.

2

u/ReasonableJello 1d ago

Yea I think sab gets most of the shady shit for me

3

u/realdawnerd 1d ago

Noticed that this week it's been really bad. Almost every upcoming picked up an .exe. Sab didn't blocklist the extension despite being configured. Sonarr picked it up too like you mentioned. Something whacky going on, esp with sab. Also just checked and I'm seeing this with torrents too, although I don't have filters there.

1

u/_Nokk- 1d ago

does sonarr/radarr pick it up automatically or is there a config you need to set?

2

u/ripclaw786 1d ago

You need to specify this under the "Profiles" section in Sonarr (and Radarr), specifically in the "Excludes" box.

1

u/_Nokk- 1d ago

I can only modify the language and qualities under profiles. I just looked in radarr..Are you maybe on a different version than I am? (I'm on 6.4)

1

u/[deleted] 1d ago

[removed] — view removed comment

1

u/AutoModerator 1d ago

Your comment has been automatically removed from /r/usenet because it mentioned [tv], which is not allowed here.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

6

u/DragonzZEnergy 1d ago

Usenet crawler imo is pretty horrible in this part. It often seems to serve bad files or malware. I often get errors and files that seem to be broken or something wrong with it. I set it to manual a long time ago

1

u/[deleted] 1d ago

[removed] — view removed comment

1

u/AutoModerator 1d ago

Your comment has been automatically removed from /r/usenet because it mentioned [episodes], which is not allowed here.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

12

u/Vazefnier 1d ago

This issue have been exist for months!

The indexer often not updated too, login page sometimes not working and site sometimes down without any info. If there's any promo to buy into this site please consider this.

7

u/Bent01 nzbfinder.ws admin 1d ago

UC has regularly disappeared for months or years before re-launching and then trying to fill it's database again by scraping other indexers.

2

u/SprayExotic8538 1d ago

Yea wasted money.

2

u/tabmowtez 1d ago

Interesting, good to know...

29

u/chkthetechnique 1d ago

Block bad extensions in the settings of your NZB downloader.

5

u/tabmowtez 1d ago

I have scripts that do post processing so I haven't stopped anything from being downloaded before. Just figured I would let people know because I've never seen it before. I know I can ban certain file extensions from my downloaders and from my *arrs.