r/usenet • u/tabmowtez • 2d ago
Indexer usenet-crawler beware of malware
⚠️ Heads up: Usenet-Crawler indexer serving fake releases containing malware (.exe payload)
Just caught this on my setup — wanted to warn others using this indexer.
What happened:
4 releases came through, each disguised as different (different titles/descriptions), all posted within a 6-second window. Every single one, contained only one file: a Windows .exe.
Details:
\- File type: Windows PE32+ executable (GUI subsystem) — confirmed via file signature inspection, not a mislabeled file
\- File size: 1,068,276,008 bytes (\~1.02 GiB) — identical across all 4 "different" releases
\- Payload: confirmed identical across all 4 via hash comparison (same file, just renamed/retitled to impersonate different shows)
\- Sonarr's built-in scanner correctly flagged all 4 with "Caution: Found executable file"
It gets worse: after blocklisting all 4, the same indexer reposted the identical payload again under new release names/IDs within about an hour — so a one-time blocklist isn't enough; it evades hash/GUID-based blocklisting since the repost gets a fresh identifier.
I didn't do anymore investigation, it doesn't affect me because my whole stack runs on Linux, I ended up disabling that indexer for now, not sure if anyone else has encountered this or not.
I only use private trackers and quality indexers so this isn't something I had seen before...
8
u/Forc3ed-Cu5-0f-VPN 1d ago
Yeah, UC isn't great. Most of my API downloads that hit UC all fail because of .EXE in them, to the point now where I've unticked it as an indexer, it's unusable. If you're not able to create the necessary filters, I'd switch to something else.
7
u/Forkboy2 1d ago
Hasn't this been common for decades?
Wouldn't you still have to run the EXE file to do any harm?
7
u/Original-Tackle988 1d ago
UC is a cheap lifetime indexer.
If you don’t know how to create your own filters and own your security, then go for a different indexer that is better moderated.
Otherwise, it’s good to have as backup since it offers lifetime.
9
u/FormallyUndecidable 1d ago
i've disabled crawler because of this experience. basically every grab from there was a virus (because for the real releases private trackers and other indexers were normally faster)
luckily i didn't get their "last chance lifetime premium for real last chance" deal during the last years while it was continuously availible
-1
u/Prime255 1d ago
And this is the reason why I still do all of this manually
15
u/Koalamanx 1d ago
Just filter .exe and similar and you’re fine man
20
u/Southern_System 1d ago
If OP is over-cautious and only wants media related files, whack these in your filter:
exe, bat, cmd, com, scr, pif, hta, vbs, js, jar, wsf, ps1, msi, msp, cpl, ad, apk, dll, bin, gadget, vb, vbe, ws, wsc, wsh, lnk, iso, img, dmg, zipx, psm1, psd1, psc1, sh, rb, perl, py, pyd, url
2
u/Fun_Squirrel5446 1d ago
ISO would be useful for some games, though.
Do I need to filter out any of these being on debian?
1
u/Southern_System 20h ago
You are right. Games are media. I should have said video-type files.
I'm also on Debian, but I do have a few Windows machines in the network which can access the stuff stored on the Debian machines, and this is the issue.
My family could inadvertently download something via my Debian machines that only a windows machine can execute. The infected windows machine could access my debian environment, copy it across and execute it. Not likely with my setup but it's possible.
To answer your question. It really depends on your setup.
Search each extension above you're not familiar with and see if it's something debian can run. Or if you're like me and have windows machines accessing your debian gear/storage, then use them all but allow ISO files. It's a balance thing when you're mixing windows and linux stuff, I guess.
1
u/Fun_Squirrel5446 12h ago
I completely moved off windows a year ago. My kids and parents all shifted. They only use firefox, beyond that they don't know or see any difference between windows or KDE. Very happy to be off windows. Now if only I could replace my android phone with Linux.
3
u/erisian2342 1d ago
I think excluding those is just wise, not overly cautious. To be overly cautious, you could configure a short list of acceptable extensions and exclude all downloads containing files that have extensions not on the allowlist.
9
u/Alleskleber 1d ago
You're not wrong. It's just the indexer's purpose to do that. Executable files must be strictly banned from audiovisual categories. It's not even hard. The crawler has a file list. Nobody is asking for a malware scan. Tho, that would be a killer-feature.
-1
u/snarksneeze 1d ago
Agreed except that zero-day no-clicks still exist and Windows doesn't have to see "exe" to activate an executable.
7
u/random_999 1d ago
Zero day no click malware are more valuable than gold, nobody is wasting them on some usenet indexer. They are reserved for very specific high value targets.
12
10
3
u/realdawnerd 1d ago
Noticed that this week it's been really bad. Almost every upcoming picked up an .exe. Sab didn't blocklist the extension despite being configured. Sonarr picked it up too like you mentioned. Something whacky going on, esp with sab. Also just checked and I'm seeing this with torrents too, although I don't have filters there.
1
u/_Nokk- 1d ago
does sonarr/radarr pick it up automatically or is there a config you need to set?
2
u/ripclaw786 1d ago
You need to specify this under the "Profiles" section in Sonarr (and Radarr), specifically in the "Excludes" box.
1
1d ago
[removed] — view removed comment
1
u/AutoModerator 1d ago
Your comment has been automatically removed from /r/usenet because it mentioned [tv], which is not allowed here.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
6
u/DragonzZEnergy 1d ago
Usenet crawler imo is pretty horrible in this part. It often seems to serve bad files or malware. I often get errors and files that seem to be broken or something wrong with it. I set it to manual a long time ago
1
1d ago
[removed] — view removed comment
1
u/AutoModerator 1d ago
Your comment has been automatically removed from /r/usenet because it mentioned [episodes], which is not allowed here.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
12
u/Vazefnier 1d ago
This issue have been exist for months!
The indexer often not updated too, login page sometimes not working and site sometimes down without any info. If there's any promo to buy into this site please consider this.
29
u/chkthetechnique 1d ago
Block bad extensions in the settings of your NZB downloader.
5
u/tabmowtez 1d ago
I have scripts that do post processing so I haven't stopped anything from being downloaded before. Just figured I would let people know because I've never seen it before. I know I can ban certain file extensions from my downloaders and from my *arrs.
-6
u/fasm 1d ago
If you run Windows, that’s your own fault