There are some torrrents showing up with .lnkextension (ex: movie.mp3.lnk, tvshow.mkv.lnk) and automated software (Sonarr, Radarr, Lidarr, qBittorrent RSS Downloader) could pick those torrents (but not import).

These (fake) torrents include a .lnk file that executes a script on your Windows


HOW TO exclude from download on qBittorrent.

  • Go to Options -> Downloads

  • Enable “Exclude file names”

  • Add patterns:

(one by line)

*.mp4.lnk  
*.mp3.lnk  
*.mkv.lnk
*.torrent.lnk 

Or exclude all together: *.lnk


Example on VirusTotal https://www.virustotal.com/gui/file/e74f64df6ebaf3a1b6e3f42591eb6e87d2ac2828eb5a99fd8d3d82c140137fc9/detection

    • wizardbeardEnglish
      arrow-up
      41
      arrow-down
      0
      ·
      18 days ago
      edit-2
      18 days ago
      link
      fedilink

      Yes, but also whoever set the defaults for the *arr tools. Why would any filename with extra shit past the extensions you’re looking for be considered an acceptable result?

      Tack $ on the end of your regex, for fucks sake.

      • American_JesusOPEnglish
        arrow-up
        8
        arrow-down
        1
        ·
        17 days ago
        edit-2
        17 days ago
        link
        fedilink

        Is not regex
        https://github.com/qbittorrent/qBittorrent/pull/17106

        Examples
        *.exe: filter ‘.exe’ file extension.
        readme.txt: filter exact file name.
        ?.txt: filter ‘a.txt’, ‘b.txt’ but not ‘aa.txt’.
        readme[0-9].txt: filter ‘readme1.txt’, ‘readme2.txt’ but not ‘readme10.txt’

    • ad_on_isEnglish
      arrow-up
      21
      arrow-down
      1
      ·
      17 days ago
      edit-2
      17 days ago
      link
      fedilink

      Microsoft: De nada, amigo! Oh here’s an ad, btw anddid you enable Recall already?

      • ReversalHatcheryEnglish
        arrow-up
        12
        arrow-down
        0
        ·
        17 days ago
        link
        fedilink

        or rather: oh silly you were so clumsy that you disabled recall by accident again. let us be so kind to re-enable it for you

      • Boomkop3English
        arrow-up
        4
        arrow-down
        0
        ·
        16 days ago
        link
        fedilink

        Have you tried setting your region to Europe? it’s not an issue here

    • CmdrShepard42English
      arrow-up
      86
      arrow-down
      0
      ·
      18 days ago
      link
      fedilink

      What if it executes and install Windows 11 on your machine!?

      • black0utEnglish
        arrow-up
        40
        arrow-down
        0
        ·
        18 days ago
        link
        fedilink

        Oh lord please have mercy! Blacklisting the file extension right now!

      • TrentEnglish
        arrow-up
        22
        arrow-down
        0
        ·
        18 days ago
        link
        fedilink

        That would be the very worst malware. I mean both the malware that installed it and win11

      • Aatube
        arrow-up
        11
        arrow-down
        3
        ·
        18 days ago
        link
        fedilink

        ackshually the proprietary .lnk shortcut format can only be run on windows 🤓

        • Avid AmoebaEnglish
          arrow-up
          5
          arrow-down
          1
          ·
          18 days ago
          link
          fedilink

          A Linux executable can’t be named ending on .lnk? 🤔🤔

          • Aatube
            arrow-up
            5
            arrow-down
            1
            ·
            17 days ago
            link
            fedilink

            Making such a polyglot that can run on both systems requires much more effort for little gain.

          • mexicancartelEnglish
            arrow-up
            3
            arrow-down
            0
            ·
            17 days ago
            link
            fedilink

            But its not lnk but an executable that needs to be excecuted manually?

    • American_JesusOPEnglish
      arrow-up
      25
      arrow-down
      0
      ·
      18 days ago
      link
      fedilink

      Me too, but don’t want to download GBs of malware and bandwidth

      • LiveLMEnglish
        arrow-up
        18
        arrow-down
        1
        ·
        18 days ago
        edit-2
        18 days ago
        link
        fedilink

        Weak.
        Harbor disaster. Seed the malware. Spread the fruits of chaos amongst the unworthy. Be complicit in their downfall. Feed on their agony ^^/s

      • catloafEnglish
        arrow-up
        2
        arrow-down
        1
        ·
        18 days ago
        link
        fedilink

        .lnk files are less than 4kb

        • Aatube
          arrow-up
          5
          arrow-down
          0
          ·
          18 days ago
          link
          fedilink

          That would seem suspicious. I’m sure they have some way to pad out the size.

          • catloafEnglish
            arrow-up
            5
            arrow-down
            0
            ·
            18 days ago
            link
            fedilink

            Anyone paying attention to size would probably also notice they’re just .lnk files.

            • Aatube
              arrow-up
              3
              arrow-down
              0
              ·
              18 days ago
              link
              fedilink

              Not necessarily. Even with “hide extensions” unchecked, Windows hides the .lnk extension by default; it just shows an arrow in the bottom-right corner of the icon, which is plausibly missed when in the list view. I’m surprised antivirus doesn’t know about it already tbh.

        • American_JesusOPEnglish
          arrow-up
          3
          arrow-down
          0
          ·
          18 days ago
          edit-2
          18 days ago
          link
          fedilink

          Not these ones, some could have more than 1GB, look at the virustotal link, the file had 422MB.

          Also Sonarr/Radarr filter torrents by size

          Here some examples
          https://bt4gprx.com/search?q=The.Lord.of.The.Rings.The.Rings.of.Power.S02E08

          Those where posted on 1337x (and removed) and probably other sites, Sonarr can pick those based on release name and torrent size

          PS: had to rename the fine from .lnk to .com so virustotal could accept

  • Daemon SilversteinEnglish
    arrow-up
    53
    arrow-down
    0
    ·
    18 days ago
    link
    fedilink

    When I read the title, I was thinking of something sophisticated such as hidden executable streams inside the MKV container (IIRC, it’s possible to append binary data other than audio, video or subtitles specifically inside a MKV). The .lnk” trick only works in Windows and, even there, it’s easy to prevent: Windows Explorer > Options > Advanced > find and check “Always show extensions for files” (i can’t really remember the exact label for this option as I’m not a Windows user, but something like this will be there).

    • American_JesusOPEnglish
      arrow-up
      20
      arrow-down
      0
      ·
      17 days ago
      link
      fedilink

      Sonarr will still pick the release and download GBs of malware, and if you don’t notice your download directly is filled with GBs of fake torrents

  • bad_newsEnglish
    arrow-up
    39
    arrow-down
    0
    ·
    18 days ago
    link
    fedilink

    You gotta love how aggressively they prevent users from seamlessly running executables from the internet, a VERY legitimate common use case, but a desktop shortcut from the internet? Run away!

  • Bobby TurkalinoEnglish
    arrow-up
    32
    arrow-down
    1
    ·
    18 days ago
    link
    fedilink

    Yet another reminder that piracy on Linux is the way because new files don’t have execute permissions by default

    • American_JesusOPEnglish
      arrow-up
      12
      arrow-down
      0
      ·
      18 days ago
      link
      fedilink

      On many distros will open with WINE by default, not a big deal, you can just delete ~/.wine. If it does anything

  • KuvwertEnglish
    arrow-up
    21
    arrow-down
    3
    ·
    18 days ago
    link
    fedilink

    Could you just add *.lnk?

    • canEnglish
      arrow-up
      11
      arrow-down
      0
      ·
      18 days ago
      link
      fedilink

      That’s mentioned near the bottom of the post.

  • woodgenEnglish
    arrow-up
    19
    arrow-down
    2
    ·
    16 days ago
    link
    fedilink

    that executes a script on your Windows.

    I don’t have a Windows.

  • N0x0nEnglish
    arrow-up
    17
    arrow-down
    0
    ·
    17 days ago
    edit-2
    16 days ago
    link
    fedilink

    For those interested, John Hammond did a video a few months ago about .lnk extension (and other 16 hidden extensions on Windows).

    He doesn’t go to much or to deep into the subject, but you get a general view how this could be exploitable.

    YouTube link

    Piped Link

  • LojcsEnglish
    arrow-up
    5
    arrow-down
    0
    ·
    18 days ago
    link
    fedilink

    How is the link file executing malware? Can you put any shell script as the target?

    • LordeMostardaEnglish
      arrow-up
      12
      arrow-down
      0
      ·
      18 days ago
      link
      fedilink

      I am pretty sure a link file can open cmd/powershell with parameters to execute commands

      • montarEnglish
        arrow-up
        3
        arrow-down
        0
        ·
        16 days ago
        link
        fedilink

        yep! I’ve found out browsing hacking/spamming site and i’ve found something too good to be true, it downloaded archive nested inside other archive and in it was silngle .lnk file leading to “the resource”. Peeking inside i’ve found powershell executing base64 (or base32?) encoded script (it’s got commandline option for that. if you want to ask wtf ask microsoft, and tell me), it dl’d some exe from some site and ran it, site was down alredy.

    • wizardbeardEnglish
      arrow-up
      8
      arrow-down
      0
      ·
      18 days ago
      link
      fedilink

      You can put the script itself as the link. Shortcut to: powershell -command “Write-Host ‘Gonna pwn your shit’”

  • LostXOR
    arrow-up
    4
    arrow-down
    0
    ·
    18 days ago
    link
    fedilink

    Also make sure you have file extensions enabled in Explorer, it makes it waaay harder for something like this to work.

  • NexyEnglish
    arrow-up
    2
    arrow-down
    1
    ·
    18 days ago
    link
    fedilink

    Nice to know! Thank you!

  • DoucheBagMcSwagEnglish
    arrow-up
    1
    arrow-down
    0
    ·
    18 days ago
    link
    fedilink

    Is that the malware that is undetectable because it runs purely in memory? The name is escaping me

  • XianshiEnglish
    arrow-up
    1
    arrow-down
    0
    ·
    12 days ago
    link
    fedilink

    Nice one OP. Just had sonar pick up one of these today named like a proper release of a trusted group. Sonarr didn’t move it from qbit but better to not DL it in the first place even though its a linux box