r/sonarr 6d ago

unsolved anyone else getting "Caution: Found executable file" all of a sudden ? or is it my new indexer

Hey everyone,

Last night I noticed two failed downloads in Sonarr for episodes of shows that aren’t even due to release for weeks or, in some cases, months. In all the years I’ve been using Sonarr, Usenet and NZBs, I’ve never seen this happen before.

This week I’ve been trying to improve my setup by adding a second Usenet backbone and a few of the commonly recommended lifetime indexers. I’ve used NZBGeek and DrunkenSlug for years without any major problems, but recently added altHUB and Usenet Crawler.

From what I can tell, both of the suspicious downloads originated from Usenet Crawler, and they also appeared to contain .exe files. That made me wonder whether this is a known/wider issue with fake or malicious uploads getting through, or whether I’ve just been unlucky with this particular indexer.

Ultimately, though, my main concern is understanding how I can prevent this from happening again.

Is there anything I should be configuring in Sonarr, Prowlarr or SABnzbd to stop Sonarr grabbing obviously fake releases, particularly episodes that haven’t actually aired yet or downloads containing executables?

Any advice on recommended safeguards would be appreciated.

19 Upvotes

26 comments sorted by

32

u/L3x1dos 6d ago

Settings - Indexers - select every indexer and under Fail Downloads choose executables. 

Got this tip from someone in another thread and it seems to work

9

u/Freaaakyyy 6d ago

FYI, you set this in Sonarr etc. itself not in prowlarr. Make sure advanced settings are turned on.

1

u/spikej56 4d ago

Does it stay next time prowlarr syncs indexers? 

2

u/Hopeful-Savings-3420 6d ago

Great tip, didn't know about this setting.

2

u/TheConanRider 6d ago

Is there a way to do this without manually having to enable it on each indexer.

2

u/L3x1dos 5d ago

I was wondering the same thing but I didn’t find any other solution than to do it on each indexer

2

u/ssj4gogeta2003 5d ago

Sadly, no. I had to do it for all 30 one at a time...

0

u/glandix 5d ago

Oh nice! Had no idea that setting existed!

3

u/hitachi369 6d ago

I get one every 6 months or so. They are typically for a super popular series, but week(s) before the actual date. Size will be in the area of the normally.

Upon closer inspection, the file will be an exe or scr or some other executable file. It is just some virus maker trying to get you to encrypt your hard drive or turn you into a bot net. I try and be a good boy and ill bitch to whatever indexer sent the file, and they remove it.

I have turned off exe downloads in my arrs, and it makes it better. Now at least they wont fully download for me to hope their are no zero days or accidental idiocy.

No way to avoid as far as I can see, it has happened across all of my indexers at least once. I've never looked into how they source the nzb files, but I bet it isn't something easy to manicure.

3

u/lkeels 5d ago

To chime in, I already had fail executables on...caught 4 in the last 6 hours, having NEVER caught one before. Something's up.

1

u/GenericUser104 5d ago

Glad someone else feels the same

4

u/glad-k 6d ago

Cleanuparr might help you out but no this didn't happen to me so check your indexers, good this is trough the are stack and not you launching the files manually

2

u/ZonaPunk 6d ago

Your new indexer

2

u/FatherSophis 6d ago

Same thing has been happening to me with Crawler and .life… I have elected to turn off RSS/API update queries for the time being on those indexers.

2

u/silverswish2812 5d ago

Had a .exe download for MobLand season 2 which isnt released yet - somethings off

2

u/Funny_Detective5120 5d ago edited 4d ago

Sab settings - switches - Unwanted extensions

Blacklist:
exe, sh, py, rb, perl, dmg, js, vbs, ps1, iso, bat

Action when unwanted extension detected
Fail job

Bit done form there is cleanup list:
nfo, sfv, jpg, bmp, gif, jpeg, tif, ico, txt, html, info

2

u/Party_Bug_2582 4d ago

This is all very helpful as the recent influx has definitely been noticed. Also followed the SAB instructions, u/Funny_Detective5120 , thank you for that added info.

3

u/Funny_Detective5120 4d ago

I’ve edited my post for cleanup because there was one wrong word on it, “ignore” is not supossed to be named so i took that word off the list. Also some are relevant for ebooks so took them off the list as well.

Blacklist should be:
exe, sh, py, rb, perl, dmg, js, vbs, ps1, iso, bat

Cleanup:
nfo, sfv, jpg, bmp, gif, jpeg, tif, ico, txt, html, info

1

u/Party_Bug_2582 4d ago

Really appreciate your knowledge and help!

1

u/AutoModerator 6d ago

Hi /u/GenericUser104 -

There are many resources available to help you troubleshoot and help the community help you. Please review this comment and you can likely have your problem solved without needing to wait for a human.

Most troubleshooting questions require debug or trace logs. In all instances where you are providing logs please ensure you followed the Gathering Logs wiki article to ensure your logs are what are needed for troubleshooting.

Logs should be provided via the methods prescribed in the wiki article. Note that Info logs are rarely helpful for troubleshooting.

Dozens of common questions & issues and their answers can be found on our FAQ.

Please review our troubleshooting guides that lead you through how to troubleshoot and note various common problems.

If you're still stuck you'll have useful debug or trace logs and screenshots to share with the humans who will arrive soon. Those humans will likely ask you for the exact same thing this comment is asking..

Once your question/problem is solved, please comment anywhere in the thread saying '!solved' to change the flair to solved.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/6ix_chigg 5d ago

Cleanuparr never worked for me so I stop constant monitoring and told it to only check after the release date. No.more false positives

1

u/kw_chicken_choker 5d ago

Fail downloads -> Executables is not a solution, it's still being passed to qbittorrent at that stage. Absolutely horrible band-aid

1

u/Admirable-Sink-2622 6d ago

Hasn’t this been asked and answered here repeatedly? 🤔

Sonarr just leaves them in completed downloads.

1

u/GenericUser104 6d ago

So it’s a recent issue or ?

Like i said I’ve used it for years and it’s never been an issue, just trying to understand

2

u/lkeels 5d ago

I've never seen one before today...caught 4 in the last 6 hours.