Anon Files may be compromised

cvxcvgg

Newbie
Dec 30, 2019
96
179
Today I have attempted to download a few different .7z archives and was instead presented with a .exe file with the exact same name. Out of curiosity, I looked at the file and found that what I actually downloaded was some fake as hell weather program built with nw.js but I'm not sure what the purpose of the program is. Probably just your standard trojan.

Not sure if this will be resolved quickly but wanted to warn other users to either avoid Anon Files for now or otherwise be very mindful of what you are actually downloading.
 
  • Like
Reactions: scrumbles

anne O'nymous

I'm not grumpy, I'm just coded that way.
Modder
Donor
Respected User
Jun 10, 2017
10,391
15,307
Today I have attempted to download a few different .7z archives and was instead presented with a .exe file with the exact same name.
It's a dumb question, sorry for that. I try to eliminate the possible cause before stating that anon is effectively in cause.
Are you sure that you effectively clicked on the right download link ? It's more than frequent on hosting site to have the page filled with thousand of false link trying to lure you. And even when you're perfectly aware of it, there's days where you're too tired and just totally mess where you click.
 

cvxcvgg

Newbie
Dec 30, 2019
96
179
It's a dumb question, sorry for that. I try to eliminate the possible cause before stating that anon is effectively in cause.
Are you sure that you effectively clicked on the right download link ? It's more than frequent on hosting site to have the page filled with thousand of false link trying to lure you. And even when you're perfectly aware of it, there's days where you're too tired and just totally mess where you click.
Yes, I am aware that Anon likes to open new tabs and all that, but after following multiple links I wound up getting the same fake program with the same names as the .7z archives. This is several different archives, and after several attempts to download each of these archives, with the same result.
 

Niv-Mizzet the Firemind

Active Member
Mar 15, 2020
571
1,111
Would you mind sharing the links or the threads of the games you downloaded?
I downloaded 2 games out of curiousity from anonfiles (from the latest updates page) and are clean, as expected.
Maybe it's something on your end?
 

F4C430

Active Member
Dec 4, 2018
649
727
Would you mind sharing the links or the threads of the games you downloaded?
I downloaded 2 games out of curiousity from anonfiles (from the latest updates page) and are clean, as expected.
Maybe it's something on your end?
Same, i checked a couple as well and there's no problem. I've never seen anonfiles spawn new tabs.
 

cvxcvgg

Newbie
Dec 30, 2019
96
179
It may have to do with any ad/js blocker you're using. It doesn't spawn for me either, but my browser is rather locked up in that respect.
Yeah, Anon is shady as hell, but the ad-blocker would definitely help.

Also, this isn't the first time that the site has had a few hours of download links sending some bullshit virus weirdness instead of what you're looking for, and generally I've seen it resolve itself after an hour or two like nothing happened and with no mention of the issue. We really should just toss it off the approved list, because it's happened before, and the pop-ups are kind of gross.
 

scrumbles

Engaged Member
Jan 12, 2019
2,335
2,425
Same, it happened both to me (and not just once) and to some patrons of a top 100 game a few weeks ago.
The archive had the expected name, but the file size was just ~4 MB. Iirc it included a shady exe and a txt file with a password.

But maybe anonfiles did nothing wrong and those actually infected were our browsers, not their servers. Last time anonfiles returned that weird file, I tried the gofile link and I got the same suspicious file.

OP, try again with a different, clean browser + an adblock and see what happens. If anonfiles is actually compromised, you should download the same malware.
 

anne O'nymous

I'm not grumpy, I'm just coded that way.
Modder
Donor
Respected User
Jun 10, 2017
10,391
15,307
But maybe anonfiles did nothing wrong and those actually infected were our browsers, not their servers. [...]
There definitively something odd anyway.

I just tried to see if I get strange result myself, and, well, anonfiles is now unknown of all DNS. And I also tried root A and root K DNS, as well as the cloudfare DNS linked to the domain. Those who achieve to reach them do it because the entry is still in cache for the DNS they use, or in the cache of their OS.

I don't know about cloudfare policy in case of non-payment, but well, it was past 00:00 GMT the first of the month when I tried, so it can be that.
And if effectively they didn't payed, it's not impossible that used their last days online doing a dick move to earn some money in another way.


If anonfiles is actually compromised, you should download the same malware.
I depend how deeply it have been compromised. It's not really difficult to put a script that will randomly pick the malware sent in place of the requested archive.
It's not trivial, since you still need the writing rights for the HTTP server, but it's all you need. And if the server isn't correctly protected, it's something that can possibly be achieved more easily that being granted root access.
 
  • Like
Reactions: cvxcvgg

MissFortune

I Was Once, Possibly, Maybe, Perhaps… A Harem King
Respected User
Game Developer
Aug 17, 2019
4,935
8,054
It may have to do with any ad/js blocker you're using. It doesn't spawn for me either, but my browser is rather locked up in that respect.
If someone's not using uBlock Origin for every website, then they're just outright asking for it. Especially on websites with intrusive ads.
 
  • Like
Reactions: Jaike and Hagatagar

Hagatagar

Well-Known Member
Oct 11, 2019
1,024
3,008
I wanted to test how the Firefox addon Popup Blocker (strict) handles it, but I can't even access ************* anymore. :oops:
 

anne O'nymous

I'm not grumpy, I'm just coded that way.
Modder
Donor
Respected User
Jun 10, 2017
10,391
15,307
Just now I tried the links of the 3 newest updated games and it seems they are still uploaded to the old url (*************). :unsure:
Look my comment above, it's because the entries are still the the cache of the DNS they use, or the one of their OS.


Edit:
Also I wonder what make them pass from a domain name they registered until 2030, to one registered for only two years.
 

Darth Vengeant

Active Member
May 6, 2020
943
1,107
It just did this to me. Many Add blockers, etc. It download a .iso instead of your .zip that has spam/garbage in it. This has only started since the "We need help" stuff started popping up recently.
 

Odinn7

New Member
Mar 14, 2021
6
2
It just did this to me. Many Add blockers, etc. It download a .iso instead of your .zip that has spam/garbage in it. This has only started since the "We need help" stuff started popping up recently.
If one were to have downloaded and executed this, what would you do to solve any problems? It seems to be adware but I’m unsure if there’s anything more dangerous involved. Malwarebytes doesn’t register any threats, rKill doesn’t find any processes to terminate.

I found stream link-twitch-gui files within my local and localLow file space and promptly removed them. Though I’m concerned there’s stuff leftover. I also ran Combo Cleaner which identified spam in the Edge file space and removed it. Am I missing anything?