Malware News FBI: Free file converter sites and tools deliver malware

Gandalf_The_Grey

Level 85
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
7,778
Malware peddlers are increasingly targeting users who are searching for free file converter services (websites) and tools, the FBI’s Denver Field Office has warned earlier this month.

“To conduct this scheme, cyber criminals across the globe are using any type of free document converter or downloader tool. This might be a website claiming to convert one type of file to another, such as a .doc file to a .pdf file. It might also claim to combine files, such as joining multiple .jpg files into one .pdf file. The suspect program might claim to be an MP3 or MP4 downloading tool,” the FBI said.

“These converters and downloading tools will do the task advertised, but the resulting file can contain hidden malware giving criminals access to the victim’s computer.”

Also, some of these tools and services can analyze the files submitted by the users, and scrape them for personal identifying information (PII), banking and crypto-related info (e.g., crypto wallet seed phrases), passwords, and other sensitive information.
Malwarebytes researcher Pieter Arntz provided a list of domains hosting sites that ostensibly provide file conversion services or tools, but actually engage in phishing and delivering trojans, adware and “riskware” – a category that encompasses programs that are not strictly malicious, but pose some sort of risk for the user (e.g., programs that can be used as a backdoor for other malware, may be illegal, or may violate the terms of service of other software or a user platform):
  • Imageconvertors[.]com (Phishing)
  • Convertitoremp3[.]it (Riskware)
  • Convertisseurs-pdf[.]com (Riskware)
  • Convertscloud[.]com (Phishing)
  • Convertix-api[.]xyz (Trojan)
  • Convertallfiles[.]com (Adware)
  • Freejpgtopdfconverter[.]com (Riskware)
  • Primeconvertapp[.]com (Riskware)
  • 9convert[.]com (Riskware)
  • Convertpro[.]org (Riskware)
 

Zero Knowledge

Level 20
Verified
Top Poster
Content Creator
Dec 2, 2016
970
Yeah it's a problem, converting YouTube to 320kbs is a pain now :poop:. Sites offering malware extensions so be careful, site admins limit you if you convert too much (YES I know your watching :cautious:).
 

nicolaasjan

Level 5
Verified
Well-known
May 29, 2023
232
See also:
Malware News - FBI Denver Warns of Online File Converter Scam ;)

Just to be sure, I put these in my hosts file:
Code:
0.0.0.0 9convert.com
0.0.0.0 convertallfiles.com
0.0.0.0 convertisseurs-pdf.com
0.0.0.0 convertitoremp3.it
0.0.0.0 convertix-api.xyz
0.0.0.0 convertpro.org
0.0.0.0 convertscloud.com
0.0.0.0 freejpgtopdfconverter.com
0.0.0.0 imageconvertors.com
0.0.0.0 primeconvertapp.com

For file conversion, I have several shell scripts, which can be called via the right-click menu on Linux Mint. :)
 
Last edited:

brambedkar59

Level 33
Verified
Top Poster
Well-known
Apr 16, 2017
2,235
Yeah it's a problem, converting YouTube to 320kbs is a pain now :poop:.
Why would you even do that? Convert from one lossy codec to another lossy codec. Losing quality while increasing file size. Instead download the file in whatever format it is stored on YT servers (eg. Opus, aac etc.) with yt-dlp.

Edit: m4a is a container not a codec
 
Last edited:

Morro

Level 20
Verified
Top Poster
Well-known
Jul 8, 2012
961
See also:
Malware News - FBI Denver Warns of Online File Converter Scam ;)

Just to be sure, I put these in my hosts file:
Code:
0.0.0.0 9convert.com
0.0.0.0 convertallfiles.com
0.0.0.0 convertisseurs-pdf.com
0.0.0.0 convertitoremp3.it
0.0.0.0 convertix-api.xyz
0.0.0.0 convertpro.org
0.0.0.0 convertscloud.com
0.0.0.0 freejpgtopdfconverter.com
0.0.0.0 imageconvertors.com
0.0.0.0 primeconvertapp.com

For file conversion, I have several shell scripts, which can be called via the right-click menu on Linux Mint. :)

Added those to my NextDNS blocklist. (y)

Why would you even do that? Convert from one lossy format to another lossy format. Losing quality while increasing file size. Instead download the file in whatever format it is stored on YT servers (eg. Opus, m4a, aac etc.) with yt-dlp.

Never heard of that one, will take a look at it. :)
 

brambedkar59

Level 33
Verified
Top Poster
Well-known
Apr 16, 2017
2,235
Never heard of that one, will take a look at it. :)
Just to be clear yt-dlp is a cmd-line open source program with no official GUI. There are several unofficial GUIs available for it, I use this:

Edit: changed "native" to "official"
 
Last edited:

Morro

Level 20
Verified
Top Poster
Well-known
Jul 8, 2012
961

Zero Knowledge

Level 20
Verified
Top Poster
Content Creator
Dec 2, 2016
970
Why would you even do that? Convert from one lossy format to another lossy format. Losing quality while increasing file size. Instead download the file in whatever format it is stored on YT servers (eg. Opus, m4a, aac etc.) with yt-dlp.
Audio formats/quality is a subject I'm not a expert in, thanks for the link. I just assumed 320kbs is the highest audio rate and quality under FLAC. Never knew there were better options.
 

nicolaasjan

Level 5
Verified
Well-known
May 29, 2023
232
I just assumed 320kbs is the highest audio rate and quality under FLAC.
The aac (in m4a container) and especially the opus codec achieve the same quality at roughly half the bitrate. :)
(opus is the best option, but not all devices can play it)

Also, it depends on the quality of the audio that was uploaded to YouTube in the first place!
Some just upload 128kbps mp3 grabbed from e.g. Soundcloud. :eek:
YT then converts it to m4a and opus and in the process there is even more loss.

mp3 is considered ancient now.
 

The_King

Level 12
Verified
Top Poster
Well-known
Aug 2, 2020
553
Just to be clear yt-dlp is a cmd-line open source program with no official GUI. There are several unofficial GUIs available for it, I use this:

Edit: changed "native" to "official"
Sorry for the slightly off topic, but is this working for anyone on YT?

I get a please sign in error to show you are not a bot, but there is no option to sign in on the GUI?
error yt.jpg


changed from IOS to Android still getting errors
error and.jpg
 
Last edited:

Morro

Level 20
Verified
Top Poster
Well-known
Jul 8, 2012
961
Sorry for the slightly off topic, but is this working for anyone on YT?

I get a please sign in error to show you are not a bot, but there is no option to sign in on the GUI?
View attachment 287800

changed from IOS to Android still getting errors
View attachment 287801

Well, I got that sign in problem at first, but after I had set the settings seen in the "settings" picture under Building the source section, that message was gone.

But, then I got some warning that chrome cookies could not be imported or something, even though I had set the GUI to import cookies from Brave. Maybe we both are doing something wrong?
 
  • Like
Reactions: brambedkar59

nicolaasjan

Level 5
Verified
Well-known
May 29, 2023
232
Sorry for the slightly off topic, but is this working for anyone on YT?

I get a please sign in error to show you are not a bot, but there is no option to sign in on the GUI?
View attachment 287800

changed from IOS to Android still getting errors
View attachment 287801
Is this video lXuAf8ly6hs?
But, then I got some warning that chrome cookies could not be imported or something, even though I had set the GUI to import cookies from Brave. Maybe we both are doing something wrong?
Chrome cookies can't be imported when the browser is open.
Try with Firefox.
Code:
--cookies-from-browser firefox

Then it will work:
(however for some reason the download also proceeded here without providing cookies)

Code:
yt-dlp https://www.youtube.com/watch?v=lXuAf8ly6hs
Extracting cookies from firefox
Extracted 48 cookies from firefox
[youtube] Extracting URL: https://www.youtube.com/watch?v=lXuAf8ly6hs
[youtube] lXuAf8ly6hs: Downloading webpage
[youtube] lXuAf8ly6hs: Downloading tv client config
[youtube] lXuAf8ly6hs: Downloading player 69f581a5
[youtube] lXuAf8ly6hs: Downloading tv player API JSON
[SponsorBlock] Fetching SponsorBlock segments
[SponsorBlock] Found 1 segments in the SponsorBlock database
[info] lXuAf8ly6hs: Downloading 1 format(s): 298+140
[info] Downloading video thumbnail 41 ...
[info] Writing video thumbnail 41 to: /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webp
[ThumbnailsConvertor] Converting thumbnail "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webp" to jpg
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webp (pass -k to keep)
[download] Destination: /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f298.mp4
[download] 100% of   40.49MiB in 00:00:01 at 26.31MiB/s
[download] Destination: /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f140.m4a
[download] 100% of    1.62MiB in 00:00:00 at 20.57MiB/s
[Merger] Merging formats into "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4"
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f140.m4a (pass -k to keep)
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f298.mp4 (pass -k to keep)
[ModifyChapters] Removing chapters from /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.uncut.mp4 (pass -k to keep)
[Metadata] Adding metadata to "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4"
[EmbedThumbnail] mutagen: Adding thumbnail to "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4"

This was done via command line. Configuration was read from my config file.
I also used:
Code:
--sponsorblock-remove all

Also, make sure you are using the latest Nightly build.
 
Last edited:

Morro

Level 20
Verified
Top Poster
Well-known
Jul 8, 2012
961
Is this video lXuAf8ly6hs?

Chrome cookies can't be imported when the browser is open.
Try with Firefox.
Code:
--cookies-from-browser firefox

Then it will work:
(however for some reason the download also proceeded here without providing cookies)

Code:
yt-dlp https://www.youtube.com/watch?v=lXuAf8ly6hs
Extracting cookies from firefox
Extracted 48 cookies from firefox
[youtube] Extracting URL: https://www.youtube.com/watch?v=lXuAf8ly6hs
[youtube] lXuAf8ly6hs: Downloading webpage
[youtube] lXuAf8ly6hs: Downloading tv client config
[youtube] lXuAf8ly6hs: Downloading player 69f581a5
[youtube] lXuAf8ly6hs: Downloading tv player API JSON
[SponsorBlock] Fetching SponsorBlock segments
[SponsorBlock] Found 1 segments in the SponsorBlock database
[info] lXuAf8ly6hs: Downloading 1 format(s): 298+140
[info] Downloading video thumbnail 41 ...
[info] Writing video thumbnail 41 to: /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webp
[ThumbnailsConvertor] Converting thumbnail "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webp" to jpg
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webp (pass -k to keep)
[download] Destination: /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f298.mp4
[download] 100% of   40.49MiB in 00:00:01 at 26.31MiB/s
[download] Destination: /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f140.m4a
[download] 100% of    1.62MiB in 00:00:00 at 20.57MiB/s
[Merger] Merging formats into "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4"
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f140.m4a (pass -k to keep)
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.f298.mp4 (pass -k to keep)
[ModifyChapters] Removing chapters from /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4
Deleting original file /dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.uncut.mp4 (pass -k to keep)
[Metadata] Adding metadata to "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4"
[EmbedThumbnail] mutagen: Adding thumbnail to "/dev/shm/test-dlp/Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.mp4"

This was done via command line. Configuration was read from my config file.
I also used:
Code:
--sponsorblock-remove all

Also, make sure you are using the latest Nightly build.

OK, thank you.

EDIT: I just had to change the cookies to none, and the new nightly build and now it works perfectly. :cool:
 
Last edited:

brambedkar59

Level 33
Verified
Top Poster
Well-known
Apr 16, 2017
2,235
Sorry for the slightly off topic, but is this working for anyone on YT?

I get a please sign in error to show you are not a bot, but there is no option to sign in on the GUI?
View attachment 287800

changed from IOS to Android still getting errors
View attachment 287801
Try updating the yt-dlp and ffmpeg builds. I am on stable build and it's working fine. I have never used yt-dlp CLI because I didn't need to.
You can download latest ffmpeg builds from here too.
Also, r/youtubedl is friendly place to ask questions.
1742577303383.png
1742577159918.png
1742576750354.png
[GUI] executing command line: "D:\Backup\Media\ytdlp-interface\yt-dlp.exe" -x -f 251 --no-mtime -P "D:\Music Download" -o "%(title)s.%(ext)s" "www.youtube.com/watch?v=lXuAf8ly6hs"

[generic] Extracting URL: www.youtube.com/watch?v=lXuAf8ly6hs
WARNING: [generic] The url doesn't specify the protocol, trying with http
[youtube] Extracting URL:
[youtube] lXuAf8ly6hs: Downloading webpage
[youtube] lXuAf8ly6hs: Downloading tv client config
[youtube] lXuAf8ly6hs: Downloading player 69f581a5
[youtube] lXuAf8ly6hs: Downloading tv player API JSON
[youtube] lXuAf8ly6hs: Downloading ios player API JSON
[youtube] lXuAf8ly6hs: Downloading m3u8 information
[info] lXuAf8ly6hs: Downloading 1 format(s): 251
[download] Destination: D:\Music Download\Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webm
[ExtractAudio] Destination: D:\Music Download\Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.opus
Deleting original file D:\Music Download\Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webm (pass -k to keep)

[GUI] yt-dlp.exe process has exited


Edit: added more screnshots
 
Last edited:
  • Like
Reactions: Morro and The_King

The_King

Level 12
Verified
Top Poster
Well-known
Aug 2, 2020
553
Try updating the yt-dlp and ffmpeg builds. I am on stable build and it's working fine. I have never used yt-dlp CLI because I didn't need to.
Also, r/youtubedl is friendly place to ask questions.
[GUI] executing command line: "D:\Backup\Media\ytdlp-interface\yt-dlp.exe" -x -f 251 --no-mtime -P "D:\Music Download" -o "%(title)s.%(ext)s" "www.youtube.com/watch?v=lXuAf8ly6hs"

[generic] Extracting URL: www.youtube.com/watch?v=lXuAf8ly6hs
WARNING: [generic] The url doesn't specify the protocol, trying with http
[youtube] Extracting URL:
[youtube] lXuAf8ly6hs: Downloading webpage
[youtube] lXuAf8ly6hs: Downloading tv client config
[youtube] lXuAf8ly6hs: Downloading player 69f581a5
[youtube] lXuAf8ly6hs: Downloading tv player API JSON
[youtube] lXuAf8ly6hs: Downloading ios player API JSON
[youtube] lXuAf8ly6hs: Downloading m3u8 information
[info] lXuAf8ly6hs: Downloading 1 format(s): 251
[download] Destination: D:\Music Download\Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webm
[ExtractAudio] Destination: D:\Music Download\Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.opus
Deleting original file D:\Music Download\Lewis Hamilton and Max Verstappen's Ghost Car Lap Comparison | 2025 Chinese Grand Prix.webm (pass -k to keep)

[GUI] yt-dlp.exe process has exited

After clicking on both the update buttons in settings, now the GUI is working as well. :LOL:
gui.jpg
 

nicolaasjan

Level 5
Verified
Well-known
May 29, 2023
232
I do have a kind of GUI. :)
Using the "Open With" extension in Firefox.
For me this is the fastest way to use yt-dlp.

Setup is a bit cumbersome though; you need to have Python installed, since Open With needs a file outside of the browser to communicate with.
screenshot1.png

Unfortunately not maintained any more, but still works great.
screenshot_Open-With.png
PS,
The UI of this Firefox fork is heavily modified with custom style sheet (CustomCSSforFx).
 
Last edited:
  • Like
Reactions: Zero Knowledge

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top