Specificially https://en.z-lib.gs/

I downloaded some pdfs from there and according to virustotal and some pdf online scanner i tried, they have something possibly malicious going on in them. I already deleted them but i opened them in firefox pdf reader. I dont have acrobat installed.

Scanning my system with malwarebytes now, but nothing is finding anything wrong and I havent seen any suspicious activity.

Here is the analysis itself.

https://www.virustotal.com/gui/file/f3140c932ab57256a8438eba31d18e4baee1413e7ec23d93b1c1f5194b6dea95/behavior

I’m starting to panic, please help if you have any advice


Thank you all, you are wonderful people

hendrik
link
fedilink
English
63d

Correct me if I’m wrong, but that virustotal link gives a summary of: “No security vendors flagged this file as malicious”

So Virustotal did not find and malware or viruses?! The files should be perfectly fine to use.

@reksas@sopuli.xyz
creator
link
fedilink
English
03d

Check the behavior tab

hendrik
link
fedilink
English
22d

I think these tabs are meant for experts who know how to interpret a full log. Seems to me like Virostotal uses Acrobat Reader or something to open the files. I’m not an expert on what Acrobat is supposed to do once it runs. Sure, it’s going to do some system calls as every software does. And there is something with internet URLs. Could be some phishink link detection or URL prefetching, that is either part of Acrobat or Virustotal? And Acrobat Reader seems to be calling home to check for updates. That triggers the “low” IDS rule. Everything else is pretty much “NOT FOUND” or “INFO” and tells the story of how Acrobat Reader operates. None of it is flagged or indicated in red text.

I’d treat those PDFs like any other one. Don’t just click on any random link in them, and if the PDF contains a form, don’t enter your private details and submit them unless you’ve verified where that form sends them to. But I doubt that’s happening here.

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ
!piracy@lemmy.dbzer0.com
Create a post
⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don’t request invites, trade, sell, or self-promote

3. Don’t request or link to specific pirated titles, including DMs

4. Don’t submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):


💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

  • 1 user online
  • 228 users / day
  • 386 users / week
  • 929 users / month
  • 3.25K users / 6 months
  • 1 subscriber
  • 3.66K Posts
  • 86.5K Comments
  • Modlog