Specificially https://en.z-lib.gs/

I downloaded some pdfs from there and according to virustotal and some pdf online scanner i tried, they have something possibly malicious going on in them. I already deleted them but i opened them in firefox pdf reader. I dont have acrobat installed.

Scanning my system with malwarebytes now, but nothing is finding anything wrong and I havent seen any suspicious activity.

Here is the analysis itself.

https://www.virustotal.com/gui/file/f3140c932ab57256a8438eba31d18e4baee1413e7ec23d93b1c1f5194b6dea95/behavior

I’m starting to panic, please help if you have any advice


Thank you all, you are wonderful people

  • unlogic@lemmy.zip
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 day ago

    None of the activity looks hugely out of place for opening a pdf. My advice would be to take a known safe pdf, upload that to virustotal and compare the activity results and see how different they are if at all.

    There might be differences based on pdf content so best to try and find a similar pdf (images, urls, etc)

    • reksas@sopuli.xyzOP
      link
      fedilink
      English
      arrow-up
      2
      ·
      20 hours ago

      This was good advice. I did that with another pdf and it does look similar.