Is Peter Pacheco-An Introduction to Parallel Programming-Morgan Kaufmann (2011).pdf safe?
No antivirus engine detected malware in this long-established PDF, while unresolved direct-IP contacts warrant ordinary caution when opening documents.
The PDF received no detections from 76 antivirus engines, including no tier-1 flags, and has been observed repeatedly for more than 13 years. Two direct-IP contacts lack a completed reputation check, but there is no corroborating malware family, offensive technique, malicious child, or researcher-intelligence hit.
09d71f72635756bef1…8e25674193c22dRecommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
The PDF received no detections from 76 antivirus engines, including no tier-1 flags, and has been observed repeatedly for more than 13 years. Two direct-IP contacts lack a completed reputation check, but there is no corroborating malware family, offensive technique, malicious child, or researcher-intelligence hit.
No engine among 76 detected malware or suspicious content, and all 18 reporting tier-1 engines were silent. The PDF has a long history and 101 submissions from 75 sources, reducing concern that it is a newly introduced sample. No completed runtime observation is available because the sandbox count is zero, so the activity cannot be characterized as normal or harmful. A heuristic noted two direct-IP contacts, but their reputation was not checked and no independent evidence identifies them as malicious. External intelligence produced no YARAify, CIRCL, or MalwareBazaar hit, while none of the eight inspected child hashes was confirmed malicious.
What We Detected
The PDF produced 0 detections across 76 antivirus engines, with tier1Malicious=0 and 18 tier-1 engines reporting no detection. It has been known for 5,018 days and has appeared in 101 submissions from 75 sources.
Threat Behavior
No completed sandbox run is available because behaviour.sandboxCount=0, and no offensive-only MITRE technique was recorded. The MalwareTips.Synth.DirectIpC2 heuristic noted contacts to 54.144.73.197 and 2.18.233.74, but contactedHosts=null means no complete reputation assessment exists for those addresses. Eight child hashes were inspected without a confirmed malicious child, although all eight remain unclassified.
What To Do Now
Open the document only with an updated PDF reader and keep endpoint protection enabled. If the source is unexpected or the document requests scripts, embedded files, credentials, or unusual permissions, close it and verify the source independently.
Where this verdict could be wrong3 caveats
- MalwareTips.Synth.DirectIpC2 fired after contacts to 54.144.73.197 and 2.18.233.74; contactedHosts=null means no complete host-reputation result is available.
- behaviour.sandboxCount=0 means the listed activity was not backed by a completed sandbox verdict.
- All 8 inspected dropped children have unknown verdicts, so hasMaliciousChild=false does not establish that those children are benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/76 antivirus engines detected malware or suspicious content.
- tier1Malicious=0 and tier1ReportedClean=18.
- The file has 5,018 days of history and 101 submissions from 75 sources.
- No offensive-only MITRE techniques were recorded.
- YARAify, CIRCL, and MalwareBazaar returned no hit.
- MalwareTips.Synth.DirectIpC2 recorded two direct-IP contacts without a completed host-reputation check.
- No completed sandbox observation is available.
- Eight dropped child hashes remain unclassified.
The evidence supports opening it with an updated PDF reader from a trusted source. Keep endpoint protection enabled and avoid interacting with unexpected links, scripts, or embedded attachments.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 76 engines flagged the file.
Sandbox
PartialRuntime data is present, but no completed sandbox environment is recorded.
Network
Partial2 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete1 signature or behavior rule matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Peter Pacheco-An Introduction to Parallel Programming-Morgan Kaufmann (2011).pdf
09d71f72635756bef15a38041bc7608419a535c4e5c742a0fe8e25674193c22d
01Uploaded file
Files
Created or changed
- Written fileObserved
LocalLow
C:\Users\user\AppData\LocalLow
02Isolated runtime analysis - Written fileObserved
Cache
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Cache
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
54.144.73.197
Contact observed during runtime.
04Isolated runtime analysis - Contacted hostObserved
2.18.233.74
Contact observed during runtime.
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Runtime behavior was not available
The report does not treat a missing runtime observation as a clean result.
Files this sample writes at runtime
This file drops 8 children at runtime. None are currently flagged malicious in our cache.
- a418bffeb6e9539701f6…4f32e8Never scannednever seen before
- 159a51cef4822afe893c…750c98Never scannednever seen before
- 726bcbb5f825feee1e63…506e66Never scannednever seen before
- 8d6aaffcdddc8cb7069c…f5ebf5Never scannednever seen before
- 2477b4aa138e2f36e348…140236Never scannednever seen before
- 7c2d9a250fc94fc5958c…ac0784Never scannednever seen before
- 5630f3305dbc0f9a6700…4969d0Never scannednever seen before
- a4bfcfbabe76188f0942…ee4ffbNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 1rule hit recorded
- 0 / 76engines flagged
- 75sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 76 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
No completed runtime observation is available for this file.
ProvenanceDerivedSourceRuntime coverageObserved at - 03
The hash has been submitted 101 times from 75 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: Peter Pacheco-An Introduction to Parallel Programming-Morgan Kaufmann (2011).pdf — 09d71f72635756bef15a38041bc7608419a535c4e5c742a0fe8e25674193c22d
ProvenanceObservedSourceUploaded fileObserved at - 05
File written: LocalLow — C:\Users\user\AppData\LocalLow
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: Cache — C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Cache
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
Contacted host: 54.144.73.197 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 2.18.233.74 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence54.144.73.197 · 2.18.233.74
0 of 76 engines flagged this file
View all 76 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Peter Pacheco-An Introduction to Parallel Programming-Morgan Kaufmann (2011).pdf
- Format
- Code signing
- Not applicable to this file type
- Size
- 3.7 MB
- Last analyzed
- Sep 9, 2026, 1:22 AM UTC
09d71f72635756bef15a38041bc7608419a535c4e5c742a0fe8e25674193c22dSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is this file safe?
What is this file?
How many antivirus engines detected this file?
What is the SHA-256 hash of this file?
Is it safe to open this file?
How up to date is this analysis of this file?
Community
Member reviews and reports for this exact file hash.