Is Designing Data-Intensive Applications (Martin Kleppmann) (z-library.sk, 1lib.sk, z-lib.sk).pdf safe?
No antivirus engine detected the long-established PDF, while concerning sandbox technique mappings remain uncorroborated and may reflect reader or environment activity.
All 75 antivirus engines produced no malicious or suspicious detection, including 17 tier-1 engines, and the PDF has circulated widely since 2022. One sandbox mapped activity to credential access, injection, and file destruction techniques, but issued no malicious verdict; incomplete host coverage prevents treating the network activity as fully cleared.
1186eaa1d12ade984f…a04265e0129944Recommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
All 75 antivirus engines produced no malicious or suspicious detection, including 17 tier-1 engines, and the PDF has circulated widely since 2022. One sandbox mapped activity to credential access, injection, and file destruction techniques, but issued no malicious verdict; incomplete host coverage prevents treating the network activity as fully cleared.
The strongest evidence is the complete absence of detections across 75 engines, including 17 tier-1 products. The file is also well established, with 110 sources and 124 submissions over several years, rather than being newly encountered. One runtime session produced mappings to T1003, T1055, and T1485, but no malicious sandbox verdict or known-malicious child supported those mappings. The observed processes and files prominently involve Adobe Acrobat components, making environmental or reader-generated attribution plausible. Host-reputation coverage was incomplete, so the no complete contacted-host reputation result was available. No MalwareBazaar, CIRCL, or YARAify corroboration was present.
What We Detected
No malicious or suspicious result was reported by any of 75 antivirus engines, and all 17 reporting tier-1 engines were silent. The PDF has also been submitted 124 times by 110 sources since October 2022, providing a substantial observation history.
Threat Behavior
One sandbox session mapped activity to T1003, T1055, and T1485 and surfaced an LSASS-related heuristic. However, the sandbox did not issue a malicious verdict, no inspected child was identified as malware, and the recorded process activity prominently involved Adobe Acrobat and Windows components. Only three contacted hosts were cross-checked despite numerous observed IP and URL contacts, so no complete host-reputation conclusion is available.
What To Do Now
Open the document only with a fully updated PDF reader and keep endpoint protection enabled. If it came from an untrusted download source, prefer obtaining the book from the publisher or another authorized channel and avoid enabling embedded actions or launching attachments.
Where this verdict could be wrong3 caveats
- The sandbox mapped activity to T1003, T1055, and T1485, including an LSASS-related credential-dumping heuristic; these are meaningful counter-signals despite lacking engine or sandbox-verdict corroboration.
- contactedHosts.inspected=3 is incomplete relative to the observed IP and URL contacts, so the available no complete contacted-host reputation result was available networking.
- The PDF carries file.tags including file-embedded, autoaction, detect-debug-environment, and direct-cpu-clock-access, which merit caution even though no engine detected a payload.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines reported a malicious or suspicious result.
- 17 tier-1 engines reported no detection.
- Observed since 2022 across 110 sources and 124 submissions.
- No malicious sandbox verdict was recorded.
- No MalwareBazaar, CIRCL, or YARAify hit was found.
- Runtime mappings include T1003, T1055, and T1485.
- An LSASS-related credential-dumping heuristic fired.
- The PDF is tagged file-embedded and autoaction.
- Contacted-host reputation coverage is incomplete.
- All 10 inspected child hashes remain without individual verdicts.
Use an updated, protected PDF reader and keep endpoint protection enabled. Prefer an authorized source if the document was downloaded from an untrusted library or file-sharing site.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial3 of 23 contacted hosts were cross-checked; coverage is incomplete.
YARA
Complete3 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 20MITRE ATT&CK techniques
- 15spawned processes
- 23network contacts
- 40filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Designing Data-Intensive Applications (Martin Kleppmann) (z-library.sk, 1lib.sk, z-lib.sk).pdf
1186eaa1d12ade984f9007f4eba19c6f3a64ba19cd34fee710a04265e0129944
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Windows\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}
02Isolated runtime analysis - ProcessObserved
Observed process
C:\Windows\System32\mobsync.exe -Embedding
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
acroNGLLog.txt
C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
04Isolated runtime analysis - Written fileObserved
Tmp26CC.tmp
C:\Users\<USER>\AppData\Local\Temp\Tmp26CC.tmp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
23.220.188.152
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
23.46.240.131
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 23.220.188.152
- 23.46.240.131
- 3.233.129.217
- 8.8.8.8
- 192.28.144.124
- 35.165.115.120
- 204.79.197.200
- 142.251.31.147
- 93.184.220.66
- 65.9.79.74
- https://ardownload3.adobe.com/pub/adobe/reader/win/AcrobatDC/2200320263/AcroRdrDCUpd2200320263.msi
- http://oreilly.com/safari
- http://www.oreilly.com/safari
- C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
- C:\Users\<USER>\AppData\Local\Temp\Tmp26CC.tmp
- C:\Users\<USER>\AppData\Local\Temp\NGL\
- C:\Users\<USER>\AppData\Local\Temp\Tmp2D74.tmp
- C:\Users\<USER>\AppData\Local\Temp\A9gvo62f_pps28t_22w.tmp
- C:\Users\<USER>\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FAF.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER5D2A.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER6123.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER3FAF.tmp.dmp
- Local\SyncServiceThread
- Local\Acrobat Instance Mutex
- Local\SessionImmersiveColorMutex
- Global\_MSIExecute
- Global\MSILOG_899d633a1dbae27GOL.a9131ISM_pmeT_lacoL_ataDppA_onurB_sresU_:C
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- bc112c7b85466f7852fe…7d4b60Never scannednever seen before
- eacad3e01b8b0a44ac03…df796dNever scannednever seen before
- 513fb5d3b4195ab59af2…64de2eNever scannednever seen before
- f42a1604898391a30e67…c89691Never scannednever seen before
- a779a261df447a4c298c…b1b86dNever scannednever seen before
- a6ce2291a38cc10f8e64…b90d1eNever scannednever seen before
- 53eeb1f6a9d3d64df493…9c8980Never scannednever seen before
- 81ff65efc4487853bdb4…7c8e06Never scannednever seen before
- f1adcb21c50ff7585286…163446Never scannednever seen before
- e0ba1a6ebca0d7b3e58e…9bb2c6Never scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 3rule hits recorded
- 0 / 75engines flagged
- 110sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 75 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has a long, established submission history across 110 sources.
Verdict inputView chapterProvenanceDerivedSourceSubmission historyObserved at - 03
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 04
Scanned file: Designing Data-Intensive Applications (Martin Kleppmann) (z-library.sk, 1lib.sk, z-lib.sk).pdf — 1186eaa1d12ade984f9007f4eba19c6f3a64ba19cd34fee710a04265e0129944
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — C:\Windows\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — C:\Windows\System32\mobsync.exe -Embedding
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: acroNGLLog.txt — C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: Tmp26CC.tmp — C:\Users\<USER>\AppData\Local\Temp\Tmp26CC.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 23.220.188.152 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 10
Contacted host: 23.46.240.131 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exeThe sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence23.220.188.152 · 23.46.240.131 · 3.233.129.217
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Widely seen in the wild for a long time. High prior this is legitimate; isolated detections on common-old files are usually false positives.
Fingerprint and provenance
- File name
- Designing Data-Intensive Applications (Martin Kleppmann) (z-library.sk, 1lib.sk, z-lib.sk).pdf
- Format
- Code signing
- Not applicable to this file type
- Size
- 23.3 MB
- Last analyzed
- Sep 15, 2026, 9:51 AM UTC
1186eaa1d12ade984f9007f4eba19c6f3a64ba19cd34fee710a04265e0129944Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is this file safe?
What is this file?
How many antivirus engines detected this file?
What is the SHA-256 hash of this file?
Is it safe to open this file?
How up to date is this analysis of this file?
Community
Member reviews and reports for this exact file hash.