Our call: Is _OceanofPDF.com_Whatever_-_Michel_Houellebecq.pdf safe?Suspicious
Zero detections but sandbox shows LSASS access and process injection in a brand-new PDF from a piracy site.
- 1 high-confidence signature or behavior rule matched this file.Derived · Signature and behavior rules
- 0 of 75 antivirus engines flagged the file.Observed · Antivirus analysis
- The hash has been submitted 1 time from 1 source.Derived · Saved report facts
15fd59cc1bf2884488…d0a3ca852bRecommended next actions
Before opening
Do not open it until the source can be verified independently.
If you already opened it
Stop using it, scan the device, and watch for unexpected behavior or security alerts. Get a fresh copy from the original trusted source and verify its exact hash when possible.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 75 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Not runNo contacted-host reputation check is recorded.
No timestamp recordedYARA
Complete2 signature or behavior rules matched.
External intel
PartialIndependent reference checks were attempted but are incomplete.
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
_OceanofPDF.com_Whatever_-_Michel_Houellebecq.pdf
15fd59cc1bf28844883df60a329f16a65563d63315e52a0754e29fd0a3ca852b
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
C:\Windows\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\<USER>\Desktop\_OceanofPDF.com_Whatever_-_Michel_Houellebecq.pdf"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
acroNGLLog.txt
C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
04Isolated runtime analysis - Written fileObserved
TmpEB1B.tmp
C:\Users\<USER>\AppData\Local\Temp\TmpEB1B.tmp
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
5 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
1 high-confidence signature or behavior rule matched this file.
Verdict inputView chapterProvenanceDerivedSourceSignature and behavior rulesObserved at - 02
0 of 75 antivirus engines flagged the file.
ProvenanceObservedSourceAntivirus analysisObserved at - 03
The hash has been submitted 1 time from 1 source.
ProvenanceDerivedSourceSaved report factsObserved at - 04
Scanned file: _OceanofPDF.com_Whatever_-_Michel_Houellebecq.pdf — 15fd59cc1bf28844883df60a329f16a65563d63315e52a0754e29fd0a3ca852b
ProvenanceObservedSourceUploaded fileObserved at - 05
Observed process — C:\Windows\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
Observed process — "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\<USER>\Desktop\_OceanofPDF.com_Whatever_-_Michel_Houellebecq.pdf"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: acroNGLLog.txt — C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
File written: TmpEB1B.tmp — C:\Users\<USER>\AppData\Local\Temp\TmpEB1B.tmp
ProvenanceObservedSourceIsolated runtime analysisObserved at
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
No antivirus engine flagged the file, yet the sandbox recorded credential-dumping and process-injection behaviour. The sample is brand-new, rare, and originates from a known piracy domain. These conflicting signals leave the risk level uncertain.
All 75 engines returned clean, but the sandbox captured LSASS reads and process-injection activity that legitimate PDF readers do not perform. The file is one day old, submitted once, and carries an OceanofPDF.com filename, a common piracy source. No external-intel hits or dropped malicious children were found, and the contacted-host reputation check was not completed. The combination of clean static results and suspicious runtime artefacts places the file in mixed-signal territory.
What We Detected
75 engines scanned the PDF; none returned a malicious or suspicious label. Sandbox execution recorded three offensive MITRE techniques (T1003, T1055, T1485) and LSASS memory access, yet produced no malicious sandbox verdict and no malicious dropped children.
Threat Behavior
The observed LSASS access and process-injection artefacts are inconsistent with normal Acrobat Reader activity. The filename references OceanofPDF.com, a known piracy portal, and the file is brand-new with only one recorded submission.
What To Do Now
Do not open the PDF on any production system. Re-scan after additional engines have coverage and monitor for follow-up submissions of the same hash. Keep endpoint protection enabled.
Where this verdict could be wrong2 caveats
- Sandbox artefacts show LSASS access and process injection, but no malicious sandbox verdict or dropped malicious children were recorded.
- Zero engine detections could reflect low coverage for this rare_new PDF rather than true absence of malice.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/75 engines flagged the file
- No dropped malicious children
- No external intelligence hits
- Sandbox observed LSASS access and process injection
- Filename references known piracy domain
- rare_new prevalence (single submission, zero days old)
- contacted-host reputation check incomplete
Treat the PDF as untrusted; do not open it until further reputation data or additional engine coverage becomes available.
Behavior
Plain-English impact first, then the observed runtime evidence.
What this file does
Observed actions and their security significance
High concern: Accessed operating-system credential data, which can expose saved passwords.
High concern: Injected code into another process, a technique that can conceal execution.
Moderate concern: Communicated over a common application protocol; malware can use this for command-and-control.
Moderate concern: Checked the environment for virtualisation or analysis tools.
Note: Reads your Windows user-account details.
Note: Listed running processes; both legitimate software and malware may do this.
Note: Collects details about your system.
These are observed capabilities from an isolated analysis. A technique does not prove malicious intent on its own, and the file never ran on your device.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
- C:\Users\<USER>\AppData\Local\Temp\TmpEB1B.tmp
- C:\Users\<USER>\AppData\Local\Temp\TmpEE29.tmp
- C:\Users\<USER>\AppData\Local\Temp\A9d1j181_dpm5g6_2kw.tmp
- C:\Users\<USER>\AppData\Local\Temp\A9uz0v0d_dpm5g7_2kw.tmp
- C:\Users\<USER>\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
- C:\Users\<USER>\AppData\Local\Packages\Microsoft.XboxGamingOverlay_8wekyb3d8bbwe\LocalCache\KnownGameList.bin
- C:\Users\<USER>\AppData\Local\Microsoft\GameDVR\KnownGameList.update
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER404B.tmp
- C:\ProgramData\Microsoft\Windows\WER\Temp\WER54DD.tmp
- Global\_MSIExecute
- Global\MSILOG_ecbd12bd1dd21c7GOL.ccffISM_pmeT_lacoL_ataDppA_onurB_sresU_:C
- Local\SessionImmersiveColorMutex
- Global\AdobeCrashProcessorLocalLowLock
- Local\WERReportingForProcess3792
Files this sample writes at runtime
This file drops 3 children at runtime. None are currently flagged malicious in our cache.
- eacad3e01b8b0a44ac03…df796dNever scannednever seen before
- 513fb5d3b4195ab59af2…64de2eNever scannednever seen before
- a779a261df447a4c298c…b1b86dNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Detection sources at a glance
The available sources did not agree on a named threat category.
Available reference checks returned no match, but at least one source was unavailable. This is not a clean result.
Signatures and behavior heuristics
A community signature or high-severity behavioral heuristic matched. Signatures identify known patterns; heuristics are strong leads but are not proof on their own.
The saved runtime evidence maps this activity to MITRE T1055 (Process Injection). The mapping supports possible process injection, but it does not prove the exact injection method or the operator's intent.
EvidenceC:\Windows\system32\DllHost.exe /Processid:{133EAC4F-5891-4D04-BADA-D84870380A80}Sandbox observed process activity targeting LSASS (Windows credential store). Legitimate software has no business reading LSASS memory — this is Mimikatz-shape behaviour.
EvidenceC:\Windows\system32\lsass.exe
0 of 75 engines flagged this file
View all 75 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Barely seen in the wild and first surfaced recently. That limits reputation evidence, but rarity alone is not proof of malware.
Fingerprint and provenance
- File name
- _OceanofPDF.com_Whatever_-_Michel_Houellebecq.pdf
- Format
- Code signing
- Not applicable to this file type
- Size
- 416.7 KB
- Last analyzed
- Aug 1, 2026, 8:23 AM UTC
15fd59cc1bf28844883df60a329f16a65563d63315e52a0754e29fd0a3ca852bSafety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
We couldn't fully clear this file. Treat it with caution.
Don't open it unless you're certain it came from a source you trust.
Check where you got it — an unexpected attachment or a random download link is a red flag.
If its origin cannot be confirmed, delete this file and use a fresh copy from a trusted source. Get a fresh copy from the original trusted source and verify its exact hash when possible.
If you're still unsure, scan it again in a day or two — detections often catch up on newer files.