Safe
Legitimate PDF textbook with 15+ years of prevalence; zero malicious detections across 17 tier-1 engines; heuristic flags reflect benign PDF scripting.
4f1a1f3c8251caa03c…c42b92afa6The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file exhibits a clean profile across our antivirus network: zero malicious detections from 64 reporting engines, including 17 high-trust vendors (Avast, BitDefender, ESET, Kaspersky, Microsoft, Fortinet, and others). The filename and metadata match a legitimate published textbook with medium prevalence (92 submitters, 106 submissions since 2010). Heuristic rules flagged MITRE techniques T1003 and T1485, but these map to standard Adobe Acrobat Reader behaviour: temp file writes, cache operations, and process spawning. The DirectIpC2 rule cited three IP contacts, but one contacted URL is the legitimate Windows Update domain, and our URL cache shows zero malicious or suspicious hosts. No malicious sandbox verdict was recorded, and all 10 dropped children remain undetected. The combination of universal tier-1 silence, 15+ years of prevalence, and benign runtime behaviour indicates this is a safe file.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/64 malicious; tier1Malicious=0; tier1ReportedClean=17 (Avast, BitDefender, ESET, Kaspersky, Microsoft, Fortinet, Emsisoft, Ikarus, F-Secure, GData, DrWeb, Avira, AVG all silent)
File: 'Remembering the Kanji vol. I (James W. Heisig)' — legitimate published textbook; age=5774 days (first submitted 2010-09-03); medium prevalence (92 submitters, 106 submissions)
Behaviour: Adobe Acrobat Reader process execution; temp files and cache writes consistent with PDF rendering; contactedHosts=0 malicious; droppedChildren=0 malicious (10 inspected)
triggeredHeuristics: 'DirectIpC2' cites 3 IPs but one contacted URL is legitimate Windows Update domain (download.windowsupdate.com); no malicious sandbox verdict recorded
External intel: CIRCL=no hit, MalwareBazaar=no hit, YARAify=0 rules; no brand mismatch; unsigned (normal for PDFs)
- Zero malicious detections across 64 reporting engines
- 17 tier-1 vendors (Avast, BitDefender, ESET, Kaspersky, Microsoft, Fortinet, etc.) all report clean
- 15+ years of prevalence (first submitted 2010-09-03); 106 submissions from 92 unique sources
- Legitimate textbook metadata ('Remembering the Kanji vol. I' by James W. Heisig)
- No malicious sandbox verdict; no malicious contacted hosts; no malicious dropped children
This file is safe. No quarantine or removal is necessary. The heuristic flags reflect benign PDF scripting and legitimate Windows Update contact, not malware behaviour.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 199.232.210.172
- 2.20.156.175
- 52.202.204.11
- http://download.windowsupdate.com/d/msdownload/update/others/2015/05/17930914_a3b333eff1f0428f5a2c87724c542504821cdbd8.cab
- C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
- C:\Users\<USER>\AppData\Local\Temp\NGL\NGLClient_AcrobatReader123.8.20533.6.log
- C:\Users\<USER>\AppData\Local\Temp\NGL\NGLClient_AcrobatReader123.8.20533.6 2024-07-15 23-09-52-615.log
- C:\Users\<USER>\AppData\Local\Temp\Tmp7881.tmp
- C:\Users\<USER>\AppData\Local\Temp\Tmp7E6E.tmp
- C:\Users\<USER>\AppData\Roaming\Adobe\Acrobat\9.0\SharedDataEvents-journal
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0ace9ee3d914a5c0_0
- Local\Acrobat Instance Mutex
- Global\AdobeCrashProcessorLocalLowLock
- Local\ZonesCacheCounterMutex
- Local\ZonesLockedCacheCounterMutex
- 2AC1A572DB6944B0A65C38C4140AF2F4954751A310C
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- b9e3c3c717faec02233c…d8e5ebNever scannednever seen before
- bd656371531f669220d9…78eb50Never scannednever seen before
- 641af60cbbfbee8af595…9004c9Never scannednever seen before
- b5bef7ae9cb4d0998f92…f38518Never scannednever seen before
- 8c03ea2f91c57472fa65…6a0ea5Never scannednever seen before
- 27a64454cb31cde79e69…ff24ffNever scannednever seen before
- 6e097c6e5d353b4ccf57…0f31f0Never scannednever seen before
- eacad3e01b8b0a44ac03…df796dNever scannednever seen before
- 44c0236926074e782c17…6e2fadNever scannednever seen before
- 513fb5d3b4195ab59af2…64de2eNever scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
MITRE T1003 (OS Credential Dumping) mapped by at least one sandbox run.
Sample contacted 3 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence199.232.210.172 · 2.20.156.175 · 52.202.204.11
0 detections across 76 engines
How often this file shows up in the wild
Moderate prevalence — neither rare nor common. No strong prior applies.
Forensic fingerprint
- File name
- Remembering the Kanji vol. I (James W. Heisig) (z-library.sk, 1lib.sk, z-lib.sk).pdf
- Size
- 5.52 MB
- MIME type
- (unknown)
- Detected type
- SHA-256
- 4f1a1f3c8251caa03c6756f9931ae0f515ca8e666ed010557b0843c42b92afa6
- MD5
- ca125b05ce7ddba4c271b764330b6e65
- SHA-1
- ca9d58cdc3d5a62629d86188a0cd6049d8352953
- First seen (VT)
- 9/3/2010, 9:40:53 AM
- Last analysis (VT)
- 11/10/2025, 11:23:36 AM
- First scan (MalwareTips)
- 6/25/2026, 9:59:37 AM
- Last scan (MalwareTips)
- 6/25/2026, 9:59:37 AM
- Community reputation
- +2trusted
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.