Is Power System Analysis and Design (SI Edition), Fifth Edition -- J_ Duncan Glover, Mulukutla S_ Sarma, Thomas Overbye -- SI Edition, 5th, 2011 -- isbn13 9781111425777 -- 0d6f773da41da789172d5e8fffbcc579 -- Anna’s Ar.pdf safe?
No antivirus engine detected the long-established PDF, while isolated sandbox technique mappings lack a malicious verdict or independent threat-intelligence corroboration.
None of 76 antivirus engines flagged this PDF, including all 17 participating tier-1 engines, and the completed sandbox issued no malicious verdict. Two offensive technique mappings and direct-IP traffic warrant ordinary caution, but they are not corroborated by detections, malicious children, or researcher rules.
871e29c2677b868cdc…ca60b071b6b363Recommended next actions
Before opening
Open it only when its sender or download source is one you independently trust.
If you already opened it
Keep normal device protection enabled and stop if the file behaves unexpectedly.
Intelligence
The saved assessment, checked against the scan evidence and recorded coverage.
The reasoning behind this verdict
This section explains the evidence supporting the verdict and keeps conflicting or missing signals visible.
None of 76 antivirus engines flagged this PDF, including all 17 participating tier-1 engines, and the completed sandbox issued no malicious verdict. Two offensive technique mappings and direct-IP traffic warrant ordinary caution, but they are not corroborated by detections, malicious children, or researcher rules.
The strongest evidence is the complete absence of detections across 76 antivirus engines, with all 17 participating tier-1 engines silent. The file has also been observed for more than 13 years and submitted 32 times by 29 sources, reducing concern that it is an untested recent sample. One sandbox mapped T1003 and T1485, but it produced no malicious verdict and no inspected child was identified as malicious. Three external IP contacts triggered a heuristic, yet no complete host-reputation result is available because the contacted-host check was not saved. No matching researcher rule, known-malware record, or named family provides independent corroboration.
What We Detected
None of 76 antivirus engines flagged the PDF, including all 17 participating tier-1 engines. The hash has been known since 2013 and has 32 submissions from 29 sources. No named malware family, researcher rule, or known-malware intelligence hit was present.
Threat Behavior
One sandbox completed execution without issuing a malicious verdict. It mapped MITRE techniques T1003 and T1485 and observed direct connections to 142.250.125.94, 184.30.16.138, and 34.193.227.236. Those mappings are concerning in isolation, but they are not backed by process evidence showing credential theft or destructive actions. A complete reputation check for the contacted hosts is unavailable. Ten dropped files were inspected without a malicious-child finding, although their individual verdicts remain unknown.
What To Do Now
Open the document only with a fully updated PDF reader and keep endpoint protection enabled. If the source is unfamiliar or the document requests scripts, embedded files, credentials, or external downloads, close it and obtain another copy from a trusted source.
Where this verdict could be wrong3 caveats
- The sandbox mapped T1003 and T1485, techniques associated with credential access and destructive activity, although it issued no malicious verdict.
- MalwareTips.Synth.DirectIpC2 fired for three external IP addresses, and contactedHosts=null leaves their reputation unresolved.
- All 10 inspected child files have unknown individual verdicts, so dropped-file evidence is incomplete rather than affirmatively benign.
These are the assessment's weak points. If you believe one applies to your file, report the verdict and we'll re-review it.
- 0/76 antivirus engines reported a detection.
- All 17 participating tier-1 engines reported no detection.
- behaviour.hasMaliciousSandboxVerdict=false.
- droppedChildren.hasMaliciousChild=false.
- No YARAify, MalwareBazaar, or CIRCL hit was recorded.
- Sandbox mapped offensive techniques T1003 and T1485.
- Direct-IP heuristic fired for 142.250.125.94, 184.30.16.138, and 34.193.227.236.
- contactedHosts=null, so the observed IP addresses lack a complete saved reputation check.
- The PDF carries autoaction, runtime-modules, and acroform tags.
- Ten dropped children have unknown individual verdicts.
Use an updated PDF reader and keep endpoint protection enabled. Prefer a trusted source, particularly if the document prompts for credentials, launches attachments, or requests external downloads.
Coverage & freshness
Complete means the check returned a usable result. It does not mean the file is safe.
Antivirus
Complete0 of 76 engines flagged the file.
Sandbox
Complete1 isolated runtime environment contributed observations.
Network
Partial4 runtime contacts were observed without a completed reputation cross-check.
YARA
Complete2 signature or behavior rules matched.
External intel
Complete3 of 3 independent reference sources completed.
Behavior
Plain-English impact first, then the observed runtime evidence.
Runtime flight recorder
Capture complete- 1isolated sandbox run
- 10MITRE ATT&CK techniques
- 8spawned processes
- 4network contacts
- 40filesystem & mutex artifacts
Attack story
Runtime observations grouped by analysis stage. Arrows organize the stages; they do not claim chronology or causality.
Input file
The submitted object
- FileObserved
Power System Analysis and Design (SI Edition), Fifth Edition -- J_ Duncan Glover, Mulukutla S_ Sarma, Thomas Overbye -- SI Edition, 5th, 2011 -- isbn13 9781111425777 -- 0d6f773da41da789172d5e8fffbcc579 -- Anna’s Ar.pdf
871e29c2677b868cdc4ff43e6a0fccddc1a33dc69646cebce7ca60b071b6b363
01Uploaded file
Processes
Runtime execution
- ProcessObserved
Observed process
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\<USER>\Desktop\attachment.pdf"
02Isolated runtime analysis - ProcessObserved
Observed process
"C:\Program Files\Adobe\Acrobat DC\Acrobat\Adobe Crash Processor.exe"
03Isolated runtime analysis - +1 more recorded observation in Analyst mode
Files
Created or changed
- Written fileObserved
acroNGLLog.txt
C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
04Isolated runtime analysis - Written fileObserved
NGLClient_AcrobatReader123.8.20533.6.log
C:\Users\<USER>\AppData\Local\Temp\NGL\NGLClient_AcrobatReader123.8.20533.6.log
05Isolated runtime analysis - +1 more recorded observation in Analyst mode
Network
Hosts contacted
- Contacted hostObserved
142.250.125.94
Contact observed during runtime.
06Isolated runtime analysis - Contacted hostObserved
224.0.0.251
Contact observed during runtime.
07Isolated runtime analysis - +1 more recorded observation in Analyst mode
7 recorded facts from one runtime window. Every fact remains independently traceable in Analyst mode.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
Adversary techniques mapped to the MITRE ATT&CK framework.
- 142.250.125.94
- 224.0.0.251
- 184.30.16.138
- 34.193.227.236
- C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
- C:\Users\<USER>\AppData\Local\Temp\NGL\NGLClient_AcrobatReader123.8.20533.6.log
- C:\Users\<USER>\AppData\Local\Temp\Tmp8A35.tmp
- C:\Users\<USER>\AppData\Local\Temp\Tmp8E3D.tmp
- C:\Users\user\AppData\LocalLow
- C:\Users\<USER>\AppData\Roaming\Adobe\Acrobat\DC\JSCache\GlobSettings
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\05349744be1ad4ad_0
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0786087c3c360803_0
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0998db3a32ab3f41_0
- C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Code Cache\js\0f25049d69125b1e_0
- Local\Acrobat Instance Mutex
- Global\_MSIExecute
- Global\MSILOG_d402cd331daf7dcGOL.04aa2ISM_pmeT_lacoL_ataDppA_onurB_sresU_:C
- Global\AdobeCrashProcessorLocalLowLock
- Local\ZonesCacheCounterMutex
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- eacad3e01b8b0a44ac03…df796dNever scannednever seen before
- 8476839229c419e2bbf7…84948aNever scannednever seen before
- a2acabbb218e9a1205b9…0367abNever scannednever seen before
- 610bd324afb0f74bf298…54abb5Never scannednever seen before
- dedead640d6edcdca083…dea262Never scannednever seen before
- 7999c4c84beceb4caa30…43366fNever scannednever seen before
- 766caff7446bad3369f3…629366Never scannednever seen before
- 244e92fad2d802691976…ceec27Never scannednever seen before
- 1015de23015d3edfb46c…e8d014Never scannednever seen before
- 8aa0011c981eed009959…f15e2dNever scannednever seen before
Detection & Forensics
Consensus, attribution, signatures, code structure, prevalence, and identity.
Evidence integrity
Chain of custody for the facts preserved in this report.
- 2rule hits recorded
- 0 / 76engines flagged
- 29sources in submission history
Why these facts are shown
Each statement identifies whether it was directly recorded or derived from saved scan facts.
- 01
0 of 76 antivirus engines flagged the file.
Verdict inputView chapterProvenanceObservedSourceAntivirus analysisObserved at - 02
The hash has been submitted 32 times from 29 sources.
ProvenanceDerivedSourceSaved report factsObserved at - 03
Scanned file: Power System Analysis and Design (SI Edition), Fifth Edition -- J_ Duncan Glover, Mulukutla S_ Sarma, Thomas Overbye -- SI Edition, 5th, 2011 -- isbn13 9781111425777 -- 0d6f773da41da789172d5e8fffbcc579 -- Anna’s Ar.pdf — 871e29c2677b868cdc4ff43e6a0fccddc1a33dc69646cebce7ca60b071b6b363
ProvenanceObservedSourceUploaded fileObserved at - 04
Observed process — "C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe" "C:\Users\<USER>\Desktop\attachment.pdf"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 05
Observed process — "C:\Program Files\Adobe\Acrobat DC\Acrobat\Adobe Crash Processor.exe"
ProvenanceObservedSourceIsolated runtime analysisObserved at - 06
File written: acroNGLLog.txt — C:\Users\<USER>\AppData\Local\Temp\acroNGLLog.txt
ProvenanceObservedSourceIsolated runtime analysisObserved at - 07
File written: NGLClient_AcrobatReader123.8.20533.6.log — C:\Users\<USER>\AppData\Local\Temp\NGL\NGLClient_AcrobatReader123.8.20533.6.log
ProvenanceObservedSourceIsolated runtime analysisObserved at - 08
Contacted host: 142.250.125.94 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at - 09
Contacted host: 224.0.0.251 — Contact observed during runtime.
ProvenanceObservedSourceIsolated runtime analysisObserved at
Detection sources at a glance
The available sources did not agree on a named threat category.
MalwareBazaar, YARAify, and CIRCL hashlookup completed and returned no entries for this hash.
Signatures and behavior heuristics
Behavioral heuristics matched patterns associated with malware. Corroborating evidence determines how much weight they carry.
MITRE T1003 (OS Credential Dumping) mapped by at least one sandbox run.
The sample contacted an external IP address directly and no application domain was recorded. Direct-IP traffic also occurs in legitimate installers and infrastructure, so this is supporting context only and requires corroboration from host reputation and other runtime evidence.
Evidence142.250.125.94 · 184.30.16.138 · 34.193.227.236
0 of 76 engines flagged this file
View all 76 engine results
PE structure
Not applicablePE structure analysis applies to Windows executable formats, not this file type.
How widely this file has been seen
Moderate prevalence — neither rare nor common. No strong prior applies.
Fingerprint and provenance
- File name
- Power System Analysis and Design (SI Edition), Fifth Edition -- J_ Duncan Glover, Mulukutla S_ Sarma, Thomas Overbye -- SI Edition, 5th, 2011 -- isbn13 9781111425777 -- 0d6f773da41da789172d5e8fffbcc579 -- Anna’s Ar.pdf
- Format
- Code signing
- Not applicable to this file type
- Size
- 15.8 MB
- Last analyzed
- Sep 9, 2026, 8:08 PM UTC
871e29c2677b868cdc4ff43e6a0fccddc1a33dc69646cebce7ca60b071b6b363Safety & FAQ
Complete recovery guidance and answers for the next decision.
What to do now
This file appears low risk based on the evidence available now.
- Recovery step 01
Open it only when its sender or download source is one you independently trust.
- Recovery step 02
A clean result reduces known risk, but it cannot guarantee that every new or targeted threat has been detected.
- Recovery step 03
Keep your antivirus and Windows updates switched on so you stay protected.
Safety FAQ
Direct answers grounded in the saved verdict and evidence in this report.
Is this file safe?
What is this file?
How many antivirus engines detected this file?
What is the SHA-256 hash of this file?
Is it safe to open this file?
How up to date is this analysis of this file?
Community
Member reviews and reports for this exact file hash.