Skip to main content
Participant
July 8, 2026
Answered

Adobe Acrobat contacted certain URL in antivirus test

  • July 8, 2026
  • 13 replies
  • 511 views

I uploaded a PDF to Virustotal to make sure it had no malware. NO vendors flagged it as malicious. However, the PDF file contacted a certain URL that is flagged as malicious by 2/91 vendors:

 

dunamis-ethos508-prod-va6-856defacfb833db1[.]elb[.]us-east-1[.]amazonaws[.]com

 

 

The URL in question seems to be tied to two other domains that I believe are legitimate Adobe domains:
 

cc-api-data[.]adobe[.]io
ethos[.]dunamis[.]ethos508-prod-va6[.]ethos[.]adobe.net

 

If you look at the SSL reports below, they all connect to the very same IP addresses.

https://www.ssllabs.com/ssltest/analyze.html?d=cc-api-data.adobe.io 
https://www.ssllabs.com/ssltest/analyze.html?d=ethos.dunamis.ethos508-prod-va6.ethos.adobe.net 
https://www.ssllabs.com/ssltest/analyze.html?d=dunamis-ethos508-prod-va6-856defacfb833db1.elb.us-east-1.amazonaws.com

 

Can anyone here please let me know whether this URL is legitimately used by Adobe services or not?

 

(PS. I added the hook parentheses to the URLs just in case)

{Post edited by Adobe Moderator on the user request]

    Correct answer Anand Sri Bhattacharya

    @darby-1886 As confirmed internally, the URL dunamis-ethos508-prod-va6-856defacfb833db1[.]elb[.]us-east-1[.]amazonaws[.]com is legitimate.

     

    Please let us know if you have any questions, and thanks for your patience and cooperation on this.

    Regards,

    Anand Sri.

    13 replies

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 15, 2026

    Hello ​@darby-1886 

     

    I hope you are doing well. We are awaiting your response and the requested information, which will assist the product team in their investigation.

     

    Regards,

    Anand Sri.

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 14, 2026

    Hello ​@darby-1886 

     

    I hope you are well, and sorry for the delayed response.

    The product team has been investigating this internally and needs some more information. Could you please provide the following info, which will help us with the investigation: 

     

    • Are you seeing the URL dunamis-ethos508-prod-va6-856defacfb833db1.elb.us-east-1.amazonaws.com while opening PDFs in Acrobat/Reader, or is it only appearing when the PDF is uploaded to Virus Total?
      • If it is occurring in Acrobat/Reader, does it happen with a specific workflow, or simply when opening any PDF?
    • Is this URL being observed for all PDFs, or only for certain PDFs that are being flagged as malicious?
    • If this is limited to specific PDFs, can you please share one of those PDFs with us?
      • You can share the file directly with me via direct/private message. Upload the file to any cloud storage and share the link with us.
        • To send a direct/private message. Click on my user profile name, in the next window, select message. Add the file cloud link and add the community thread in the message for identification and tracking purposes.

    Thanks again for your patience and cooperation on this. I will wait for your response.

    Regards,

    Anand Sri.

    Participant
    July 15, 2026

    Hi Mr. Bhattacharya,

     

    • I only noticed the URL when I uploaded the PDF to VirusTotal. I am not sure how it works, but I thought that they perhaps use Acrobat Reader in their test environment. If contacting the URL is normal procedure, then it is probably contacted simply when opening Acrobat Reader. I only use it to read, not to edit.

     

    • The PDF-file that I uploaded was itself not flagged as malicious. It is only the contacted URL that is flagged as malicious by some vendors. VirusTotal said that this URL was contacted, along with two other URLs that are not flagged as such:
    acroipm2.adobe.com (mentioned here: https://community.adobe.com/questions-9/is-http-acroipm2-adobe-com-a-legitimate-site-1295277)
    ethos.dunamis.ethos508-prod-va6.ethos.adobe.net

    It appears, from looking at Relations > Communicating Files at the domain's VirusTotal page, that the vast majority of files that contact the domain are not flagged as malicious, as said before.

     

    • I unfortunately no longer have the PDF that was uploaded. I deleted it immediately out of fear that it could be infected with malicious script contacting a potentially malicious URL after seeing the vendor results, and reading what shows up on Google. But I do recall that the metadata showed 4 Object Streams and 1 AcroForm. Not sure what that means though, or if it has any relevance here.

    Sorry for not being able to provide you with a complete set of information.

     

    I noticed that cc-api-data.adobe.io, which appears to be connected to the domain in this thread, has previously been mentioned on this forum. Perhaps this can be of use:
    https://community.adobe.com/questions-12/questions-about-calling-cc-api-data-adobe-io-in-adobe-reader-1506802

    This domain seems to be in use for something called "Sign in user experience" (according to this page: https://helpx.adobe.com/business/enterprise/kb/network-endpoints.html).

     

    This thread here also discusses what appears to be a recurrent problem of legitimate Adobe URLs being erroneously flagged by vendors on VirusTotal:
    https://community.adobe.com/questions-624/many-missing-urls-in-kb-article-about-network-endpoints-1552547

     

    Best regards,
    D.

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 15, 2026

    Thank you for sharing the details, ​@darby-1886 

     

    I will get this checked with the product team and will share updates soon.

     

    Regards,

    Anand Sri.

    Participant
    July 11, 2026

    I should clarify that the domain is flagged as malicious by 2/91 vendors at the time of writing (https://www.virustotal.com/gui/domain/dunamis-ethos508-prod-va6-856defacfb833db1.elb.us-east-1.amazonaws.com).

     

     

     

    This may very well be a false positive, but since this info is so easily accessible, I found it pertinent to relay it here so that someone can clear up whether the domain is legitimate or if it should be treated with utmost caution, as this would be helpful to any user who comes across it.

     

    Or, if this is the wrong channel, would it be better to remove this thread altogether and instead forward the information to the cyber security department for review?

     

    {Post edited by Adobe Moderator on the user request]

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 13, 2026

    Thanks for the update ​@darby-1886 

     

    I have shared this with the product team, and they are checking it internally. We’ll share an update here soon.

     

    Regards,

    Anand Sri.

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 8, 2026

    Hello @darby-1886,


    I hope you are doing well, and thanks for reaching out and sharing the details.


    We'll get this checked internally and will get back to you with an update.


    Regards,

    Anand Sri.

    Participant
    July 9, 2026

    Dear Anand Sri,

     

    These sites also connect the domains previously mentioned:

    https://www.scamadviser.com/check-website/cc-api-data.adobe.io (look under Server Name)
    https://www.netify.ai/resources/hostnames/cc-api-data.adobe.io (it mentions the IP addresses and Amazon AWS)

    In addition, Virustotal lists over 800.000 uploaded files (mainly PDFs) that contacted the URL in question during the antivirus test. Most of them appear to be safe.

     

    Based on this, dunamis-ethos508-prod-va6-856defacfb833db1[.]elb[.]us-east-1[.]amazonaws[.]com appears to be a legitimate domain that Adobe Acrobat Reader uses to contact the Adobe servers. But I can't be sure until this is confirmed by Adobe itself.

     

    I'm looking forward to your reply!

     

    Best regards.

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    July 9, 2026

    Thank you for the details ​@darby-1886 

     

    I have updated the product team with the latest details you shared. I will follow up with the information soon.

     

    Regards,

    Anand Sri.