Security Scan Report: adobe-express-cloud.s3.us-east-2.amazonaws.com

Redirected to:
https://adobe-express-cloud.s3.us-east-2.amazonaws.com/adobe_acrobat_r...
Submitted: Sep 29, 2026, 12:45:07 AMCompleted: Sep 29, 2026, 12:46:03 AMpubliccompleted

This website contacted 6 IPs in 2 countries across 3 domains to perform 5 HTTP transactions. The main domain is adobe-express-cloud.s3.us-east-2.amazonaws.com and was registered 2 years 7 months ago.

Submitted URL: http://adobe-express-cloud.s3.us-east-2.amazonaws.com/adobe_acrobat_reader.html

Effective URL:

https://adobe-express-cloud.s3.us-east-2.amazonaws.com/adobe_acrobat_r...
Redirected

Downloads:

AI Security Verdict

Confirmed Scam

Confidence: 90%

9
Risk Score

Fake Adobe Acrobat Reader page on an S3 bucket that auto-downloads a ScreenConnect remote-access installer - a brand-impersonating remote-access/malware delivery lure. Do not run the file.

Risk Factors (5)
Impersonation of Adobe Acrobat Reader on a non-Adobe, unranked S3 bucket
Automatic delivery of a ScreenConnect remote-access installer (executable)
CRITICAL IDS alert for Windows PE executable download
Packed executable download from third-party ScreenConnect host
Unranked shared-hosting tenant domain with unknown page creation date; 'Adobe' used only as a bucket name lure
Domain age information unavailable

Details

Page Title

N/A

Scan Type

public

Domain Name Analysis

The domain name 'adobe-express-cloud.s3.us-east-2.amazonaws.com' uses the commercial generic top-level domain (.com) and includes subdomain 'adobe-express-cloud.s3.us-east-2'. The second-level label 'amazonaws' is 9 characters long split between four vowels and 5 consonants. Tokenizing the label suggests three words: amazon, aw, s. Median word length is two characters. No strong language cues emerged from the frequency lists.

Screenshot

Security scan screenshot of http://adobe-express-cloud.s3.us-east-2.amazonaws.com/adobe_acrobat_reader.html

Page Load Overview

1.84s
Total Load Time
6 KB
Total Size

Language Analysis

Primary Language

🇺🇸English
Code: en
Confidence:59%
Script:Latin
Direction:ltr

Detection Details

Text Length:593 chars
Detector Agreement:67%

Website Classification

Primary Category

technology software76% confidence
Type: static
Method: ml+structural

All Detected Categories

technology software
76%
documentation technical
42%

Detected Features

No structural features detected

Domain & IP Information

RequestsIP AddressLocationAS Autonomous System
552.219.110.138Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
0216.246.47.102Chicago, Illinois, United States
AS23352DEFT.COM
016.12.64.90Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
03.5.130.126Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
052.219.232.82Aws · CLOUDColumbus, Ohio, United States
AS16509Amazon.com, Inc.
051.222.11.121Canada
AS16276OVH SAS
56--

Content Similarity HashesFor malware variant detection

TLSH (Trend Micro Locality Sensitive Hash)

Security-focused

Specialized for malware detection and similarity analysis

T1685197669363050735629084B7A297853C30840B6243D699FFAE2BAEEFC25DFD1637DC

ssdeep (Context Triggered Piecewise Hashing)

Context-aware

Detects similar content even with modifications

48:GvwxbYu12H4JASzjhATlDAo4j7ashSedckPeeeBR3yAYBzuNigOzUib9TSLPvsQ4:jWP4UljuuQiR3kxoiYibMDAH7

sdhash (Similarity Digest Hashing)

High-precision

High-precision similarity detection for forensic analysis

sdhash:3:2914:AhAAIAgVACAAAIAoBQACADgEFCAgBwAEgAIgABQDAgAAQgAAAAAgPgAAAEAIAEEUkIDAAgAIBgRkAEAQKgAAAAAgUQoABAhw

These hashes enable detection of similar websites and malware variants by comparing content similarity even when exact matches aren't found.

Image Hashes

Perceptual Hashes

Average Hash:ffffffe7e7ffffc1
Perceptual Hash:e39a4c9a639a4c9e
Difference Hash:0000000c0c00000a
Wavelet Hash:0c0c0c04e7ffcf00
Color Hash:#2dd29e

Other Hashes

Crop Resistant:0000000c0c00000a

Scan History

Scan history not available

Unable to load historical scan data