Safe
Unsigned PDF with zero malicious detections from 16 tier-1 engines; Adobe Reader runtime behaviour benign; direct-IP contact is Google DNS, not C2.
9e4601c6a88da791cb…d83e6f8856The verdict, reasoned out.
Not a rules engine. The MT AI Engine reads every signal we collected, weighs them against history, and commits to an answer.
The file is a 2.08 MB PDF named 'contract.pdf' with zero detections across 63 reporting engines, including all major tier-1 vendors (Kaspersky, BitDefender, Microsoft, ESET-NOD32, Fortinet, Emsisoft, F-Secure, GData, Avira, DrWeb, AVG, Avast). No tier-1 consensus on any malware family exists. Sandbox analysis shows Adobe Reader executing the PDF normally, writing to standard Adobe cache directories and telemetry files. The only heuristic alert ('DirectIpC2') flags contact with 8.8.8.8, which is Google Public DNS — a benign resolver, not a command-and-control server. Ten dropped children were inspected with no malicious verdicts. No external intelligence hits, no malicious hosts contacted, no persistence indicators. The file is brand-new (rare_new prevalence) and unsigned, but the absence of detections from high-trust engines and the benign runtime behaviour strongly indicate a legitimate business document.
Each signal cites a concrete token from the evidence the arbiter saw — engine name, MITRE technique, signer string, or an exact count.
engines: 0/63 malicious; tier1Malicious=0; tier1ReportedClean=16 (Avast, BitDefender, Kaspersky, Microsoft, ESET-NOD32, Fortinet, Emsisoft, F-Secure, GData, Avira, DrWeb, AVG all undetected)
Unsigned PDF, filename 'contract.pdf' consistent with ordinary document; no adversarial injection flags
Behaviour: Adobe Reader (RdrCEF.exe) executed normally; contacted 8.8.8.8 (Google Public DNS) — benign resolver, not C2
10 dropped children inspected; 0 malicious; no malicious sandbox verdicts, no malicious hosts contacted, no persistence
triggeredHeuristics: 'MalwareTips.Synth.DirectIpC2' fired on Google DNS contact — false positive; benign software routinely uses public DNS
- Zero detections from 16 tier-1 antivirus engines (Kaspersky, BitDefender, Microsoft, ESET-NOD32, Fortinet, Emsisoft, F-Secure, GData, Avira, DrWeb, AVG, Avast)
- Adobe Reader runtime behaviour consistent with legitimate PDF viewing
- No malicious dropped children, no malicious sandbox verdicts, no persistence indicators
- Contacted IP is Google Public DNS (8.8.8.8), a benign resolver
This file is safe to open. It is a standard PDF with no malware detections from any high-trust antivirus engine and benign runtime behaviour. The heuristic alert about direct-IP contact is a false positive caused by the use of Google's public DNS resolver.
What this file did when executed
This file was detonated in 1 sandbox and its runtime behaviour was observed.
- 8.8.8.8
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\SOPHIA.json
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\TESTING
- Local\08B31A60
- Local\088711D0
- Local\0856B320
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\DC_READER_LAUNCH_CARD
- C:\Users\<USER>\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Reader\Files\ACROBAT_READER_MASTER_SURFACEID
- C:\Users\<USER>\AppData\LocalLow\Adobe\Acrobat\DC\ReaderMessages-journal
- C:\Users\<USER>\AppData\Local\Temp\CabFDCA.tmp
- C:\Users\<USER>\AppData\Local\Temp\TarFDDA.tmp
Files this sample writes at runtime
This file drops 10 children at runtime. None are currently flagged malicious in our cache.
- ad27039abac3252c3b39…37ede5Never scannednever seen before
- 75a1943a8b8d1b2c3984…5bf4c0Never scannednever seen before
- 81ff65efc4487853bdb4…7c8e06Never scannednever seen before
- a979c4aedeeab4be3928…87e35aNever scannednever seen before
- 5bd86ea5e07de6412240…6ac8a4Never scannednever seen before
- 34b094f505a93f2b2f16…0b3563Never scannednever seen before
- e3b0c44298fc1c149afb…52b855Never scannednever seen before
- a1a0894b57af5307b417…7b80d6Never scannednever seen before
- a5c6d4dbae668479ccb9…11631bNever scannednever seen before
- 4df98d996551189e28df…fe1f0dNever scannednever seen before
YARA + heuristic rules that fired
One or more medium-severity heuristic rules matched. Not definitive, but the patterns match known malware behaviour.
Sample contacted 1 external IP address(es) and zero domains. Benign software virtually always uses DNS; no-DNS direct-IP C2 is a strong malware indicator because it bypasses reputation systems and dodges domain-based blocklists.
Evidence8.8.8.8
0 detections across 75 engines
How often this file shows up in the wild
Barely seen in the wild and first surfaced recently. This is the footprint of targeted malware the AV industry hasn't signatured yet — extra scrutiny is warranted.
Forensic fingerprint
- File name
- contract.pdf
- Size
- 1.98 MB
- MIME type
- (unknown)
- Detected type
- SHA-256
- 9e4601c6a88da791cb899ef4d61d57544b3637e3c3ed0a7d894f80d83e6f8856
- MD5
- 4647e793920be630610bd5b99cd05e28
- SHA-1
- 2263253b4c35d9e743be4cc11ad2f4f731b19150
- First seen (VT)
- 6/11/2026, 4:14:10 AM
- Last analysis (VT)
- 6/11/2026, 4:14:10 AM
- First scan (MalwareTips)
- 6/11/2026, 4:21:51 AM
- Last scan (MalwareTips)
- 6/11/2026, 4:21:51 AM
Reviews & malware reports(0)
Tell the community what you saw. Tag the sample — Trojan, Adware, False Positive — and share what the file did on your system. Your report helps confirm or dispute the AV verdict.