Suspicious server as updater for Adobe program?

RoboMan

Level 38
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
High Reputation
Forum Veteran
Jun 24, 2016
2,614
24,627
3,600
Hidden Village of Hispanic America
I was surfing on the web when suddenly ESET noticed me of a strange event. Adobe Acrobat Updater was trying to open a connection to an unknown server: ocsp.digicert.com. Used to known servers to update and after the CCleaner incident paranoia, i decided to block the access and google. Apparently, on the web they say this OCSP is a protocol related to certificates. VirusTotal throws 0 detected threats but community there voted all negative. If you visit the aforementioned server, it automatically downloads a file that i uploaded to VT and again threw 0 detected threats but has a community score of -188 (negative).

Anybody knows anything about this? Can anybody clarify a little if you have knowledge on the subject?

VT link to downlaoded file: VirusTotal

VT link to host scan: VirusTotal