PULSE NAME
New malware campaign discovered via ManualFinder
WHITE AlienVault 2025-09-03 Modified: 2025-09-03
59
IOCs
HIGH VOLUME
A global malware infection of Windows computers has been uncovered, stemming from software users installed themselves. The malware, disguised as legitimate PDF editors and manual finders, turns infected systems into residential proxies for malicious actors. The infection chain starts with deceptive ads posing as PDF manuals. The campaign, which appears to have ceased, was widespread due to large-scale advertising. The malware creates scheduled tasks, executes JavaScript files, and communicates with various C2 domains. It's potentially linked to the OneStart Browser, known for spreading spyware and adware. Authorities advise blocking access to related domains, checking for specific applications, and removing software signed by certain certificate issuers.
Indicators of Compromise (59)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 192b80bab47bce9b96f683409db2fe61 2025-09-03
FileHash-MD5 213eca72f00563fa2ed788a1212c67e0 2025-09-03
FileHash-MD5 56fff546ce738e76884611ca49c5751c 2025-09-03
FileHash-MD5 62e43638548bbe4909eaf8408d8b5686 2025-09-03
FileHash-MD5 6b5e479394633f4af9957df1d847c665 2025-09-03
FileHash-MD5 6fd6c053f8fcf345efaa04f16ac0bffe 2025-09-03
FileHash-MD5 a5d7966e70b62f95ec2e3d18f5f8ab2a 2025-09-03
FileHash-MD5 b87167c7e4d8c0b180fc6a6a6643069c 2025-09-03
FileHash-SHA1 1b77beedb0b99bf5430c1a18315302399d07812c 2025-09-03
FileHash-SHA1 1eb5be9e5662811fa1412287fa8e5a2d88d0a4d2 2025-09-03
FileHash-SHA1 21df00ac8bf8baa1111f3fc564d27a9eabf0f097 2025-09-03
FileHash-SHA1 2ecd25269173890e04fe00ea23a585e4f0a206ad 2025-09-03
FileHash-SHA1 99201eee9807d24851026a8e8884e4c40245fac7 2025-09-03
FileHash-SHA1 a2278eb6a438dc528f3ebfeb238028c474401bef 2025-09-03
FileHash-SHA1 c60c964e4e0d40e5d038950d75db60b84d4cd911 2025-09-03
FileHash-SHA1 d249a92c9594c0410570a01abe2fce4cd16f762d 2025-09-03
FileHash-SHA1 e0db7b5eaf92feff220c805b0e5f3d8916e18d51 2025-09-03
FileHash-SHA1 f734dc5fb78cf67e63eae2830e656a70c015db15 2025-09-03
FileHash-SHA256 372d89d7dd45b2120f45705a4aa331dfff813a4be642971422e470eb725c4646 2025-09-03
FileHash-SHA256 46c9f63648d1a0fab977ec7b921ee1111a85402591984b12bd41391ecb2f5d6e 2025-09-03
FileHash-SHA256 6bf2cc4e9d9901541214d7efc8bb8bb24ef5bddc238598333c843e421c042c6b 2025-09-03
FileHash-SHA256 71edb9f9f757616fe62a49f2d5b55441f91618904517337abd9d0725b07c2a51 2025-09-03
FileHash-SHA256 cb15e1ec1a472631c53378d54f2043ba57586e3a28329c9dbf40cb69d7c10d2c 2025-09-03
FileHash-SHA256 d9f9584f4f071be9c5cf418cae91423c51d53ecf9924ed39b42028d1314a2edc 2025-09-03
FileHash-SHA256 da3c6ec20a006ec4b289a90488f824f0f72098a2f5c2d3f37d7a2d4a83b344a0 2025-09-03
FileHash-SHA256 e95de8452d32b439e0286868ed16f63943af3bc059dca6bcb48d1cbe2431440e 2025-09-03
FileHash-SHA256 ed797beb927738d68378cd718ea0dc74e605df0e66bd5670f557217720fb2871 2025-09-03
FileHash-SHA256 fde67ba523b2c1e517d679ad4eaf87925c6bbf2f171b9212462dc9a855faa34b 2025-09-03
domain allpdflive.com 2025-09-03
domain businesspdf.com 2025-09-03
domain convertpdfplus.com 2025-09-03
domain easyonestartpdf.com 2025-09-03
domain fastonestartpdf.com 2025-09-03
domain getonestart.co 2025-09-03
domain getonestartpdf.com 2025-09-03
domain getpdfonestart.com 2025-09-03
domain getsmartpdf.com 2025-09-03
domain gopdfhub.com 2025-09-03
domain gopdfmanuals.com 2025-09-03
domain justpdflab.com 2025-09-03
domain manualsbyonestart.com 2025-09-03
domain mypdfonestart.com 2025-09-03
domain onestartbrowser.com 2025-09-03
domain pdf-central.com 2025-09-03
domain pdfappsuite.com 2025-09-03
domain pdfdoccentral.com 2025-09-03
domain pdfeditorplus.com 2025-09-03
domain pdfonestart.com 2025-09-03
domain pdfonestarthub.com 2025-09-03
domain pdfonestartlive.com 2025-09-03
domain pdfonestarttoday.com 2025-09-03
domain pdforsmartminds.com 2025-09-03
domain printwithonestart.com 2025-09-03
domain proonestarthub.com 2025-09-03
domain proonestartpdf.com 2025-09-03
domain quickfastpdf.com 2025-09-03
domain quickpdfmanuals.com 2025-09-03
domain smartonestartpdf.com 2025-09-03
domain smartviewpdf.com 2025-09-03