Understand Your Exposure

Threat alert: PDF Editor.exe appears compromised

The application "PDF Editor.exe" appears to have been compromised, while it is widely present across many organisations in Denmark and abroad. The following IOCs identify the version in question.

Hashes:

cb15e1ec1a472631c53378d54f2043ba57586e3a28329c9dbf40cb69d7c10d2c
abbb3e96b910c9d1e2074dc05fd51e78984941f03bcb7d443714838849a7a928

Domains, defanged:

appsuites[.]AI
MKA3E8[.]com
pdfartisan[.]com
pdfmeta[.]com
pdfreplace[.]com
y2iax5[.]com
inst.productivity-tools[.]ai

We recommend an immediate search across your environment to ensure that devices and users are safe.

If your searches result in identified matches, we recommend that:

  • Devices are reinstalled
  • User passwords are changed
  • Network connections originating from compromised devices are reviewed, to identify potential lateral movement

Stay safe.

← All news

If you need help, we're here.

Tell us where you are, and we'll help you find the right first step.

Talk to us