logo

Executive Impersonation Email Delivering Malicious PDF Link

ID: dbe210c0-b53b-41ff-ae32-80e35be726cb

STIX ID: report--dbe210c0-b53b-41ff-ae32-80e35be726cb

Threat Score

62/100

Uploaded: 2026-04-13

Created by: Report Uploader

TLP:GREEN
...
...
A regional sales organization received CEO-impersonation phishing emails on 11 April 2026 containing a malicious PDF (Strategic_Update_Q2.pdf) that redirected to https://executive-briefing-center.net/open?id=55312 to download briefing_update.js; execution launched PowerShell to fetch an additional payload from 172.104.55.73. Observed IOCs include sender office.ceo@global-boardmail.com, the PDF attachment, the redirect URL, the JavaScript filename, and the payload IP.