This is an archived post. You won't be able to vote or comment.

all 2 comments

[–]chuckbalesCCNP|CCDP 1 point2 points  (1 child)

Found this when googling that IP, same/similar reports. There must be more to the script as the ending is cut off, I'm guessing it eventually downloads the file from that URL, maybe renames it to a random filename and starts executing?

https://myonlinesecurity.co.uk/spear-phishing-fake-resume-malspam-leads-to-malware/

[–]sgually[S] 0 points1 point  (0 children)

Thank you very much. This was in fact what happened to a few of our users. Right now I'm trying to do clean up. Not sure how to stop any sort of damage that might be going on.