Oct 04 2016 10:47 AM
A client of mine received the below email:
He unfortunately clicked on it, the URL had Onedrive in it, but was just redirecting to another HTTP page. The virus then sent the above email to all contacts in Outlook. Be vigilant, people.
Oct 04 2016 01:20 PM
Oct 04 2016 02:02 PM
Umm, so what did it actually download an the user allow to run ? I guess it wasn't a .docx, it must either be something with macros (.docm) or some kind of executable, either way the user must have allowed them to run for it to be able to hijack outlook to propogate.
The social attack is one that many of my users would clearly fall for, but having clicked it I would hope that windows makes it pretty clear this isn't the file they were expecting.
Oct 06 2016 12:26 AM
Curiosity killed the cat and lets phishers install viruses.
Social engineering is the most dangerous attack. You can only try to educate your users.