Just downloaded vbs phishing file...what do I do??

1,249 Views | 8 Replies | Last: 4 yr ago by SJEAg
agcrock2005
How long do you want to ignore this user?
AG
A client sent me an e-mail with a onedrive link and password to access the file. I downloaded it and then tried to open it was but alerted it was a vbs file. E-mailed her back asking to send over in different file type and she said it wasn't from her and to not open it. What do I need to do to protect my computer ASAP? Thank you!
UmustBKidding
How long do you want to ignore this user?
I would disconnect from network and scan. Typically to run the script it will ask you if ok and unfortunately most people just click ok.
This is becoming more popular to send cloud links since it bypasses mail scanners. Think most recent ones use powershell to grab and install a backdoor Trojan.
MouthBQ98
How long do you want to ignore this user?
AG
I assume you are running a current antivirus/security suite right now. It may handle it if it detected it.
agcrock2005
How long do you want to ignore this user?
AG
Thank you both for responses. I ran the virus and protection scan from Windows 10 and said there were 0 threats. Is that good enough or is there something else I should do? Thanks again! This is the first time I've ever been duped because it was from a client we're sending lots of documents back and forth and even the title of the vbs file was relevant to our business dealings. Scary.
jay040
How long do you want to ignore this user?
I'd run Malwarebytes (do the free trial option) and then McAfee Stinger. Reboot and run again.
Cloud
How long do you want to ignore this user?
Did you have to login with your own office 365 creds to access the file as well? If so you've been compromised. Reset your password.
AGSPORTSFAN07
How long do you want to ignore this user?
AG
You could optionally install Fiddler and watch your network I/O...see all the dirty things your machine is sending to the world wide web. Bwuhahahahahahahah!!!!
Al Bula
How long do you want to ignore this user?
AG
Cloud said:

Did you have to login with your own office 365 creds to access the file as well? If so you've been compromised. Reset your password.
username checks out
agcrock2005
How long do you want to ignore this user?
AG
jay040 said:

I'd run Malwarebytes (do the free trial option) and then McAfee Stinger. Reboot and run again.
I did this. Seems thing to be running fine. Thanks.
SJEAg
How long do you want to ignore this user?
AG
Inform your IT Security Dept, if you have one, so they can block the malicious sender's account/hostname/IP (they can see through the spoof if that's what it was) in the email gateway and the link in their web content filter. They can maybe even investigate/detonate it in a sandbox to see what the threat actually is. And really, if you actually went as far as you did they should know about it.

Be prepared to receive a tutorial video though, lol

Refresh
Page 1 of 1
 
×
subscribe Verify your student status
See Subscription Benefits
Trial only available to users who have never subscribed or participated in a previous trial.