Upgraded malicious Word, Excel attachments targeting WFH employees

April 1, 2020
  • Unusual severity event for your VPN server device
  • Account authentication from a rare geolocation
  • VPN connection from anonymous proxy
  • Connection to a rare domain for a peer group followed by an executable download
  • Landspeed anomaly
  • Emails from typosquatted domain
  • Abnormal number of emails sent to a rare external recipient
  • Abnormal amount of data sent to a rare external recipient
  • Unusual VPN session length
  • Unusual amount of data for VPN session compared to peers
  • Unusual sensitive data access increase for a user
prestitial ad