Somebody within your environment seems to have received a malicious attachment (possibly) that tries to download some nasty stuff from the internet. Malware nowadays almst never comes in its "pure" form, but rather an innocently looking Office document that by using Macros and Powershell will download the "real" malware.
You should therefore take a look at which machine is causing these threats and have your endlpoint team take a look at what's happening on that box.