In the ongoing spam campaign of Locky, there is a small upgrade made by attackers in the delivery mechanism. The VBScript based downloaders have added a Geo IP check. Based on the geographical region in which the user is located, it either downloads Locky or Trickbot.
MD5 hash: 6e2692c124a69566838cde01b7669532
So, now Two in One based on the geographical region the user is located in.
More details here: http://www.pwncode.club/2017/10/locky-b ... check.html
MD5 hash: 6e2692c124a69566838cde01b7669532
So, now Two in One based on the geographical region the user is located in.
More details here: http://www.pwncode.club/2017/10/locky-b ... check.html