Locky Downloader upgrades itself with GeoIP Check

explo1t

Level 1
Thread author
Oct 1, 2017
3
In the ongoing spam campaign of Locky, there is a small upgrade made by attackers in the delivery mechanism. The VBScript based downloaders have added a Geo IP check. Based on the geographical region in which the user is located, it either downloads Locky or Trickbot.

Two in One - Locky + Trickbot delivered through the same Downloader based on Geographical region.

More details here: Neutralize Cyber Threats: Locky based Downloader adds a Geo IP Check
 

vemn

Level 6
Verified
Malware Hunter
Well-known
Feb 11, 2017
264
Thanks for the article.
Think one of my recent samples is this sort...
Surprised to see the flag changed from USA to my country, and even changing the bank details to a local bank icon, and showing a local map of where's the nearest BitCoin ATM... zzz Innovation they call it... Customer Service Excellence...
 
  • Like
Reactions: Weebarra

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top