In the ongoing spam campaign of Locky, there is a small upgrade made by attackers in the delivery mechanism. The VBScript based downloaders have added a Geo IP check. Based on the geographical region in which the user is located, it either downloads Locky or Trickbot.
Two in One - Locky + Trickbot delivered through the same Downloader based on Geographical region.
More details here: Neutralize Cyber Threats: Locky based Downloader adds a Geo IP Check
Two in One - Locky + Trickbot delivered through the same Downloader based on Geographical region.
More details here: Neutralize Cyber Threats: Locky based Downloader adds a Geo IP Check