From: Althea DukeWho the message is "from" varies from message to message, but the body text is the same. Analysis of the payload is pending, but it is probably similar to yesterday's Locky run.
Date: 22 June 2016 at 16:00
Subject: Corresponding Invoice
Thank you for your email regarding your order of 21 June, and sorry for the delay in replying. I am
writing to confirm receipt of your order, and to inform you that the item you requested will be delivered
by 25 June at the latest. If you require more information regarding this order, please do not hesitate to
Also, our records show that we have not yet received payment for the previous order of 11 June,
so I would be grateful if you could send payment as soon as possible. Please find attached the
If there is anything else you require, our company would be pleased to help. Looking forward to
hearing from you soon.
A little bit of analysis, via these automated reports      show some download locations as:
Various files are dropped, including these samples   the latter of which is a three week old version of Locky. Go figure. The comments in this report show C2 servers at:
18.104.22.168 (Andrey Orlov aka Relink LLC, Russia / OVH, France)
22.214.171.124 (FLP Kochenov Aleksej Vladislavovich aka uadomen.com, Ukraine)
126.96.36.199 (ITL, Bulgaria)
188.8.131.52 (PE Dunaeivskyi Denys Leonidovich, Ukraine)
Three out of those four servers are the same as yesterday.