From: victim@victimdomain.tldAttached is a ZIP file that matches the reference number in the subject and body text. I have only seen one sample, downloading a binary from:
Date: 17 May 2016 at 13:28
Subject: Per E-Mail senden: DOC0000329040
Folgende Dateien oder Links können jetzt als Anlage mit Ihrer Nachricht
gesendet werden:
DOC0000329040
katyco.net/0uh8nb7
The VirusTotal detection rate is 4/57, the comments in that report indicate that this is Locky ransomware and the C&C servers are at:
188.127.231.124 (SmartApe, Russia)
176.53.21.105 (Radore Veri Merkezi Hizmetleri, Turkey)
217.12.199.151 (ITL, Ukraine)
107.181.174.15 (Total Server Solutions, US)
Recommended blocklist:
188.127.231.124
176.53.21.105
217.12.199.151
107.181.174.15
No comments:
Post a Comment