According to Racco42:
#locky is back with “E 2017-08-09 (xxx).doc” campaign https://pastebin.com/Qbr66946″
Email sample: ————————————————————————————————————– From: Jeanne@[REDACTED] To: [REDACTED] Subject: E 2017-08-09 (87).xls Date: Mon, 24 Jul 2017 07:51:08 +0000 Attachment: “E 2017-08-09 (87).zip” -> “E 2017-08-09 (443).vbs” ————————————————————————————————————– – sender address is faked to look to be from same domain as recepient – subject is “E 2017-08-09 (<2-3 digits>).<doc|docx|xls|xlsx|jpg|tiff|pdf|jpg>” – email body is empty – attached file “E 2017-08-09 (<2-3 digits>).zip” contains file “E 2017-08-09 (<2-3 digits>).vbs” a VBScript downloader
Thursday, August 10, 2017
Locky Ransomware has returned with a spam campaign
A security researcher with the nickname “Racco42” found a new campaign that was pushing a new Locky variant that spread through spam emails that contain subject lines similar to E [date](random_num).docx. For example, E 2017-08-10 (698).docx. The message body contains “Files attached. Thanks”.
These emails have a compressed file attached (zip) that use the same subject name, the attached file holds a VBS downloader script. The script contains one or more URLs that will be used to download the Locky ransomware executable to the Windows %Temp% folder and then execute it.
Once it executed, it will encrypt all files. The new Locky ransomware will then modify the file name and then add the “.diablo6.”, after that, it will remove the downloaded file (exe) and then display a ransom note to the victim that presents information on how to pay the ransom.
Sadly, it is not possible to recover the original files unless you pay a ransom of 0.49 Bitcoin (about $1,600 USD).
Tags
# cyber attacker
# cyberattacker

About ANONYMOUS JEKLOY
|==========[ :: Mseesage for you :: ]===========| To All Governments of the world, we are watching you, we can see what you re doing. we control you . we are everywhere. rememeber this, the people you re trying to step on. we are everyone you depend on. we are the people who do your laundry and cook your food and serve your dinner we make your bed we guard you while you are sleeping. we drive the ambulances. we durect your calls. we are cooks and taxi drivers. we are everyone you come into contact with on a daily basis. we know everything aboutyou. we process your insurance claims and credit card charges. we control every part of your life. together we stand against the injustice of corrunt governments
cyberattacker
Labels:
cyber attacker,
cyberattacker
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment