Attached is the paper concerning with the cancellation of your current credit card malspam delivering Locky Ransomware — 1 Comment

  1. That’s a change. Usually the payloads have the same file name :S
    Tried one and it doesn’t do the decrypt thing (mind you I don’t have a source file to decompile yet)
    They haven’t hit us yet…

