2016-05-03 - LOCKY RANSOMWARE ACTIVITY

NOTICE:

ASSOCIATED FILES:

 

NOTES:

The Palo Alto Networks Unit 42 blog about Locky ransomware can be found here.

Proofpoint's blog about Locky ransomware is available here.

Other posts also covering these same items of Locky ransomware emails from today include:

 

EMAILS AND ATTACHMENTS


Shown above:  Data from the .csv spreadsheet on 10 emails from today's Locky ransomware.

 


Shown above:  Data from the .csv spreadsheet on 10 attachments from today's Locky ransomware.

 

TRAFFIC


Shown above:  Traffic from executing the extracted .js files, filtered in Wireshark.

 

HTTP REQUESTS FROM THE EXTRACTED .JS FILES:

POST-INFECTION CALLBACK FROM THE LOCKY RANSOMWARE SAMPLES:

 

IMAGES


Shown above:  Desktop of a Windows host after executing one of the .js attachments from the malspam.

 

ZIP ARCHIVE CONTENTS

 

Click here to return to the main page.