2016-07-12 - LOCKY RANSOMWARE ACTIVITY

NOTICE:

NOTES:

ASSOCIATED FILES:

  • 2016-07-12-Locky-ransomware-email-tracker.csv   (1,104 bytes)
  • 2016-07-12-Locky-ransomware-infection-from-1355-UTC-email.pcap   (174,188 bytes)
  • 2016-07-12-Locky-ransomware-infection-from-1356-UTC-email.pcap   (171,189 bytes)
  • 2016-07-12-Locky-ransomware-infection-from-1402-UTC-email.pcap   (162,357 bytes)
  • 2016-07-12-Locky-ransomware-infection-from-1408-UTC-email.pcap   (160,405 bytes)
  • emails / 2016-07-12-email-pushing-Locky-ransomwware-1355-UTC.eml   (12,895 bytes)
  • emails / 2016-07-12-email-pushing-Locky-ransomwware-1356-UTC.eml   (12,714 bytes)
  • emails / 2016-07-12-email-pushing-Locky-ransomwware-1402-UTC.eml   (12,808 bytes)
  • emails / 2016-07-12-email-pushing-Locky-ransomwware-1408-UTC.eml   (12,903 bytes)
  • attachments / alan_copies_315759.zip   (8,825 bytes)
  • attachments / gregory_forward_937188.zip   (8,850 bytes)
  • attachments / robert_copies_560364.zip   (8,708 bytes)
  • attachments / susan_copies_104906.zip   (8,782 bytes)
  • extracted-files / -SWIFT-1ec2-.js   (81,589 bytes)
  • extracted-files / -SWIFT-43f-.js   (80,760 bytes)
  • extracted-files / -SWIFT-883f-.js   (80,807 bytes)
  • extracted-files / -SWIFT-f48e-.js   (81,616 bytes)
  • files-from-infected-hosts / 3VkFo0ErNhs9.exe   (139,776 bytes)
  • files-from-infected-hosts / OWVQ1Igf.exe   (139,776 bytes)
  • files-from-infected-hosts / _HELP_instructions.bmp   (3,864,030 bytes)
  • files-from-infected-hosts / _HELP_instructions.html   (9,345 bytes)
  • files-from-infected-hosts / j4NxFPY45Bz3Q.exe   (139,776 bytes)
  • files-from-infected-hosts / xmLXfRH8gYbB7.exe   (139,776 bytes)

EMAILS


Shown above:  Email data from the spreadsheet (part 1 of 2).

 


Shown above:  Email data from the spreadsheet (part 2 of 2).

 


Shown above:  Text of the emails.

 

TRAFFIC


Shown above:  Traffic generated from the first email.


Shown above:  Traffic generated from the second email.


Shown above:  Traffic generated from the third email.


Shown above:  Traffic generated from the 4th email.

 

ASSOCIATED URLS:

 

DOMAINS FROM THE DECRYPT INSTRUCTIONS:

 

FILE HASHES

LOCKY RANSOMWARE SAMPLES FROM THE INFECTED HOSTS:

 

IMAGES


Shown above:  Infected Windows desktop from one of the emails.

 

Click here to return to the main page.