2016-05-19 - LOCKY RANSOMWARE ACTIVITY

NOTICE:

ASSOCIATED FILE:

 

NOTES:

 

EMAILS AND ATTACHMENTS


Shown above:  Data from the .csv spreadsheet on 4 emails from today pushing Locky ransomware.

 


Shown above:  Data from the .csv spreadsheet on 4 attachments from today's emails pushing Locky ransomware.

 


Shown above:  Example from one of the emails.

 

TRAFFIC


Shown above:  Traffic from enabling macros on the .docm files, filtered in Wireshark.

 

HTTP REQUESTS FROM THE WORD MACROS:

POST-INFECTION TRAFFIC FROM THE LOCKY RANSOMWARE SAMPLE:

 

IMAGES


Shown above:  Desktop of a Windows host after enabling macros on one of the .docm files from the emails.

 

ZIP ARCHIVE CONTENTS

 

Click here to return to the main page.