logo

Understanding Locky

ID: 706dae52-147a-5321-a5b0-e4f52ef6e00c

STIX ID: report--706dae52-147a-5321-a5b0-e4f52ef6e00c

Feed Name: SensePost Blog

Threat Score
75/100

Date Published: 2016-02-19

Date Updated: 2026-04-29

...
...

This report analyzes the Locky ransomware campaign (Feb 2016), describing delivery through malicious Microsoft Word macros, execution/persistence (copying to Temp, Run key), anti-analysis measures (MMX/SSE checks, INT3 loops, TLS callbacks), C2 communications (HTTP POST to main.php, DGA/hardcoded IPs), encryption behavior (AES-based file encryption with RSA-protected keys, renaming files to a 32-hex identifier + .locky), deletion of Volume Shadow Copies, and deployment of ransom notes and Tor payment infrastructure; it also provides IOCs and mitigation recommendations (backups, user awareness).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.