What is Locky?
Locky is ransomware that upon execution encrypts certain file types present in the user’s system. Locky encrypts files and adds a .locky file extension to them.
Below is basic behaviour about how locky ransomware infects user's machine.
Main routes of locky infection are spam mail campaigns or compromised websites.
Spam mail may have two type of attachment.
1. Word documents containing a malicious macro:

Malicious .doc file attachment
Attached .doc file contains macro, It ask user to enable macro to view the content of the
document

Macro in .doc file
Once a victim enables the macros, the macros will download an executable from a remote
server and execute it.
The file that is downloaded by the macro will be stored in the %Temp% folder and executed.
This executable is the Locky ransomware that when started will begin to encrypt the files on
user's computer.
2. JavaScript – e-mail attachment
After office macro based attachment, Locky attacker shifted to malicious Java Script
attachment to evade detection :

Zip file as attachment, containing malicious JavaScript

Malicious JavaScript
When the user runs the attached JavaScript, the JavaScript will attempt to download
and execute the Locky ransomware
Snapshots of a locky infected machine:

Desktop set to this .bmp image

randomname_Instruction.txt
This randomename_instruction.txt file copied to every folder which
infected or encrypted by Locky.
Locky is ransomware that upon execution encrypts certain file types present in the user’s system. Locky encrypts files and adds a .locky file extension to them.
Below is basic behaviour about how locky ransomware infects user's machine.
Main routes of locky infection are spam mail campaigns or compromised websites.
Spam mail may have two type of attachment.
1. Word documents containing a malicious macro:
Malicious .doc file attachment
Attached .doc file contains macro, It ask user to enable macro to view the content of the
document
Macro in .doc file
Once a victim enables the macros, the macros will download an executable from a remote
server and execute it.
The file that is downloaded by the macro will be stored in the %Temp% folder and executed.
This executable is the Locky ransomware that when started will begin to encrypt the files on
user's computer.
2. JavaScript – e-mail attachment
After office macro based attachment, Locky attacker shifted to malicious Java Script
attachment to evade detection :

Zip file as attachment, containing malicious JavaScript

Malicious JavaScript
When the user runs the attached JavaScript, the JavaScript will attempt to download
and execute the Locky ransomware
Snapshots of a locky infected machine:
Desktop set to this .bmp image

randomname_Instruction.txt
This randomename_instruction.txt file copied to every folder which
infected or encrypted by Locky.