Saturday, May 14, 2016

What is Locky?

Locky is ransomware that upon execution encrypts certain file types present in the user’s system. Locky encrypts files and adds a .locky file extension to them.
Below is basic behaviour about how locky ransomware infects user's machine.

Main routes of locky infection are spam mail campaigns or compromised websites.
Spam mail may have two type of attachment.

   1. Word documents containing a malicious macro:

               
                         Malicious .doc file attachment

       Attached .doc file contains macro, It ask user to enable macro to view the content of the
       document

              
                          Macro in .doc file

     Once a victim enables the macros, the macros will download an executable from a remote
     server and execute it.
     The file that is downloaded by the macro will be stored in the %Temp% folder and executed.
     This executable is the Locky ransomware that when started will begin to encrypt the files on
     user's computer.

   2. JavaScript – e-mail attachment

      After office macro based attachment, Locky attacker shifted to malicious Java Script
      attachment to evade  detection :

               
                   Zip file as attachment, containing malicious JavaScript

               
                           Malicious JavaScript

           When the user runs the attached JavaScript, the JavaScript will attempt to download
            and execute the Locky ransomware                        
         
          Snapshots of a locky infected machine:

              
                  Desktop set to this .bmp image

              
                 randomname_Instruction.txt

             This randomename_instruction.txt file copied to every folder which
              infected or encrypted by Locky.

No comments:

Post a Comment