Locky

References:
  • Dridex Actors Get In the Ransomware Game With "Locky" - 2016-02-16 - Proofpoint - Proofpoint Staff Locky Neutrino TA505
  • More Reading:

  • Inside Nuclear’s Core: Unraveling a Ransomware-as-a-Service Infrastructure - 2016-05-17 - Checkpoint - Check Point Research Nuclear Locky
  • Locky distributor uses newly released quant loader sold on Russian underground - 2016-09-14 - Forcepoint - Nicholas Griffin Quant Locky TA505
  • Sundown EK from 37.139.47.53 sends Locky Ransomware - 2016-10-17 - Malware-Traffic-Analysis - Brad Duncan WordsJS Bizarro Sundown Locky
  • Yet another Sundown EK variant? - 2016-10-18 - Malwarebytes - Jérôme Segura Bizarro Sundown WordsJS Locky
  • New Bizarro Sundown Exploit Kit Spreads Locky - 2016-11-04 - Trend Micro - Joseph C. Chen - Brooks Li Bizarro Sundown GreenFlash Sundown Locky WordsJS CVE-2016-4117 CVE-2015-7645