Locky Ransomware IOC Feed

The Locky Ransomware family was one of the most notorious of all the ransomware released in 2016. Some of its recent successors include Maze, Ryuk, Conti, DoppelPaymer and others. Locky has gone into retirement and has not been actively distributed since late 2017. This page is being maintained for historical reasons.

Locky Ransomware was originally characterized by the .locky file extension of the files it encrypts on the victim computer, although recently the actors have moved to other extensions including .odin, .zepto, .thor, .aesir, .zzzzz, .osiris, .ykcol and most recently: .asasin.

Below you will find historical Locky Ransomware Indicators of Compromise (IOC’s) from our Threat Intelligence feed. All of these indicators were internally verified using custom YARA rules and behavioural signatures. For live threat intelligence data including ransomware IOC’s from currently active families, please sign up for a free trial.

Historical Locky Ransomware IOCs

URL / IP / MD5 Date Added
http://www.accessyouraudience.com/ysohqct.exe 2019-11-21 13:44:05
http://accessyouraudience.com/ysohqct.exe 2019-11-21 12:10:06
http://watteimdocht.de/fabian/tescrypt.exe 2019-03-20 05:10:10
http://magical-connection.com/cs6yszw 2019-02-02 05:30:10
http://gelecekdiyarbakirsigorta.com/bnm4y 2018-09-24 21:00:07
http://setincon.com/brpxsfr.exe 2018-07-04 12:48:48
http://coloratour.com/VMIz0P/VMIz0P 2018-04-08 07:35:07
http://projectprocurement.com.au/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g 2018-03-30 16:33:28
http://projectprocurement.com.au/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g 2018-03-30 06:35:01
http://projectprocurement.com.au/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g/7fg3g 2018-03-30 05:33:08