Malware Signature

The following table shows a list of malware samples and the corresponding botnet C&C (ip:port) associated with Locky

Database Entry


Malware:Locky
First seen:2016-07-31 14:34:52 UTC
Last seen:2016-08-07 02:34:56 UTC

Malware Samples


The table below documents all malware samples associated with this malware family.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-08-07 02:34:5667579438b5cfa013bfb9f6ad3cf532ebVirustotal results 23/53 (43.40%) Locky23.249.164.126:443
2016-08-07 02:34:5667579438b5cfa013bfb9f6ad3cf532ebVirustotal results 23/53 (43.40%) Locky23.249.164.126:443
2016-07-31 14:34:5258a45542bc7bc051e2a8f0658ecec636Virustotal results 36/53 (67.92%) Locky23.249.164.126:443
2016-07-31 14:34:5258a45542bc7bc051e2a8f0658ecec636Virustotal results 36/53 (67.92%) Locky23.249.164.126:443