From: Sophia RowlandThese two Hybrid Analyses   show what appears to be Locky ransomware being downloaded from multiple locations. The dropped binary has a detection rate of 2/55. At present I don't have any C2 servers, but I would guess they are largely the same as the ones found here.
Date: 27 June 2016 at 22:17
Attached please find the documents you requested..
Technical Manager - General Insurance
Mon, 27 Jun 2016 17:17:50 -0400