Locky is usually delivered via downloader in MS Office document (i.e. DOC) or JavaScript e-mail attachment in a phishing campaign. The payload is a 32-bit Windows executable, containing the malicious core packed in a crypter/dropper. After being deployed it disappears and runs its dropped copy (renamed to svchost.exe) from the %TEMP% folder. After executing, Locky displays the ransom note in text and bitmap forms, setting the latter as the affected users wallpaper.”]
Source: https://blog.malwarebytes.com/threat-analysis/2016/03/look-into-locky/

