A new version of Locky has been released that appends the.shit. extension on encrypted files. This variant is currently being distributed through SPAM emails with a subject line of Receipt. Ransomware is installed using a DLL that is executed by Rundll32.exe. Once executed, it will encrypt targeted file types and append the.shit extension to the name of encrypted. files. The targeted extensions are:.yuv,.ycbcra,.xis,.,.tex,.sxg,.stx,.muhd,.stm,.dac,.dub,.nxl,.nwb,.nrw,.nop,.nef,nef,.neF,neF,.m,.myd,.nr,nf,.nh,nh,.mnn,nnn,nnnn,jpe,.
Source: https://www.bleepingcomputer.com/news/security/locky-ransomwares-new-shit-extension-shows-that-you-cant-polish-a-turd/

