Talos has created a configuration extraction tool that supports Locky (all current versions ie; Zepto/Odin) and allows you to extract the following configuration parameters that have been hardcoded into the malicious binary. This is the first open source tool which can dump the configuration parameters used by all currently known variants of Locky e.glocky,.zepto &odin based ransomware. Using the tool you can run a known Locky sample within a virtualized environment and it will extract and provide all of the configuration information for the sample, including the AffilID associated with the sample.”]
Source: https://blog.talosintelligence.com/2016/10/lockydump.html

