STOP (Djvu) ransomware – What is STOP (Djvu) Ransomware | Djvu Ransomware analysis

Опубликовано: 01 Ноябрь 2024
на канале: CSI digital
1,015
17

STOP (Djvu) ransomware – What is STOP (Djvu) Ransomware | Djvu Ransomware analysis

In this episode we are going to talk about the STOP (aka DJVU)l Ransomware family. STOP ransomware is a family with over 300 members that expands almost on a weekly basis and counts as one of the most widespread ransomware families. STOP has up to 200 variants (extensions), using a CC2 server for encryption key generation when internet access is present and using a local key, less complex, encryption if no Internet is available. Targeting mostly simple (consumer) users this ransomware can be a perfect example of a ”classic” ransomware

STOP is a ransomware that runs on Microsoft Windows. The ransomware first made its appearance in December 2017. The malware uses the Crypto++ implementation and encrypts user data with AES-256 (or Salsa20 in later variants) and add a certain file extension. New versions are created almost every month and is known to appending the following extensions: .SAVEfiles, .puma, .pumas, .pumax, .shadow, .keypass, DJVU and many other extensions.

This campaign has been very successful, with ID-Ransomware reporting numerous victims submitting files to their system on a daily basis. In Q2 2021 Emsisofts Ransomware report showed the DJVU variant of STOP ransomware commanding 70% of the entire reported infection landscape. Each victim is asked to pay $300-600 for the data decryptor by the ransomware gang.

Remove STOP/ DJVU Ransomawwre Virus 2021
MacOS: If your computer is already infected with Djvu, we recommend running a scan with Combo Cleaner Antivirus for macOS to automatically eliminate this ransomware.

1. Start downloading the decryption tool1 through the same website that developed this “How To” guide.
2. Make sure to launch the decryption utility as an administrator. You need to agree with the license terms that will come up. For this purpose, click on the “Yes” button:
3. As soon as you accept the license terms, the main decryptor user interface comes up:
4. Based on the default settings, the decryptor will automatically populate the available locations to decrypt the currently available drives (the connected ones), including the network drives. Extra (optional) locations can be selected with the help of the “Add” button.
5. Decryptors normally suggest several options considering the specific malware family. The currently possible options are presented in the Options tab and can be activated or deactivated there. You may locate a detailed list of the currently active Options below.
6. As soon as you add all the desired locations for decryption into the list, click on the “Decrypt” button to initiate the decryption procedure. Note that the main screen may turn you to a status view, letting you know of the active process and the decryption statistics of your data:
7. The decryptor will notify you as soon as the decryption procedure is completed. If you need the report for your personal papers, you can save it by choosing the “Save log” button. Note that it is also possible to copy it directly to your clipboard and to paste it into emails or forum messages if you need to do so.


How to protect yourself from ransomware infections?
To avoid ransomware-type infections (and other threats), carefully study each received email, especially if it contains attachment. If the email seems irrelevant (does not concern you), or is sent from an unknown/suspicious address, do not download or open the attachment, or any web link. Use official software update tools only - implemented functions or updaters provided by official software developers. Any other (unofficial) updaters/tools should not be trusted. Download apps, files (software) using official websites (or other official sources). Do not use third party channels, since they are often used to distribute various rogue downloaders/installers or even malware. Have a reputable anti-virus or anti-spyware suite installed and active. These tools deal with various threats and computer infections, and often detect and eliminate them before any damage is done.



#STOP_ransomware
#djvu_ransomware
#keypass_ransomware
#stop_djvu_ransomware_Kaspersky
#djvu_ransomware_analysis
#djvu_ransomware_reddit
#malware
#what_is_malware
#rootkit
#rootkits
#ransomware_attack
#ransomware_attacks
#what_is_ransomware
#Ransomware
#Phishing
#what_is_spear_phishing
#what_is_botnets
#what_is_a_botnet
#what_is_botnet
#cybersecurity