Stop/Djvu Ransomware (2022 Guide)

Stop/Djvu Ransomware (2022 Guide)

The STOP (DJVU) ransomware codifies the users’ data with the AES-256 algorithm (CFB mode). However, it does not encrypt the entire file, but rather approximately 5 MB in its beginning. Subsequently, it asks for a ransom that amounts to $980 in Bitcoin equivalent to restore the files.

The authors of the malware have Russian roots. The frauds use the Russian language and Russian words written in English and the domains registered through Russian domain-registration companies. The crooks most likely have allies in other countries.

DJVU Ransomware Technical Info

Many users indicate that the cryptoware is injected after downloading repackaged and infected installers of popular programs, pirated activators of MS Windows and MS Office (such as KMSAuto Net, KMSPico, etc.) distributed by the frauds through popular websites. This relates to both legitimate free applications and illegal pirated software.

The cryptoware may also be spread through hacking using poorly protected RDP configuration via email spam and malicious attachments, misleading downloads, exploits, web injectors, faulty updates, repackaged and infected installers.

The list of file extensions subject to encryption:

  • MS Office or OpenOffice documents
  • PDF and text files
  • Databases
  • Photos, Music, Video or Image files
  • Archives
  • Application files, etc.

STOP/DJVU Ransomware drop files (ransom notes) named !!!YourDataRestore!!!.txt, !!!RestoreProcess!!!.txt, !!!INFO_RESTORE!!!.txt, !!RESTORE!!!.txt, !!!!RESTORE_FILES!!!.txt, !!!DATA_RESTORE!!!.txt, !!!RESTORE_DATA!!!.txt, !!!KEYPASS_DECRYPTION_INFO!!!.txt, !!!WHY_MY_FILES_NOT_OPEN!!!.txt, !!!SAVE_FILES_INFO!!!.txt and !readme.txt. The .djvu* and newer variants: _openme.txt, _open_.txt or _readme.txt

Stages of cryptoware infection

  1. Once launched, the cryptoware executable connects to the Command and Control server (С&C). Consequently, it obtains the encryption key and the infection identifier for the victim’s PC. The data is transferred under the HTTP protocol in the form of JSON.
  2. If С&C is unavailable (when the PC is not connected to the server’s Internet does not respond), the cryptoware applies the directly specified encryption key concealed in its code and performs the autonomous encryption. In this case, it is possible to decrypt the files without paying the ransom.
  3. The cryptoware uses rdpclip.exe to replace the legitimate Windows file and implement the computer network attack.
  4. Upon successful file encryption, the cipherer is autonomously removed by means of the delself.bat command file.

Associated Items

C:\Users\Admin\AppData\Local\3371e4e8-b5a0-4921-b87b-efb4e27b9c66\build3.exe
C:\Users\Admin\AppData\Local\Temp\C1D2.dll
C:\Users\Admin\AppData\Local\Temp\19B7.exe
C:\Users\Admin\AppData\Local\Temp\2560.exe
Tasks: "Azure-Update-Task"
Registry: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SysHelper

Network Traffic

clsomos.com.br
o36fafs3sn6xou.com
rgyui.top
starvestitibo.org
pelegisr.com
furubujjul.net
api.2ip.ua
morgem.ru
winnlinne.com

Antivirus detection

Crackithub.com, kmspico10.com, crackhomes.com, piratepc.net are some of the STOP Ransomware distribution sites. Any program downloaded from there can be infected with this ransomware!

In addition to encrypting a victim’s files, the DJVU family has also install the Azorult Spyware to steal account credentials, cryptocurrency wallets, desktop files, and more.

How to decrypt STOP/DJVU Ransomware files?

Djvu Ransomware essentially has two versions.

  1. Old Version: Most older extensions (from “.djvu” up to “.carote (v154)”) decryption for most of these versions was previously supported by STOPDecrypter tool in case if infected files with an offline key. That same support has been incorporated into the new Emsisoft Decryptor for these old Djvu variants. The decrypter will only decode your files without submitting file pairs if you have an OFFLINE KEY.
  2. New Version: The newest extensions were released around the end of August 2019 after the ransomware was changed. This includes .nury, nuis, tury, tuis, etc….these new versions were supported only with Emsisoft Decryptor.

What is a “file pair”?

This is pair of files that are identical (as in they are the same precise data), except one duplicate, is encrypted, and the other is not.

Sarah Jenkins
Author

Sarah Jenkins

Sarah Jenkins is a veteran tech journalist with over 12 years of experience covering artificial intelligence, mobile innovations, and digital ethics. Her insights have appeared in leading technology publications worldwide.