Sample.mlw Ransomware STOP/Djvu Analysis

Ransomware STOP/Djvu
Updated on 2024-02-08 (2 months ago)
Checked by Online Virus Scanner
Online Virus Checkerv.1.0.158.174
DB Version:2024-02-08 05:00:31

Ransom.Win32.STOP.tr

STOP/Djvu Ransomware, also known simply as STOP Ransomware or Djvu Ransomware, is a type of malicious software that encrypts the files on a victim's computer and demands a ransom for their decryption. This ransomware variant has been active for several years and has affected numerous users and organizations.

Filesample.mlw
Checked2024-02-08 05:10:07
MD5defd2b4b32a95284081f3fd648e78f2e
SHA18de4263395950ceab672677754e42df7391dcd9a
SHA256235af59d3bc2171c77c0dabcb5add1ef12de8980cf1e700277288982e81eb47c
SHA51286258cfa995098e51bc0c8386c3ae154f91a8968d57878420c7cdff634ac3f1c84e6d5996b19546f58494ceea271d691bc18a7f98cc04a2421b90d1fc4c28a09
Imphash1a1df0030011d2d77bc5a076b2696337
File Size696832 bytes

Ransom.Win32.STOP.tr Removal

Ransom.Win32.STOP.tr Removal

Gridinsoft has the capability to identify and eliminate Ransom.Win32.STOP.tr without requiring further user intervention.

  • Start by downloading Gridinsoft Anti-Malware to your computer.
  • Double-click on the gsam-en-install.exe file and follow the on-screen instructions to install the program.
  • Once the installation of Gridinsoft Anti-Malware is complete, the program will open on the Scan screen.
  • Click on the "Standard Scan" button.
  • After the scanning process is finished, click on "Clean Now" to remove any detected threats.
  • If prompted, restart your system to complete the removal process.

File Version Information

FileDescriptionSecret
OriginalFilenameSpace
ProductNameJustifes
ProductVersion46.15.54.27
Translation0x0408 0x0678

Portable Executable Info

00e1e157fd6c06382fc32f1a48d75b28
baa14b831ac2432dd3365512fb89a328
bce9f6f2e0c4ebf4
Image Base:0x00400000
Entry Point:0x00401be2
Compilation:2023-06-04 10:03:43
Checksum:0x000b1ab7 (Actual: 0x000b1ab7)
OS Version:5.0
PDB Path:C:\wedi_kuje\tecafihevegiya48-surojogikot\heyolumo\nusamo\henow.pdb
PEiD:PE32 executable (GUI) Intel 80386, for MS Windows
Sign:The PE file does not contain a certificate table.
Sections:4
Imports: KERNEL32, GDI32,
Exports: 0
Resources:16

Sections

Name Virtual Address Virtual Size Raw Size MD5 Entropy
.text 0x00001000 0x0009a8a6 0x0009aa00 f64abd2ec87a8f12e61c901bbf0901e6 7.99
.rdata 0x0009c000 0x00002cd8 0x00002e00 e04720e7290b5a278a2e39adf866233f 5.42
.data 0x0009f000 0x026db57c 0x00004c00 32bbacea48029c397c9b659373383c55 0.64
.rsrc 0x0277b000 0x00007890 0x00007a00 67709ac9af6f56cfd460f3a0bacd4dfd 4.67

Leave a comment*

Share your thoughts or insights about this file. Do you align with our conclusion?

*Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Please Wait...

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware