Online Virus Checker | v.1.0.168.174 |
DB Version: | 2024-03-12 03:00:41 |
STOP/Djvu Ransomware, also known simply as STOP Ransomware or Djvu Ransomware, is a type of malicious software that encrypts the files on a victim's computer and demands a ransom for their decryption. This ransomware variant has been active for several years and has affected numerous users and organizations.
File | nood |
Checked | 2024-03-12 02:02:28 |
MD5 | 373dbc2f5f92e4b275e9a6716b432d98 |
SHA1 | a74b2bce1c8d9d89ec0cb5c80d4df3cad0a1480b |
SHA256 | 9f24cff00ff55730e61d9fd9a182f92f272735ba6ce55bc93bdc7ea24424dc42 |
SHA512 | d79ae6ca8f2fd0e8a2626b10167a93c97e72f6ac89f51d2ceaba8258322e97ac0997b6b6276f728aa876e7fe30222a4423df25b16c5c69bf8787df095690ee63 |
Imphash | e4b2b7336d3e0f97560f9bdf06345817 |
File Size | 775168 bytes |
Gridinsoft has the capability to identify and eliminate Ransom.Win32.STOP.tr without requiring further user intervention.
FileVersions | 72.15.66.32 |
ProductVersion | 71.84.54.50 |
InternalName | Slupido |
CompanyNames | Laying |
Translation | 0x146c 0x0235 |
c1abe480a75b51ed87430b507a2d5c70 bcf813c72901e7647d313b9058ca5962 f2f0c494ecf0b1f0 |
|
Image Base: | 0x00400000 |
Entry Point: | 0x00401490 |
Compilation: | 2023-01-13 03:25:08 |
Checksum: | 0x000c5887 (Actual: 0x000c5887) |
OS Version: | 5.1 |
PEiD: | PE32 executable (GUI) Intel 80386, for MS Windows |
Sign: | The PE file does not contain a certificate table. |
Sections: | 4 |
Imports: | KERNEL32, USER32, |
Exports: | 0 |
Resources: | 33 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000b66e | 0x0000b800 | fa8c24bac3b140ed99706c6ecf7a9fa7 | 6.67 |
.rdata | 0x0000d000 | 0x0009af6e | 0x0009b000 | fae1622c219885a43c84d3d3ad095995 | 7.85 |
.data | 0x000a8000 | 0x01ad76f4 | 0x00002c00 | 7f0f43f8f43646f845984c35e265e14a | 1.69 |
.rsrc | 0x01b80000 | 0x00013b10 | 0x00013c00 | bc182405f09f5c4b987ec96d9614668e | 5.82 |