Skip to content

Malware

STOP

aka KeyPass · Djvu

STOP Djvu Ransomware it is a ransomware which encrypts user data through AES-256 and adds one of the dozen available extensions as marker to the encrypted file's name.

STOP, also known as KeyPass, Djvu, is a Windows malware family.

Background

STOP Djvu is a ransomware that scrambles victim data with AES-256 and appends one of roughly a dozen available extensions to each encrypted file's name as a marker. Rather than encrypting whole files, it processes only the first 5 MB of each. The early version could operate offline, and in that mode it relied on a hard-coded key that could be recovered to decrypt the affected files.


Source: Malpedia (Fraunhofer FKIE).