Ransomware Research
STOP Ransomware
STOP is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on December 1, 2017, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: STOP-Keypass, STOP-Djvu, Djvu.
Quick Facts
- Ransomware Family
- STOP
- First Seen
- December 1, 2017
- Known Aliases
- STOP-KeypassSTOP-DjvuDjvu
How STOP Ransomware Works
Targeted Files
https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-puma-djvu-promo-drume-support-topic https://www.bleepingcomputer.com/forums/t/671473/stop-ransomware-stop-suspended-yourdatarestore-txt-support-topic
File Encryption Patterns
STOP modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..STOP
..promorad
..DATASTOP
..STOPDATA
..KEYPASS
..WHY
..SAVEfiles
..DATAWAIT
..INFOWAIT
..puma
..pumax
..pumas
..shadow
..djvu
..jzeq
..jzie
..djvuu
..udjvu
..uudjvu
..codnat
..djvuq
..djvus
..djvur
..djvut
..djvup
..pdff
..tro
..tfude
..tfudeq
..tfudet
..rumba
..adobe
..adobee
..blower
..promos
..promoz
..promok
..promorad2
..kroput
..kroput1
..charck
..pulsar1
..klope
..kropun
..charcl
..kropun1
..doples
..luces
..luceq
..chech
..proden
..drume
..tronas
..grovas
..trosak
..grovat
..roland
..refols
..raldug
..etols
..guvara
..browec
..norvas
..moresa
..verasto
..hrosas
..kiratos
..todarius
..hofos
..roldat
..dutan
..sarut
..fedasot
..berost
..forasom
..fordan
..bufas
..dotmap
..radman
..ferosas
..rectot
..skymap
..mogera
..rezuc
..stone
..redmat
..lanset
..davda
..poret
..pidon
..heroset
..boston
..myskle
..muslat
..gerosan
..vesad
..horon
..neras
..truke
..dalle
..lotep
..nusar
..litar
..besub
..cezor
..gycc
..gyew
..gyza
..lokas
..godes
..budak
..vusad
..herad
..berosuce
..gehad
..gusau
..madek
..tocue
..darus
..lapoi
..todar
..dodoc
..bopador
..novasof
..ntuseg
..ndarod
..access
..format
..nelasod
..mogranos
..cosakos
..nvetud
..lotej
..kovasoh
..prandel
..zatrov
..masok
..brusaf
..londec
..krusop
..mtogas
..nasoh
..coharos
..nacro
..pedro
..nuksus
..vesrato
..cetori
..masodas
..stare
..carote
..shariz
..gero
..hese
..xoza
..seto
..peta
..moka
..meds
..kvag
..domn
..karl
..nesa
..boot
..noos
..kuub
..reco
..bora
..leto
..nols
..werd
..coot
..derp
..nakw
..meka
..toec
..mosk
..lokf
..peet
..grod
..mbed
..kodg
..zobm
..rote
..msop
..hets
..righ
..gesd
..merl
..mkos
..nbes
..piny
..redl
..kodc
..nosu
..repp
..alka
..bboo
..rooe
..mmnn
..ooss
..mool
..nppp
..rezm
..lokd
..jazi
..jawr
..foop
..remk
..npsk
..opqz
..mado
..jope
..mpaj
..lalo
..lezp
..qewe
..mpal
..sqpc
..mzlq
..koti
..covm
..pezi
..nlah
..kkll
..zwer
..nypd
..usam
..tabe
..vawe
..moba
..pykw
..zida
..maas
..repl
..kuus
..erif
..kook
..nile
..oonn
..vari
..boop
..geno
..kasp
..ogdo
..npph
..kolz
..copa
..lyli
..moss
..foqe
..mmpa
..efji
..iiss
..jdyi
..vpsh
..agho
..vvoa
..epor
..sglh
..lisp
..weui
..nobu
..igdm
..booa
..omfl
..igal
..qlkm
..coos
..wbxd
..pola
..cosd
..plam
..ygkz
..cadq
..tirp
..ribd
..reig
..enfp
..ekvf
..ytbn
..fdcz
..urnb
..lmas
..iicc
..wrui
..rejg
..pcqq
..igvm
..nusm
..ehiz
..eqew
..paas
..pahd
..mppq
..qscx
..sspq
..iqll
..ddsg
..gatz
..eqza
..gash
..qopz
..qore
..fofd
..sato
..saba
..foty
..foza
..coty
..kiop
..kiwm
..kifr
..jycx
..jypo
..jywd
..jyos
..typo
..tyos
..tywd
..darj
..dapo
..dazx
..craa
..qarj
..qazx
..qapo
..coba
..coaq
..cosw
..goba
..goaq
..gosw
..qotr
..qoqa
..qowd
..iotr
..iowd
..ioqa
..hhoo
..hhee
..hhmm
..tgvv
..tgpo
..thgz
..bhgr
..bhui
..bhtw
..ahtw
..ahgr
..ahui
..neqp
..neon
..nerz
..erqw
..assm
..mztu
..mzop
..mzqw
..pouu
..poqw
..zouu
..zoqw
..bpto
..bpws
..bpsm
..znto
..taqw
..taoy
..tasa
..yytw
..yyza
..popn
..poaz
..wspn
..wsaz
..wsuu
..kitu
..kizu
..kiqu
..miqe
..mitu
..miza
..gaqq
..waqq
..gazp
..gayn
..wazp
..wayn
..agvv
..agpo
..aghz
..vvoo
..vvmm
..erop
..weqp
..werz
..weon
..vatq
..vaze
..vapo
..gaze
..gatq
..gapo
..xaro
..xatz
..xash
..nzoq
..teza
..nzqw
..nztt
..wzer
..wzoq
..wztt
..wzqw
..jaqw
..jaoy
..jasa
..mzre
..mzqt
..mzhi
..azop
..azqt
..azhi
..wwty
..wwpl
..wwza
..oohu
..oopl
..ooza
..hgew
..hgfu
..hgml
..hgkd
..rzew
..rzml
..rzkd
..ttwq
..ttrd
..ttap
..ttza
..mlwq
..mlrd
..mlap
..mlza
..ptqw
..pthh
..ptrz
..ithh
..itqw
..itrz
..zpas
..zput
..zpww
..ppvs
..ppvt
..ppvw
..yzqe
..yzoo
..yzaq
..nbzi
..hhuy
..hhaz
..ljuy
..ljaz
..nbwr
..niwm
..cdqw
..cdmx
..cdaz
..cdwe
..cdtt
..cdpo
..cdcc
..ldhy
..cdxx
..nooa
..qqqe
..iisa
..wnlu
..hoop
..pqgs
..orkf
..koom
..bbbw
..bbbe
..cuag
..bbbr
..yoqs
..stax
..eucy
..nqhd
..maiv
..lkfr
..lkhy
..muuq
..miia
..irjg
..rtgf
..qqqw
..moia
..zaps
..aeur
..cool
..wisz
..wiaw
..nood
..looy
..vook
..kool
..uazq
..uajs
..kaaa
..bgjs
..bgzq
..qehu
..qepi
..vepi
..vehu
..paaa
..qeza
..veza
..lqqw
..xcmb
..waqa
..zzla
..rivd
..maql
..tisc
..nqsq
..piiq
..reqg
..maak
..vtua
..guer
..qmak
..hlas
..vfgj
..neer
..sevr
..pooe
..moqs
..wiot
..efdc
..hgsh
..ufwj
..gujd
..irfk
..rigd
..mmuz
..udla
..ttii
..xcvf
..voom
..fgnh
..rigj
..sijr
..bbnm
..npsg
..xcbg
..gtys
..fgui
..hhjk
..iiof
..dewd
..jhbg
..qbaa
..nuhb
..dmay
..egfg
..mmob
..bpqd
..rguy
..dwqs
..wdlo
..zqqw
..ssoi
..hajd
..fefg
..ifla
Ransom Note and Payment Demands
After encrypting files, STOP displays ransom notes demanding payment for file recovery:
!!!DATA_RESTORE!!!.txt
!!!RESTORE_DATA!!!.txt
!!!KEYPASS_DECRYPTION_INFO!!!.txt
!!!DECRYPTION__KEYPASS__INFO!!!.txt
!!!WHY_MY_FILES_NOT_OPEN!!!.txt
!!!SAVE_FILES_INFO!!!.txt
!readme.txt
Ransom message:
notes/!readme.txt
Note locations:
EveryFolder
_openme.txt
Ransom message:
notes/_openme.txt
Note locations:
EveryFolder
_readme.txt
Ransom message:
notes/_readme.txt
Note locations:
EveryFolder
_open_.txt
__readme.txt
!!!YourDataRestore!!!.txt
Technical Indicators
Associated Executable Files
The following executable files are associated with STOP ransomware:
0302_2019-02-03_15-41.exe
05177199.exe
08212099.exe
09446899.exe
1.bin
1.exe
1601_2019-01-16_22-58.exe
1846355404.EXE
1MBIKZ45.exe
20240829253.exe
23954824.exe
2401_2019-01-24_12-52.exe
3.exe
34EFCDSAX.EXE.TMP
34fedwfe.exe
39.exe
3b84.exe
3BD2J1DJ.exe
3c31.exe
3db3.exe
419b.exe
585939.exe
7F2E.EXE
850867.exe
8687460552.EXE
A3E1binexe.exe
afvtnii.exe
aiecxdy.exe
aludci.exe
amix.exe
aslejn.exe
aylpsaww.exe
ays3ueggw.exe
azbmtwy.exe
B2.tmp.exe
bdpxte.exe
be2.exe
betting.exe
bigthing.exe
bin.bin
bqiewt.exe
brgrtv3f.exe
brpwmfdl.exe
bsvnx.exe
build.exe
buildp.exe
buildz.exe
Bujingle.exe
Buskepas.exe
cjebe.exe
covf.exe
CUsersabdoAppDataLocalde14c4d4-af10-40ba-b2e7-b7cd78dfba75FCEB.tmp.exe
CUsersUsAppDataLocalda3f3088-b399-4c9e-9d41-a0f53620c708E214.tmp.exe
cveog.exe
DHL7YG.exe
DJVU Ransomware.exe
dmkdih.exe
dubi.exe
DW8VXDZI.exe
edrgweasdvrb.exe
efzdqtpc.exe
enbyzga.exe
eqmmweay.exe
executable.exe
eyrfrip.exe
F9RT5XP5.exe
factura.exe
Fameros.exe
fce.exe
file.bin
file.exe
fjklzp.exe
fkpbzs.exe
fphemzq.exe
fqkwzdo.exe
fsprm.exe
fumiefqw.exe
funuir.exe
fwnfeic.exe
fyyfc.exe
gapijonc.exe
gayn.exe
gazp.exe
gdusei.exe
gehfgfjk.exe
gepquoqguv.exe
gFaZbGmI
gixj.exe
glitters.exe
gunshot.exe
gvhhzwub.exe
HerbalEssentials.exe
hgxctcth.exe
hlmoj.exe
Huklus.exe
humanity.exe
Hungle.exe
Hunlipaos.exe
hvfcfwbh.exe
hvlawaos.exe
HYDOADC8.exe
IEWO4X01.exe
important.exe
important_document.exe
ISJ5KN4I.exe
IVE39D.exe
jrinzssq.exe
jrsnygu.exe
jsjof.exe
jtdnwf.exe
JTDNWF.EXE
Keypass.exe
killeryuga.exe
km0TTTU1Ig.exe
krgqwi.exe
kyamstr.exe
liegkzrz.exe
load1903.exe
logger270.exe
lpjlujyr.exe
lwxhwfcu.exe
msoffice.exe
mvsnmp.exe
myfile.exe
NUMXYW9D.exe
olbkummk.exe
oqrvau.exe
oqvq.exe
ozlep.exe
PBER65.exe
pbky.exe
petshop.exe
phpAdLvuq
phpwXWVud
pqqfom.exe
proc.exe
ProcessKiller.exe
program.exe
PUQ5X3W2.exe
pzsjx.exe
qdnhqd.exe
qfnxti.exe
qgrm9yxfr9.exe
qhnvv.exe
qnsuk.exe
qoapybn.exe
qtyzkum.exe
qvwloVnL.exe
qwvqvk.exe
R2JL7SXH.exe
redcsrvtf.exe
report727.exe
rewrtrbvfd.exe
ridaigx.exe
RJ9067X4.exe
rlpvcs.exe
ryuk.exe
sample.mlw
sbap.exe
sbut.exe
Setup160.exe
sgsdfgds.exe
sifrtud
sndjxmz.exe
software.exe
sqlreader.exe
start.exe
starticon2.exe
STOP.exe
Stop.exe
Stop7.exe
svhost.exe
swyfkv.exe
talq.exe
tcygx.exe
Techniques.exe
twgiwo.exe
twgruos.exe
tygrfed.exe
ubmahi.exe
ucxiwb.exe
uiabfuuc.exe
UIXF9YSH.exe
ukqxssy.exe
update.exe
updatewin.exe
updatewin1.exe
uqksn.exe
urpress.bin
urpress.exe
uvjhup.exe
uwzqmrjc.exe
vatup.exe
vwmzyfx.exe
wchnu.exe
wcvqmaz.exe
wcyn.exe
WMPLAYER.EXE
wmplayer.exe
wnyknmp.exe
xnnhvtk.exe
xspf.exe
ycnsqgn.exe
yhom.exe
yhtvjk.exe
yipogls.exe
yowa.exe
ythgrfed.exe
YTHGRFED.EXE
yvircma.exe
yvxi.exe
zBeQxOa
zejw.exe
zldik.exe
zplgo.exe
zqvu.exe
zstimge.exe
zufocosq.exe
ZXJ9GJ.exe
zzz.exe
rfcle.exe
ckdlp.exe
qorw.exe
ljrhywfh.exe
malware.exe
gsqonx.exe
jpcmgaay.exe
crack.exe
4088.exe
zbetcheckin_tracker_49.exe
tngub.exe
tlde.exe
xukac.exe
zunzzjvu.exe
behasavunu.exe
Recovery and Decryption Tools
Good news! Decryption tools are available for STOP ransomware:
0
1
2
Elastio Can Help You
Don't let STOP ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This STOP ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like STOP.
Last updated: July 30, 2025