Last seven days
- First activity
- Aug 3, 2026
- Last activity
- Aug 8, 2026
- Feed role
- C2 / Distribution
- Host form
- 1 IP / 1 hostnames
STOP/DJVU is a Windows ransomware family that encrypts victim files and appends variant-specific extensions, including .hhaz, .djvuu, .ljaz, .bhtw, .bhui, .bhgr, .agho, and .vvoa.
Profile source: Mallory opens in a new tabStop
STOP/DJVU is a Windows ransomware family that encrypts victim files and appends variant-specific extensions, including .hhaz, .djvuu, .ljaz, .bhtw, .bhui, .bhgr, .agho, and .vvoa. Reported samples drop ransom notes such as _readme.txt, and one analyzed STOP/DJVU sample executed as TzjwSXczmD2hOVANbz7L7Roc.exe, contacted zexeq[.]com to retrieve a public key, then encrypted files with the .hhaz extension after reboot. In that case, encrypted files contained the mutex string {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5} at the end, and the ransom note was written to C:\Users\admin\_readme.txt.
The malware is commonly distributed through commodity malware delivery ecosystems and cracked-software lures. Supporting reporting describes STOP ransomware being delivered via SEO-poisoned cracked software sites, password-protected archives, and XLL-based infection chains. In the analyzed "CrackedCantil" intrusion, a fake cracked IDA Pro installer initiated a multi-stage chain involving PrivateLoader and Smoke loaders, multiple stealers, a miner, Socks5Systemz, and finally STOP/DJVU ransomware. STOP has also been observed as a payload distributed by the RETADUP botnet, and reporting notes delivery alongside other malware families including information stealers, click-fraud bots, cryptominers, Conti ransomware, and Arkei.
The family is widely tracked as commodity ransomware and has been reported among the more broadly distributed ransomware families in mass campaigns. One source cited STOP ransomware as 15% of massively distributed ransomware attacks in Q1 2023. There is also reporting of an extortion email address, ondrugs@firemail.cc, being seen both in a LockBit-related incident and with STOP ransomware, though the significance of that overlap is unclear.
High-confidence indicators and artifacts mentioned in the content include zexeq[.]com, the ransom note _readme.txt, the .hhaz extension, and the mutex string {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}. Variants observed by researchers append numerous other extensions, including .bhtw, .bhui, .bhgr, .agho, and .vvoa.
C2 tracking
Derp observations, rolling seven-day window
Samples
0c9dcfdf93535e11604637b01d81f471ef51b3a05a2692eb533c070fc219bb11 18cc7151267890f8e9f0e6096d9117582d41bc0d2d1447e734f6c7c9d7ea9a00 36f9c1c16e61d629ea716ac68861a2c8d0e69af44a2902ea952bf69ee3aefee2 849adaf4c209ff5e5764e7a1314e63fc83ce0cab7d0f78d8ce59ae375f767a0f db007256f974410925b903e551bb69191bc749d18180eedfa8b481736da5469f 85b413ee82c9de0f59b3ef213dc5d1e49ac0eb5e576a8609ae8f1bdf30866405 86bd7587ac0f72146d933fbb1eae807f31160a8dcc49502bfefedf17e1fc6d23 aeb547edb0829aed4029a11a2b73f1b2dafa6bfedf1e8632050c8636291829e5 fc394da215108025953b9dece68a781cd1abc4742401bfc341b0c265be01fb9f fdfd0b06cb31d68146dbb5ffb45b82ca1b59a7b4f62f917a990a9c3bd01654ab MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.