Skip to content

Stop

STOP/DJVU is a Windows ransomware family that encrypts victim files and appends variant-specific extensions, including .hhaz, .djvuu, .ljaz, .bhtw, .bhui, .bhgr, .agho, and .vvoa.

Profile source: Mallory opens in a new tab

Stop

Family profile

STOP/DJVU is a Windows ransomware family that encrypts victim files and appends variant-specific extensions, including .hhaz, .djvuu, .ljaz, .bhtw, .bhui, .bhgr, .agho, and .vvoa. Reported samples drop ransom notes such as _readme.txt, and one analyzed STOP/DJVU sample executed as TzjwSXczmD2hOVANbz7L7Roc.exe, contacted zexeq[.]com to retrieve a public key, then encrypted files with the .hhaz extension after reboot. In that case, encrypted files contained the mutex string {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5} at the end, and the ransom note was written to C:\Users\admin\_readme.txt.

The malware is commonly distributed through commodity malware delivery ecosystems and cracked-software lures. Supporting reporting describes STOP ransomware being delivered via SEO-poisoned cracked software sites, password-protected archives, and XLL-based infection chains. In the analyzed "CrackedCantil" intrusion, a fake cracked IDA Pro installer initiated a multi-stage chain involving PrivateLoader and Smoke loaders, multiple stealers, a miner, Socks5Systemz, and finally STOP/DJVU ransomware. STOP has also been observed as a payload distributed by the RETADUP botnet, and reporting notes delivery alongside other malware families including information stealers, click-fraud bots, cryptominers, Conti ransomware, and Arkei.

The family is widely tracked as commodity ransomware and has been reported among the more broadly distributed ransomware families in mass campaigns. One source cited STOP ransomware as 15% of massively distributed ransomware attacks in Q1 2023. There is also reporting of an extortion email address, ondrugs@firemail.cc, being seen both in a LockBit-related incident and with STOP ransomware, though the significance of that overlap is unclear.

High-confidence indicators and artifacts mentioned in the content include zexeq[.]com, the ransom note _readme.txt, the .hhaz extension, and the mutex string {36A698B9-D67C-4E07-BE82-0EC5B14B4DF5}. Variants observed by researchers append numerous other extensions, including .bhtw, .bhui, .bhgr, .agho, and .vvoa.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 3, 2026
Last activity
Aug 8, 2026
Feed role
C2 / Distribution
Host form
1 IP / 1 hostnames

Leading locations

  • GB1
  • US1

Leading providers

  • Amazon.com, Inc.1
  • Google LLC1

Infrastructure traits

  • Hosting 2

Samples

Recent associated samples

MITRE ATT&CK

Stop in ATT&CK

10 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.