The STOP/DJVU ransomware is a Trojan that encrypts files.
It infiltrates your computer invisibly and encrypts all of your data, making them unavailable to you.
It leaves a ransom letter warning which demands money in exchange for decrypting your data and making them available to you again.
Malware is delivered via cracked applications, fake set-up apps keygens, activators, and Windows updates.
It does not utilize local information like keyboard layouts or timezone settings to prevent infecting victims in certain countries; instead, it uses the information returned by a request to https[:]//api.2ip.ua/geo.json.
The card’s MAC address is utilized to provide unique identification for the system.
This identity is provided to STOP’s command and control server, which responded with an RSA-2048 public key for encryption.