Djvu Ransomware
First observed in December 2018, Djvu is a new ransomware tool with similarities to the STOP ransomware.
Summary
First observed in December 2018, Djvu is a new ransomware tool with similarities to the STOP ransomware.
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, Djvu is typically delivered via cracked software downloads or bundled with adware. Once opened, it will create an MD5 hash of the affected system's MAC address to use as a unique identifier for the device. This will then be sent to a command and control server, which will respond with an encryption key.
Djvu will encrypt all reachable non-system files on the affected device and append them with a hard-coded extension. During this time, it will display a fake Windows Update screen to distract the user. Once the encryption is complete, Djvu will generate a new task that will execute the ransomware at random intervals to encrypt any new files.
Remediation steps
| Type | Step |
|---|---|
|
If a device on your network becomes infected with ransomware it will begin encrypting local machine files and files on any network the logged-in user has permission to access. For system administration accounts this may include backup storage locations. To avoid becoming infected with ransomware, ensure that:
Identifying the source of infection:
To limit the damage of ransomware and enable recovery:
|
Last edited: 14 February 2020 2:46 pm