Ransom Trojan

About “Trojan-Ransom.Win32.Stop.sx” infection

Malware Removal

The Trojan-Ransom.Win32.Stop.sx is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Stop.sx virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Transacted Hollowing
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • STOP ransomware registry artifacts detected
  • CAPE detected the STOP malware family
  • Attempts to modify proxy settings
  • Creates a known STOP ransomware variant mutex
  • STOP ransomware command line behavior detected
  • Uses suspicious command line tools or Windows utilities

How to determine Trojan-Ransom.Win32.Stop.sx?


File Info:

name: 11B58AD70763A8A93366.mlw
path: /opt/CAPEv2/storage/binaries/6585c215438d2bc4ade850982cc9913ceee5cafdae6177ec10c10097d5ce074d
crc32: 45237B2D
md5: 11b58ad70763a8a9336684263bba951c
sha1: 3a941ef4b095bb38efeefb4e37524539c928b6cd
sha256: 6585c215438d2bc4ade850982cc9913ceee5cafdae6177ec10c10097d5ce074d
sha512: 00e1196df275591a23c6b6e8c6c9c86f121f97afe5751049555ef0879f3315e3525e5890535dbd6b000d0c922297330f7586e328aa6a4a74c9b5bd8155138949
ssdeep: 24576:arRNJKtf3R9y+8ICBvyvyqk2qv62f/rYQJTl:octfbQIClyvyqk2WRNJTl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1200512A4D95032A5DABB23B1F3F496EE73A130030B62B43F9539467645F22E1BE152DC
sha3_384: e1b0bb0e0cb2940e9bf41b5cc615b7b8b259abe8067ce5e15e75c8ccb273660b647477bab839cca5beb790a381fb4943
ep_bytes: 60be009041008dbe0080feff668187dc
timestamp: 2020-11-24 01:50:02

Version Info:

FileVersus: 1.0.55.28
ProductVersus: 1.0.55.28
Translations: 0x0185 0x01c6

Trojan-Ransom.Win32.Stop.sx also known as:

LionicTrojan.Win32.Malicious.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Sabsik
ALYacTrojan.Ransom.Stop
CylanceUnsafe
K7AntiVirusTrojan ( 0058a2a81 )
AlibabaTrojan:Win32/Azorult.0de7406b
K7GWTrojan ( 0058a2a81 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecRansom.Ryuk!gen10
ESET-NOD32a variant of Win32/Kryptik.HKZY
APEXMalicious
AvastFileRepMalware
ClamAVWin.Malware.Filerepmalware-9864224-0
KasperskyTrojan-Ransom.Win32.Stop.sx
BitDefenderTrojan.GenericKDZ.75428
NANO-AntivirusTrojan.Win32.Stop.ivnbho
ViRobotTrojan.Win32.Z.Kryptik.853893
MicroWorld-eScanTrojan.GenericKDZ.75428
TencentWin32.Trojan.Generic.Dxmz
Ad-AwareTrojan.GenericKDZ.75428
EmsisoftTrojan.GenericKDZ.75428 (B)
F-SecureHeuristic.HEUR/AGEN.1126878
DrWebTrojan.MulDrop17.47476
ZillyaTrojan.Stop.Win32.2677
TrendMicroRansom.Win32.RYUK.SMEY.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.11b58ad70763a8a9
SophosTroj/Kryptik-TR
IkarusTrojan-Ransom.FileCrypter
GDataWin32.Trojan.PSE.66FFOU
JiangminTrojan.Chapak.mqk
AviraHEUR/AGEN.1126878
Antiy-AVLTrojan/Generic.ASMalwS.32EC9DB
GridinsoftRansom.Win32.Sabsik.sa
ArcabitTrojan.Generic.D126A4
MicrosoftTrojan:Win32/Azorult.RF!MTB
AhnLab-V3Packed/Win.GDT.C4777089
Acronissuspicious
McAfeeArtemis!11B58AD70763
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Convagent
TrendMicro-HouseCallRansom.Win32.STOP.SMYXBE2-THT
RisingTrojan.Kryptik!1.D63F (CLASSIC)
YandexTrojan.Kryptik!9YnPomFOqXs
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_97%
FortinetW32/Kryptik.HLEW!tr
BitDefenderThetaAI:Packer.858B0BF21F
AVGFileRepMalware
Cybereasonmalicious.70763a
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Ransom.Win32.Stop.sx?

Trojan-Ransom.Win32.Stop.sx removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment