{"id":90560,"date":"2019-01-22T15:16:34","date_gmt":"2019-01-22T12:16:34","guid":{"rendered":"http:\/\/greatis.com\/blog\/?p=90560"},"modified":"2019-01-28T15:31:14","modified_gmt":"2019-01-28T12:31:14","slug":"rumba-stop-ransomware-gets-a-huge-spread-via-adware-bundles","status":"publish","type":"post","link":"https:\/\/greatis.com\/blog\/news\/rumba-stop-ransomware-gets-a-huge-spread-via-adware-bundles.htm","title":{"rendered":"Rumba Stop Ransomware gets a huge spread via adware bundles"},"content":{"rendered":"<div class=\"wpInsert wpInsertInPostMy wpInsertAbove\" style=\"padding: 0px;\"><\/div><p>The <strong>STOP ransomware<\/strong> got a wide distribution over the last month using a method of disguising cracks as adware installers. Because of the popularity of adware installers and software cracks, STOP became one of the fastest spreading ransomware in a while. The new version of the ransomware released a few days ago appends rumba extension to the names of all your encrypted files. Previous variants used <strong>djvu<\/strong> and <strong>tro extenstions<\/strong>, but the <strong>Rumba<\/strong> version is the most distributed one.<\/p>\n<div id=\"attachment_90561\" style=\"width: 650px\" class=\"wp-caption alignnone\"><a href=\"http:\/\/greatis.com\/blog\/wp-content\/uploads\/2019\/01\/ransomware-2430833_640.jpg\"><img aria-describedby=\"caption-attachment-90561\" loading=\"lazy\" class=\"size-full wp-image-90561\" src=\"http:\/\/greatis.com\/blog\/wp-content\/uploads\/2019\/01\/ransomware-2430833_640.jpg\" alt=\"\" width=\"640\" height=\"240\" srcset=\"https:\/\/greatis.com\/blog\/wp-content\/uploads\/2019\/01\/ransomware-2430833_640.jpg 640w, https:\/\/greatis.com\/blog\/wp-content\/uploads\/2019\/01\/ransomware-2430833_640-300x113.jpg 300w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><p id=\"caption-attachment-90561\" class=\"wp-caption-text\">Ransomware<\/p><\/div>\n<p>Usually, user gets the infection when downloading software <strong>bundles or cracks<\/strong> from the sites that use adware bundles to generate revenue for themselves. This bundles usually contain a big variety of <strong>potentially unwanted programs (PUPs)<\/strong>, miners and ad software, but lately a few bundles started including STOP ransomware with the other things.<\/p><div class=\"wpInsert wpInsertInPostMy wpInsertMiddle\"><\/div>\n<p>According to reports, the cracks, containing STOP Ransom, are popular copyrighted software, Windows activation cracks and various antivirus programs. There doesn&#8217;t seem to be one particular source of ransomware distribution, but a lot of crack sites distributing the same adware bundles are affected.<\/p>\n<p>The latest version of STOP encrypts the files, appending the <strong>rumba extension<\/strong> to their names, while creating a ransom note in the every folder it encrypted. This note contains the instructions on contacting the hacker and the payment instructions.<\/p>\n<p><strong>In some cases<\/strong>,\u00a0 it is possible to recover your files for free using <strong>STOPDecrypter<\/strong> software by Michael Gillespie. The latest version of the STOPDecrypter supports various extensions (.<strong>djvu, .djvuq, .djvur, .djvut, .djvuu, .pdff, .tfude, .tfudeq, .tro, .udjvu, .tfude<\/strong>t).<\/p>\n<p><a href=\"https:\/\/www.bleepingcomputer.com\/forums\/t\/690553\/stopdecrypterexe-ver-2015-cannot-decrypt-my-file\/\">More info about STOPDecrypter&#8230;<\/a><\/p>\n<div class=\"wpInsert wpInsertInPostMy wpInsertBelow\" style=\"padding: 0px;\"><\/div>","protected":false},"excerpt":{"rendered":"<p>The STOP ransomware got a wide distribution over the last month using a method of disguising cracks as adware installers. Because of the popularity of adware installers and software cracks, STOP became one of the fastest spreading ransomware in a while. The new version of the ransomware released a few days ago appends rumba extension [&hellip;]<br \/><a style=\"color: #42A2CE\" href=\"https:\/\/greatis.com\/blog\/news\/rumba-stop-ransomware-gets-a-huge-spread-via-adware-bundles.htm\"><u>More&#8230;<\/u><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[94714],"tags":[],"_links":{"self":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/posts\/90560"}],"collection":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/comments?post=90560"}],"version-history":[{"count":0,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/posts\/90560\/revisions"}],"wp:attachment":[{"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/media?parent=90560"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/categories?post=90560"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/greatis.com\/blog\/wp-json\/wp\/v2\/tags?post=90560"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}