Threat Database Ransomware STOP.YQAL.NNQP.SHGV.MOIA Ransomware

STOP.YQAL.NNQP.SHGV.MOIA Ransomware

By CagedTech in Ransomware

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 6,480
First Seen: November 29, 2021
Last Seen: December 31, 2025
OS(es) Affected: Windows

The detection of STOP.YQAL.NNQP.SHGV.MOIA Ransomware on a system indicates a serious security threat that requires immediate attention. Ransomware is a type of malware designed to encrypt files on a victim's computer, demanding payment in exchange for the decryption key. This report provides an overview of the threat, its operational methods, symptoms of infection, and steps to remove it from an affected system.

What Is STOP.YQAL.NNQP.SHGV.MOIA Ransomware?

Ransomware, like STOP.YQAL.NNQP.SHGV.MOIA Ransomware, is a malicious software that uses encryption to hold a victim's data hostage. It typically spreads through phishing emails, exploited vulnerabilities in software, or infected software downloads. Once inside a system, it begins to encrypt files, making them inaccessible to the user. The attackers then demand a ransom, usually in cryptocurrency, in exchange for the decryption key.

How STOP.YQAL.NNQP.SHGV.MOIA Ransomware Operates

The operational methods of STOP.YQAL.NNQP.SHGV.MOIA Ransomware involve exploiting system vulnerabilities to gain access, followed by the encryption of files. This malware can also spread laterally within a network if not contained, encrypting files on other connected devices. The encryption process is typically rapid, and the malware may also attempt to disable system recovery options to prevent victims from restoring their data from backups.

Symptoms of Infection

Symptoms of STOP.YQAL.NNQP.SHGV.MOIA Ransomware infection include the inability to access files, with files often having unusual extensions appended to them. Victims may also find ransom notes left on their desktop or in folders where files have been encrypted, demanding payment for decryption. System slowdowns and unusual network activity can also be indicators of a ransomware infection.

How to Remove STOP.YQAL.NNQP.SHGV.MOIA Ransomware

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. This can help identify and remove the malware and other related threats.
  3. Uninstall any suspicious programs that were installed around the time of the infection. These could be malicious or compromised applications that facilitated the ransomware's entry into your system.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings that the ransomware might have altered.
  5. Reboot your system and perform another full scan with your anti-malware tool to ensure that all traces of the malware have been removed. Regularly updating your operating system, software, and security tools can help prevent future infections.

Conclusion

The STOP.YQAL.NNQP.SHGV.MOIA Ransomware poses a significant threat to data security and integrity. Understanding its operational methods and recognizing the symptoms of infection are crucial for taking prompt action. By following the removal steps outlined above and maintaining good cybersecurity practices, such as regularly backing up data and keeping software up to date, individuals and organizations can protect themselves against this and other ransomware threats. Remember, prevention is key, and vigilance is necessary in the ever-evolving landscape of cybersecurity threats.

Analysis Report

General information

Family Name: STOP.YQAL/NNQP/SHGV/MOIA Ransomware
Signature status: No Signature

Known Samples

MD5: dc77fcfd36f9a6c3818abe0fbb6837ca
SHA1: 86bfef990e73998a1b8582765cc12bebd4ef5ff4
SHA256: E7E6CB85DDE0EE0EF3F7914387B254A06F1599B34BC163E06B114A4B0DCCA81B
File Size: 953.80 KB, 953799 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • big overlay
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 601
Potentially Malicious Blocks: 22
Whitelisted Blocks: 572
Unknown Blocks: 7

Visual Map

x 0 0 x x 0 0 0 x x x x x 0 x 0 x ? ? 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 x x 0 0 0 x x x 0 0 x x 0 ? x 0 x ? ? x ? x x ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 1 0 0 1 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 1 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Kovter.H
  • Kryptik.VCHDB
  • Kryptik.ZDG
  • Kryptik.ZDI
  • Reconyc.N
Show More
  • Tinba.A

Files Modified

File Attributes
c:\program files\common files\system\symsrv.dll Generic Write,Read Attributes
c:\program files\common files\system\symsrv.dll.000 Generic Write,Read Attributes
c:\users\user\appdata\local\c0462e1d-c8a6-45a6-8fb4-3f1f5e0fda18\86bfef990e73998a1b8582765cc12bebd4ef5ff4_0000953799 Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\a1d26e2\ad0bca8162c.tmp Generic Write,Read Attributes
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\8b2b9a00839eed1dfdccc3bfc2f5df12 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\content\b46811c17859ffb409cf0e904a4aa8f8 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\8b2b9a00839eed1dfdccc3bfc2f5df12 Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\locallow\microsoft\cryptneturlcache\metadata\b46811c17859ffb409cf0e904a4aa8f8 Generic Read,Write Data,Write Attributes,Write extended,Append data

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
Show More
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::proxybypass  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::intranetname  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::uncasintranet  RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\zonemap::autodetect RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::syshelper "C:\Users\Ieshpthf\AppData\Local\c0462e1d-c8a6-45a6-8fb4-3f1f5e0fda18\86bfef990e73998a1b8582765cc12bebd4ef5ff4_0000953799" --Aut RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection

Trending

Most Viewed

Loading...