Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Legal

Legal Notice

Notices on the nature of this website's content, intellectual property and trademarks, external links, the sourcing of our ransomware database, and prohibited uses.

Content is for reference only

This website (noransom.net) is operated by Zhengzhou SheMo Information Technology Co., Ltd. The ransomware family profiles, scenario guidance, blog articles and FAQ answers published here are general technical reference information. They are not an incident response plan for any particular environment, nor legal advice, nor a commercial commitment.

Threats evolve quickly: variants, encryption behaviour and the availability of public decryptors can all change at any time. We make reasonable efforts to keep content accurate and to state update dates, but we make no warranty as to its completeness, currency or fitness for your purpose.

Do not perform response actions on a production environment on the basis of this website alone. Real incidents require professional judgement about the specific environment; the wrong order of operations — rebooting, reinstalling, or running repair tools first — can irreversibly reduce recoverability. Anyone acting on this content does so at their own risk.

The case studies published here are illustrative examples compiled from typical scenarios and anonymized. They illustrate our approach and are not a promise of outcome for any specific environment.

Intellectual property

Except for third-party content whose source is expressly identified, the intellectual property in the text, diagrams, page design, structure and source code of this website belongs to Zhengzhou SheMo Information Technology Co., Ltd. and is protected under Chinese and applicable international copyright law.

Permitted use. You may browse and quote this content for personal study, internal technical reference or other non-commercial purposes. Please attribute the source as "SheMo Noransom (noransom.net)" and keep quoted material intact and unaltered in meaning.

Requires prior written permission. Substantial reproduction, mirroring, redistribution, commercial publication, use in training or consulting products, and use in training commercial models.

Not permitted. Removing or altering copyright and source notices, rewriting and publishing content in a way that suggests it originates from us, and using this content for misleading promotion or to impersonate us.

We reserve the right to pursue infringement under law. If you believe content on this site infringes someone's rights, please tell us through the Contact page with proof of right and the specific location, and we will verify and act promptly.

Trademarks and names

"舍末无勒", "SheMo Noransom" and the related marks used on this site are brand identifiers used by Zhengzhou SheMo Information Technology Co., Ltd. They may not be used on goods, services, promotional material or domain names without permission, or in any manner likely to cause confusion.

Third-party names and marks referenced on this site — including but not limited to Microsoft, Windows, SQL Server, Oracle, MySQL, VMware, ESXi, Hyper-V, Synology, QNAP, Kingdee and Yonyou — are the trademarks or registered trademarks of their respective owners. They are referenced descriptively, to identify the affected technical environments and product versions, and do not imply any affiliation, endorsement, agency, partnership or certification between us and those owners.

Likewise, our use of ransomware family names such as LockBit, Phobos and Mallox follows common threat-intelligence naming practice and serves technical identification and explanation only.

External links

So that readers can verify information independently, our blog articles and family profiles cite external links to government agencies, security vendors, research teams and open intelligence platforms.

That linked content is published and maintained independently by those third parties. We are not responsible for its accuracy, currency, availability or safety, and a link does not imply endorsement of any view, product or service. Third-party pages may change, move or disappear at any time, and their privacy policies and terms have nothing to do with this site — please assess and comply with them yourself.

A specific note on third-party decryptors

We may reference decryption tools published by law enforcement agencies or security vendors. Please note:

  • obtain such tools only from official channels — a great many malicious programs circulate disguised as decryptors;
  • make a read-only backup of the target data before use, as some tools cause further damage when the variant does not match;
  • applicability is constrained by the exact variant, and effectiveness has to be verified in practice;
  • we make no warranty as to the effectiveness or safety of third-party tools, and use is at the user's own risk.

Ransomware database: sources and disclaimer

Our ransomware database — family profiles, appended extensions, ransom note characteristics, decryptor status — is compiled from the following kinds of sources:

  • public advisories from government and law enforcement agencies, including alerts and joint advisories from national cybersecurity authorities;
  • analysis reports and technical blogs published by security vendors and research organizations;
  • public malware intelligence platforms and family naming projects;
  • de-identified sample characteristics and field observations accumulated in our own response work.

Disclaimer

  • Ransomware families come with many variants and imitators: different crews may use the same extension, and encryption behaviour varies widely between versions of one family, so identifying a family from an extension or note filename alone is not reliable.
  • Decryptor status (available, partially available, none) changes as keys leak, law enforcement acts and new builds appear; information here may lag the current situation.
  • Family profiles help in understanding a threat and orienting an initial assessment; they cannot replace actual analysis of the specific sample.
  • We make reasonable efforts to cite sources and state update dates, but we do not warrant that entries are fully accurate or cover every variant.

If you find an error, outdated information or a missing significant variant, please tell us through the Contact page and we will verify and update.

Prohibited uses

Content on this website is intended solely for defensive, incident response and security research purposes. The following uses are expressly prohibited:

  • using the family characteristics, propagation methods, exploitation details or attack techniques described here to carry out or assist attacks, extortion, data theft or other unlawful activity;
  • scanning, penetrating, intruding into or extracting data from systems you are not authorized to access;
  • developing, distributing or selling ransomware or its variants, or providing technical support or infrastructure for such activity;
  • impersonating SheMo Noransom, or fabricating our reports, credentials or case studies, for solicitation, fraud or misleading promotion;
  • large-scale automated scraping of this website, or access patterns that interfere with its normal operation;
  • any other use that violates the laws of the PRC or harms the lawful rights of others.

The Cybersecurity Law and the Criminal Law of the PRC, among other statutes, impose liability for unlawfully intruding into computer information systems, damaging such systems, and unlawfully obtaining their data. Please use the information on this site within the limits of the law.

This notice was last updated on 12 September 2026. We may revise it from time to time, with revisions published on this page. In the event of a discrepancy in understanding between the Chinese and English versions, the Chinese version prevails.

Updated