Free tool
Ransomware identification tool
Enter the encrypted file extension, the ransom note filename, or part of an email address or TOX ID from the note. We match it against our family profiles and tell you which families fit and how recoverable they usually are.
Waiting for input
Any single marker is enough to start. Matching is case-insensitive, supports partial matches, and the leading dot is optional.
How to use it
Extension: take the trailing extension of an encrypted file. For
report.xlsx.locked, enter.lockedorlocked.Ransom note filename: the new instruction file dropped on the desktop or in each folder, e.g.
Restore-My-Files.txtorHOW TO RECOVER.hta.Contact fragment: a few characters of the email domain, TOX ID or onion address from the note are enough.
Families using patterns like
.[8 random characters]cannot be confirmed from the extension alone. Combine it with the ransom note filename.
Things to keep in mind
The result is an initial match against public markers. It is not a substitute for sample analysis, and an engineer has to confirm the final conclusion.
One extension can be reused by several families or variants. When multiple results come back, use the ransom note content to narrow it down.
Identifying the family does not mean the data can be decrypted. Recoverability depends on the version, key status, backups and snapshots.
Do not contact the attackers or pay the ransom. We do not pay ransoms and we do not negotiate on your behalf.
Privacy
This tool runs entirely in your browser against the family profiles embedded in this page. What you type is never uploaded to a server, logged or used for anything else.