Skip to main content

Hit by ransomware? Isolate affected systems now. Do not reboot or reformat.

SheMo Noransom舍末无勒

Free tool

Ransomware identification tool

Enter the encrypted file extension, the ransom note filename, or part of an email address or TOX ID from the note. We match it against our family profiles and tell you which families fit and how recoverable they usually are.

Try:

Waiting for input

Any single marker is enough to start. Matching is case-insensitive, supports partial matches, and the leading dot is optional.

How to use it

  1. Extension: take the trailing extension of an encrypted file. For report.xlsx.locked, enter .locked or locked.

  2. Ransom note filename: the new instruction file dropped on the desktop or in each folder, e.g. Restore-My-Files.txt or HOW TO RECOVER.hta.

  3. Contact fragment: a few characters of the email domain, TOX ID or onion address from the note are enough.

  4. Families using patterns like .[8 random characters] cannot be confirmed from the extension alone. Combine it with the ransom note filename.

Things to keep in mind

  1. The result is an initial match against public markers. It is not a substitute for sample analysis, and an engineer has to confirm the final conclusion.

  2. One extension can be reused by several families or variants. When multiple results come back, use the ransom note content to narrow it down.

  3. Identifying the family does not mean the data can be decrypted. Recoverability depends on the version, key status, backups and snapshots.

  4. Do not contact the attackers or pay the ransom. We do not pay ransoms and we do not negotiate on your behalf.

Privacy

This tool runs entirely in your browser against the family profiles embedded in this page. What you type is never uploaded to a server, logged or used for anything else.