Ransomware Identifier

Have your files been encrypted? From the extension or the ransom note, find the likely family and learn what to do

First of all: what to do now

  1. Isolate the device immediately: disconnect it from the network and the Internet, and unplug external drives and USB sticks.
  2. Do not pay the ransom: paying does not guarantee recovery and funds the criminals.
  3. Do not delete or rename the encrypted files, and keep the ransom note: they are needed to identify the ransomware and for a police report.
  4. Copy the encrypted files to a separate drive: some decryptors appear months later.
  5. Report the incident to the police.
Look at an encrypted file: paste the part added at the end (just the extension or the full name). You can also type the ransomware name, if you know it.
The text or HTML file that appeared in your folders with the payment instructions.
Database of 699 ransomware families, updated automatically. Last update: 11/09/2026. Source: the community Ransomware Overview and No More Ransom.

Privacy

🔒 Do not upload your files here: they are not needed and must not be sent to anyone. The comparison with extensions and ransom notes happens entirely in your browser; nothing is sent to a server.

Have your files been encrypted and you need help?

I offer ransomware incident response: identification, containment, recovery attempts and hardening.
Open a ticket

Browse the database

699 families shown
FamilyExtensionsRansom notes

What ransomware is

Ransomware is malicious software that encrypts the files on a device and demands a ransom for the decryption key. It usually adds a distinctive extension to the files (e.g. .locked, .crypt) and drops a ransom note in every folder, a text or HTML file with payment instructions.

The extension and the ransom note are exactly the clues that let you trace the family, and from there find out whether the files can be recovered.

Why identify the family

Recognising the family tells you whether the case is recoverable:

  • some families have a free decryptor (often on No More Ransom);
  • others had flaws in their encryption that allowed recovery;
  • for the most recent ones there is often no solution, but knowing which it is helps assess the risk and document the incident.

How reliable this identification is

It is recognition by clues, not a certainty. Many families share the same extension (for example .locked or .crypto), and some generate it randomly. That is why, when the clues match several families, the tool shows them all.

The definitive confirmation comes from No More Ransom’s Crypto Sheriff, which analyses a sample of the files, or from specialist analysis.

How ransomware gets in

The most common routes are attachments and links in phishing emails, exposed remote desktop (RDP) with weak passwords, and outdated software with known vulnerabilities.

The best defence is prevention: regular offline backups, updates, multi-factor authentication and care with emails. See also the CyberThreat section on active ransomware groups.

Frequently asked questions

Look at the extension added to the encrypted files and the name of the ransom note file, and enter them above: the tool compares these clues with over 300 known families and shows the candidates.

It depends on the family. Some have a free decryptor (on No More Ransom), others do not. Identifying the family is the first step. Do not delete the encrypted files: a decryptor may appear later.

It is strongly discouraged: paying does not guarantee you get the files back, funds the criminals and exposes you to further attacks. Isolate the device, keep the evidence and report the incident.

No. This tool neither asks for nor uploads your files: the extension and the ransom note name are enough, and the comparison happens in your browser. To check a decryptor against a real sample use No More Ransom’s Crypto Sheriff.

Yes, often. Extensions like .locked or .crypto are used by many families, and some generate random ones. That is why the tool shows all candidates when the clues are not enough to tell them apart.

Related tools