Ransomware Identifier
Have your files been encrypted? From the extension or the ransom note, find the likely family and learn what to do
First of all: what to do now
- Isolate the device immediately: disconnect it from the network and the Internet, and unplug external drives and USB sticks.
- Do not pay the ransom: paying does not guarantee recovery and funds the criminals.
- Do not delete or rename the encrypted files, and keep the ransom note: they are needed to identify the ransomware and for a police report.
- Copy the encrypted files to a separate drive: some decryptors appear months later.
- Report the incident to the police.
Privacy
🔒 Do not upload your files here: they are not needed and must not be sent to anyone. The comparison with extensions and ransom notes happens entirely in your browser; nothing is sent to a server.
Have your files been encrypted and you need help?
Browse the database
| Family | Extensions | Ransom notes |
|---|
What ransomware is
Ransomware is malicious software that encrypts the files on a device and demands a ransom for the decryption key. It usually adds a distinctive extension to the files (e.g. .locked, .crypt) and drops a ransom note in every folder, a text or HTML file with payment instructions.
The extension and the ransom note are exactly the clues that let you trace the family, and from there find out whether the files can be recovered.
Why identify the family
Recognising the family tells you whether the case is recoverable:
- some families have a free decryptor (often on No More Ransom);
- others had flaws in their encryption that allowed recovery;
- for the most recent ones there is often no solution, but knowing which it is helps assess the risk and document the incident.
How reliable this identification is
It is recognition by clues, not a certainty. Many families share the same extension (for example .locked or .crypto), and some generate it randomly. That is why, when the clues match several families, the tool shows them all.
The definitive confirmation comes from No More Ransom’s Crypto Sheriff, which analyses a sample of the files, or from specialist analysis.
How ransomware gets in
The most common routes are attachments and links in phishing emails, exposed remote desktop (RDP) with weak passwords, and outdated software with known vulnerabilities.
The best defence is prevention: regular offline backups, updates, multi-factor authentication and care with emails. See also the CyberThreat section on active ransomware groups.