The ransomware identification tool didn’t load. This is usually temporary — please refresh. If you’re dealing with an active incident, don’t wait on it:
Emergency response: +1 (877) 364-5161
Most ransomware appends a new extension to every file it encrypts, so report.xlsx becomes report.xlsx.eking or similar. The appended string is often the fastest way to name the strain. Check several encrypted files before deciding: some families add a victim ID or the attacker's email to the extension, so the constant part is what identifies the strain, not the whole string. A few strains change the extension per campaign, and some share extensions with unrelated families — an extension narrows the answer, it rarely settles it alone. Paste the extension above, with or without the leading dot.
The note's filename is often more identifying than its contents, because attackers reuse note templates across families but keep filenames consistent within one. Look for files like readme.txt, how_to_decrypt.html or info.hta in any folder containing encrypted files, and on the desktop. Record the exact filename, including capitalisation. Paste the filename or the note's text above. Do not open links inside the note or contact the address it gives before you have identified the strain and know whether a decryptor exists — some families delete keys after a timer, and contact can start it.
Ransom notes usually give one or more addresses for negotiation, written as recovery[@]example.com here so it can't be clicked by accident. Addresses are often reused across campaigns by the same group, which makes them a strong identifier even when the extension is generic. They also change frequently, so an address that matches tells you a lot and an address that doesn't match tells you little. Paste the address above exactly as it appears in the note.
If you have no note and no usable extension, the encrypted file itself carries identifying structure: many families write a fixed marker or footer into every file they encrypt, and some embed the victim ID or the attacker's contact details directly in the file. Upload one encrypted file above and it will be checked against known family signatures. If you have recovered the executable itself — from a quarantine folder, a scheduled task, or your EDR — that can also be analysed for family-specific signatures, and a hash alone is often enough. Never run a recovered sample to see what it does.
Isolate affected machines from the network and from backups before anything else — encryption often continues while you investigate. Do not delete the encrypted files or the ransom note; both are needed for recovery and for any insurance or law-enforcement report. Once you have the strain name, its page here shows whether a free decryptor exists, which assets the family typically targets, and whether it exfiltrates data before encrypting — which determines whether this is also a breach-notification matter. If a free decryptor exists, it is published by a trusted vendor and linked from the strain's page. If none exists, paying is not a recovery plan: call +1 (877) 364-5161.