ID Ransomware

Upload a ransom note and/or sample encrypted file to identify the ransomware that has encrypted your data.

Knowing is half the battle!
GI Joe

2 Results


This ransomware may be decryptable under certain circumstances.

Please refer to the appropriate guide for more information.

Identified by

  • sample_extension: .<id>
  • sample_bytes: [0x00 - 0x24] 0xDAC4C4C4C4C4C4C4C4BF0D0AB35A455050454C494EB30D0AC0C4C4C4C4C4C4C4C4D90D0A

Click here for more information about Zeppelin

Vega / Jamper / Buran

This ransomware has no known way of decrypting data at this time.

It is recommended to backup your encrypted files, and hope for a solution in the future.

Identified by

  • ransomnote_filename: !!! ALL YOUR FILES ARE ENCRYPTED !!!.TXT

Click here for more information about Vega / Jamper / Buran

Would you like to be notified if there is any development regarding this ransomware? Click here.

Ransomware Got Past Your Antivirus?

Emsisoft Anti-Malware * This is an affiliate link, and I receive commission for purchases made. I do honestly recommend Emsisoft and their products even without this affiliation.