ID Ransomware
Upload a ransom note and/or sample encrypted file to identify the ransomware that has encrypted your data.
Knowing is half the battle!
1 Result
Phobos
This ransomware is decryptable!
Identified by
- ransomnote_bitcoin: 3veufeee18SdimDI1RxnL0U4gbAzxhDdPGCfpZs
- sample_extension: .id[<ID>].[<email>].Elbie
- sample_bytes: 0x00 metadata divider
- custom_rule: Padding and metadata offset verified