
This includes assessing the ransom note name, file name patterns of the encrypted file, and in some cases, even byte patterns in the encrypted file itself.

This web service aims to help answer those questions, and guide a victim to the correct information relating to their infection.īy simply uploading a ransom note, and/or an encrypted file (preferably both for best results), the site will use several techniques to help identify what ransomware may have encrypted the files.

ID Ransomware is a website I have created where a victim can identify what ransomware encrypted their files.Īll too often after a ransomware attack, the first question is, "what encrypted my files?", followed by "can I decrypt my data?".
