Name |
Extensions |
Decryptor |
Info |
.CryptoHasYou. |
.enc |
|
http://www.nyxbone.com/malware/CryptoHasYou.html |
7ev3n |
.R5A .R4A |
https://github.com/hasherezade/malware_analysis/tree/master/7ev3n |
http://www.nyxbone.com/malware/7ev3n-HONE$T.html |
Alpha Ransomware |
.encrypt |
https://download.bleepingcomputer.com/demonslay335/AlphaDecrypter-fp.zip
|
http://www.bleepingcomputer.com/news/security/decrypted-alpha-ransomware-continues-the-trend-of-accepting-amazon-cards/ |
AutoLocky |
.locky |
https://decrypter.emsisoft.com/autolocky |
|
Alcatraz Locker
|
.alcatraz
|
https://www.avast.com/ransomware-decryption-tools
|
|
Apocalypse
|
.encrypted .FuckYourData .locked .Encryptedfile .SecureCrypted
|
https://www.avast.com/ransomware-decryption-tools
|
|
Bandarchor |
|
|
https://reaqta.com/2016/03/bandarchor-ransomware-still-active/ |
Bart
|
.bart.zip
|
https://www.avast.com/ransomware-decryption-tools
|
|
BitCryptor |
.clf |
https://noransom.kaspersky.com/ |
|
Booyah |
|
|
|
Brazilian |
.lock |
|
http://www.nyxbone.com/malware/brazilianRansom.html |
BrLock |
|
|
https://www.proofpoint.com/us/threat-insight/post/ransomware-explosion-continues-cryptflle2-brlock-mm-locker-discovered |
Browlock |
|
|
|
Bucbi |
|
|
http://researchcenter.paloaltonetworks.com/2016/05/unit42-bucbi-ransomware-is-back-with-a-ukrainian-makeover/ |
BuyUnlockCode |
|
|
|
Cerber |
.cerber |
|
https://blog.malwarebytes.org/threat-analysis/2016/03/cerber-ransomware-new-but-mature/ |
Chimera |
.crypt |
|
https://blog.malwarebytes.org/threat-analysis/2015/12/inside-chimera-ransomware-the-first-doxingware-in-wild/ |
Chinese Ransom |
.txt |
|
http://www.nyxbone.com/malware/chineseRansom.html |
CoinVault |
.clf |
https://noransom.kaspersky.com/ |
|
Coverton |
.coverton .enigma .czvxce |
|
http://www.bleepingcomputer.com/news/security/paying-the-coverton-ransomware-may-not-get-your-data-back/ |
Cryaki |
.{CRYPTENDBLACKDC} |
https://support.kaspersky.com/viruses/disinfection/8547 |
|
Crybola |
|
https://support.kaspersky.com/viruses/disinfection/8547 |
|
Cryptear |
|
http://www.utkusen.com/blog/dealing-with-script-kiddies-cryptear-b-incident.html |
|
CryptFIle2 |
.scl |
|
https://www.proofpoint.com/us/threat-insight/post/ransomware-explosion-continues-cryptflle2-brlock-mm-locker-discovered |
CryptInfinite |
.crinf |
https://decrypter.emsisoft.com/ |
|
CryptoDefense |
|
https://decrypter.emsisoft.com/ |
|
CryptoHost |
|
http://www.bleepingcomputer.com/news/security/cryptohost-decrypted-locks-files-in-a-password-protected-rar-file/ |
|
CryptoJoker |
.crjoker |
|
|
CryptoLocker |
.encrypted
|
https://www.fireeye.com/blog/executive-perspective/2014/08/your-locker-of-information-for-cryptolocker-decryption.html |
https://reaqta.com/2016/04/uncovering-ransomware-distribution-operation-part-2/ |
CryptoMix |
.code |
|
http://www.nyxbone.com/malware/CryptoMix.html |
CryptoTorLocker2015 |
.CryptoTorLocker2015! |
http://www.bleepingcomputer.com/forums/t/565020/new-cryptotorlocker2015-ransomware-discovered-and-easily-decrypted/ |
|
CryptoWall |
|
|
|
CryptXXX |
.crypt |
https://support.kaspersky.com/viruses/disinfection/8547 |
|
CryptXXX 2.0 |
|
|
https://www.proofpoint.com/us/threat-insight/post/cryptxxx2-ransomware-authors-strike-back-against-free-decryption-tool |
Crypt888
|
lock.
|
https://www.avast.com/ransomware-decryption-tools
|
|
CTB-Locker |
.ctbl |
|
|
CTB-Locker WEB |
|
|
https://thisissecurity.net/2016/02/26/a-lockpicking-exercise/ |
DeCrypt Protect |
.html |
http://www.malwareremovalguides.info/decrypt-files-with-decrypt_mblblock-exe-decrypt-protect/ |
|
DMALocker |
|
https://decrypter.emsisoft.com/ https://github.com/hasherezade/dma_unlocker
|
https://blog.malwarebytes.org/threat-analysis/2016/02/dma-locker-a-new-ransomware-but-no-reason-to-panic/ |
DMALocker 3.0 |
|
|
https://blog.malwarebytes.org/threat-analysis/2016/02/dma-locker-strikes-back/ |
EDA2 / HiddenTear |
.locked |
|
|
El-Polocker |
.ha3 |
|
|
Enigma |
.enigma |
|
http://www.bleepingcomputer.com/news/security/the-enigma-ransomware-targets-russian-speaking-users/ |
Fakben |
.locked |
|
https://blog.fortinet.com/post/fakben-team-ransomware-uses-open-source-hidden-tear-code |
Fury |
|
https://support.kaspersky.com/viruses/disinfection/8547 |
|
Gomasom |
.crypt |
https://decrypter.emsisoft.com/ |
|
Gopher |
|
|
|
Globe
|
.ACRYPT .GSupport[0-9] .blackblock .dll555 .duhust .exploit .frozen .globe .gsupport .kyra .purged .raid[0-9] .siri-down@india.com .xtbl .zendrz .zendr[0-9]
|
https://www.avast.com/ransomware-decryption-tools
|
|
Harasom |
.html |
https://decrypter.emsisoft.com/ |
|
Hi Buddy! |
.cry |
|
http://www.nyxbone.com/malware/hibuddy.html |
HydraCrypt |
|
https://decrypter.emsisoft.com/ |
http://www.malware-traffic-analysis.net/2016/02/03/index2.html |
iLock |
.crime |
|
|
iLockLight |
.crime |
|
|
Jigsaw |
.btc .kkk .fun .gws |
http://www.bleepingcomputer.com/news/security/jigsaw-ransomware-decrypted-will-delete-your-files-until-you-pay-the-ransom/ |
https://www.helpnetsecurity.com/2016/04/20/jigsaw-crypto-ransomware/ |
Job Crypter |
.locked |
|
http://www.nyxbone.com/malware/jobcrypter.html |
JobCrypter |
.locked |
|
http://forum.malekal.com/jobcrypter-geniesanstravaille-extension-locked-crypto-ransomware-t54381.html |
KeRanger |
.encrypted |
http://news.drweb.com/show/?i=9877&lng=en&c=5 |
http://www.welivesecurity.com/2016/03/07/new-mac-ransomware-appears-keranger-spread-via-transmission-app/ |
KeyBTC |
.keybtc@inbox_com |
https://decrypter.emsisoft.com/ |
|
KEYHolder |
|
|
http://www.bleepingcomputer.com/forums/t/559463/keyholder-ransomware-support-and-help-topic-how-decryptgifhow-decrypthtml |
KimcilWare |
.kimcilware .locked |
https://blog.fortinet.com/post/kimcilware-ransomware-how-to-decrypt-encrypted-files-and-who-is-behind-it |
http://www.bleepingcomputer.com/news/security/the-kimcilware-ransomware-targets-web-sites-running-the-magento-platform/ |
KryptoLocker |
|
|
|
LeChiffre |
.LeChiffre |
https://decrypter.emsisoft.com/lechiffre |
https://blog.malwarebytes.org/threat-analysis/2016/01/lechiffre-a-manually-run-ransomware/ |
Linux.Encoder |
|
https://labs.bitdefender.com/2015/11/linux-ransomware-debut-fails-on-predictable-encryption-key/ |
|
Locker |
|
http://www.bleepingcomputer.com/forums/t/577246/locker-ransomware-support-and-help-topic/page-32#entry3721545 |
|
Locky |
.locky |
|
|
Lortok |
.crime |
|
|
LowLevel04 |
oor. |
|
|
Mabouia |
|
|
|
Magic |
.magic |
|
|
MaktubLocker |
|
|
https://blog.malwarebytes.org/threat-analysis/2016/03/maktub-locker-beautiful-and-dangerous/ |
MireWare |
.fucked |
|
|
MM Locker |
|
|
https://www.proofpoint.com/us/threat-insight/post/ransomware-explosion-continues-cryptflle2-brlock-mm-locker-discovered |
Mobef |
.KEYZ .KEYH0LES |
|
http://nyxbone.com/malware/Mobef.html |
NanoLocker |
|
http://github.com/Cyberclues/nanolocker-decryptor |
|
Nemucod |
.crypted |
https://decrypter.emsisoft.com/ https://github.com/Antelox/NemucodFR
|
|
Offline ransomware |
.cbf |
|
http://bartblaze.blogspot.com.co/2016/02/vipasana-ransomware-new-ransom-on-block.html |
OMG! Ransomware |
.LOL! .OMG! |
|
|
Operation Global III |
.EXE |
http://news.thewindowsclub.com/operation-global-iii-ransomware-decryption-tool-released-70341/ |
|
PClock |
|
https://decrypter.emsisoft.com/ |
|
Petya |
|
http://www.thewindowsclub.com/petya-ransomware-decrypt-tool-password-generator https://www.youtube.com/watch?v=mSqxFjZq_z4
|
https://blog.malwarebytes.org/threat-analysis/2016/04/petya-ransomware/ |
PowerWare |
|
|
|
RaaS |
|
|
http://www.nyxbone.com/malware/RaaS.html |
Radamant |
.RDM .RRK .RADAMANT |
https://decrypter.emsisoft.com/ |
http://www.bleepingcomputer.com/news/security/new-radamant-ransomware-kit-adds-rdm-extension-to-encrypted-files/ http://www.cyphort.com/radamant-ransomware-distributed-via-rig-ek/ http://www.nyxbone.com/malware/radamant.html
|
Rakhni |
.locked .kraken .darkness .nochance .oshit .oplata@qq_com .relock@qq_com .crypto .helpdecrypt@ukr.net .pizda@qq_com .dyatel@qq_com _ryp .nalog@qq_com .chifrator@qq_com .gruzin@qq_com .troyancoder@qq_com .encrypted .cry .AES256 .enc .hb15 |
https://support.kaspersky.com/us/viruses/disinfection/10556 |
|
Rannoh |
|
https://support.kaspersky.com/viruses/disinfection/8547 |
|
Ransom32 |
|
|
|
Rector |
.vscrypt .infected .bloc .korrektor |
https://support.kaspersky.com/viruses/disinfection/4264 |
|
RemindMe |
.remind |
|
|
Rokku |
.rokku |
|
https://blog.malwarebytes.org/threat-analysis/2016/04/rokku-ransomware/ |
Samas-Samsam |
.encryptedAES .encryptedRSA .encedRSA .justbtcwillhelpyou .btcbtcbtc .btc-help-you .only-we_can-help_you |
|
http://blog.talosintel.com/2016/03/samsam-ransomware.html |
Sanction |
.sanction |
|
|
Scraper |
|
http://securelist.com/blog/research/69481/a-flawed-ransomware-encryptor/ |
|
SkidLocker / Pompous |
.locked |
http://www.bleepingcomputer.com/news/security/pompous-ransomware-dev-gets-defeated-by-backdoor/ |
http://www.nyxbone.com/malware/SkidLocker.html |
Sport |
.sport |
|
|
Strictor |
.locked |
|
http://www.nyxbone.com/malware/Strictor.html |
Surprise |
.surprise |
|
|
SynoLocker |
|
|
|
SZFLocker
|
.szf
|
https://www.avast.com/ransomware-decryption-tools
|
|
|
TeslaCrypt 0.x - 2.2.0 |
.vvv .ecc .exx .ezz .abc .aaa .zzz .xyz |
http://www.bleepingcomputer.com/forums/t/576600/tesladecoder-released-to-decrypt-exx-ezz-ecc-files-encrypted-by-teslacrypt/ http://www.talosintel.com/teslacrypt_tool/
|
TeslaCrypt 3.0+ |
.micro .xxx .ttt .mp3 |
|
|
TeslaCrypt 4.1A |
|
|
https://www.endgame.com/blog/your-package-has-been-successfully-encrypted-teslacrypt-41a-and-malware-attack-chain |
TeslaCrypt 4.2 |
|
https://www.avast.com/ransomware-decryption-tools
|
http://www.bleepingcomputer.com/news/security/teslacrypt-4-2-released-with-quite-a-few-modifications/ |
TorrentLocker |
.Encrypted |
http://www.bleepingcomputer.com/forums/t/547708/torrentlocker-ransomware-cracked-and-decrypter-has-been-made/ |
|
Troldesh |
.better_call_saul .xtbl |
|
http://www.nyxbone.com/malware/Troldesh.html |
TrueCrypter |
.enc |
|
http://www.bleepingcomputer.com/news/security/truecrypter-ransomware-accepts-payment-in-bitcoins-or-amazon-gift-card/ |
UmbreCrypt |
|
http://www.thewindowsclub.com/emsisoft-decrypter-hydracrypt-umbrecrypt-ransomware |
|
VaultCrypt |
.vault .xort .trun |
|
http://www.nyxbone.com/malware/russianRansom.html |
Virus-Encoder |
.CrySiS |
|
http://www.nyxbone.com/malware/virus-encoder.html |
Xorist |
.EnCiPhErEd .73i87A .p5tkjw .PoAr2w |
https://support.kaspersky.com/viruses/disinfection/2911 |
|
XRTN
|
.xrtn |
|
|
Zlader / Russian |
.vault |
|
http://www.nyxbone.com/malware/russianRansom.html |