Ransomware identification by the note and the encrypted files
Ransomware leaves two things behind that identify it: a note demanding payment, and an extension appended to every file it touched. This tool matches both against families documented by Zscaler ThreatLabz, Europol's No More Ransom project and Emsisoft, and then answers the question that actually matters — whether a free decryptor for that family has been released. Where it has, the link goes to the authoritative source and nowhere else.
The ransom note, one encrypted file, or both. If the note names the family, typing that name is enough on its own.
Each candidate says which signal found it. A signal several families share is shown as several candidates, not as one answer.
If a free one exists, the link goes to No More Ransom or Emsisoft — and nowhere else.