October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
.locked files

TellYouThePass Ransomware: What `.locked` Files and Numbered `READ_ME*.html` Notes Mean

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Files ending in .locked alongside notes such as README1.html, READ_ME4.html or READ_ME10.html are consistent with TellYouThePass ransomware, but the extension alone does not prove it. Isolate the affected systems, preserve the note and logs, and identify the strain with a reputable service before attempting recovery or paying anyone.

This guide covers the 2024 TellYouThePass reports, safe identification, containment, rebuilding and recovery. A dedicated BleepingComputer support topic was opened on June 8, 2024: TellYouThePass Ransomware support topic.

At a glance

  • Suggestive indicators: a .locked suffix, numbered README*.html or READ_ME*.html notes, a long alphanumeric victim ID, Bitcoin instructions and an attacker email address.
  • Not proof: many unrelated ransomware families also use .locked. Do not run a decryptor selected only by that suffix.
  • First actions: disconnect networks and shares, preserve evidence, then verify the family with ID Ransomware, No More Ransom or a qualified responder.

How to recognize TellYouThePass

Reports associated with TellYouThePass include encrypted websites, databases, archives, images and documents. Notes may be named README.html, README1.html, READ_ME4.html, READ_ME9.html or READ_ME10.html; naming differs between samples. A long personal identifier is commonly embedded in the note. These clues are documented in the 2024 support discussion and an older README.html support topic.

Timeline and server clues

Security reporting linked a June 2024 campaign to exploitation of CVE-2024-4577, a CVSS 9.8 PHP CGI argument-injection flaw capable of unauthenticated code execution on affected deployments. This is especially relevant when an exposed PHP or web server was encrypted around June 8–9, 2024. Earlier TellYouThePass reporting also discussed Apache ActiveMQ and other possible entry points. A timeline is a clue, not proof of exploitation in an individual case.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Sale
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
  • World’s First 6TB 2.5” Portable Hard Drive
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption

Why .locked is not a diagnosis

The suffix is shared by multiple ransomware families. A different ransom note, multiple extensions, or no note at all may indicate another strain, a deleted note or more than one incident. Treat the result from an identification service as evidence rather than an absolute verdict.

Evidence to collect

  1. Save the complete ransom note and its text without opening links or contacting the criminals.
  2. Copy one or two benign encrypted files; retain their original names and extensions if known.
  3. Record the exact suffix and capitalization, victim ID, first encryption time and last known clean backup.
  4. Note the operating system, web/PHP software, hosting arrangement and any recent alerts.
  5. Preserve firewall, web-server, PHP, Windows, antivirus, EDR, VPN, RDP and authentication logs.

What to do immediately

Contain the spread

  • Disconnect affected computers and servers from wired and wireless networks.
  • Disconnect mapped drives, NAS devices, network shares and removable backup media.
  • Follow your incident-response plan if several systems are involved.
  • Do not reconnect a restored machine until it has been assessed and cleaned.
  • Avoid shutting down a live system when memory or forensic evidence matters, unless continued operation is causing damage or a qualified responder directs it.

Preserve ransom notes, encrypted files and logs. The CISA/FBI guidance identifies notes, wallet information, decryptors, benign samples, timing and the initial attack vector as useful evidence.

Rank #2
Sale
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
  • Slim durable design to help take your important files with you
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Protect credentials

From a known-clean device, prepare to reset exposed administrator, VPN, RDP, hosting-panel and service credentials. Do not reset accounts in a way that destroys needed evidence; coordinate with responders where possible.

Identify the variant safely

  1. Submit the ransom note or a small, non-sensitive encrypted sample to ID Ransomware.
  2. Check the identified family at No More Ransom for a current decryptor.
  3. Use an incident-response or malware-analysis provider for business-critical, confidential or multi-server cases.

Never upload confidential documents to an unknown “unlocker” site. If a service identifies a different family, do not force a TellYouThePass tool onto the files.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Can TellYouThePass files be decrypted?

A BleepingComputer responder wrote that recovery for the discussed samples required a session RSA-1024 private key held by the attackers and that no alternative solution was then available (forum page 2). A 2024 PCRisk overview likewise reported no free public decryptor for its samples.

Those are dated findings, not a permanent impossibility claim. Keys may later be recovered, infrastructure may be seized or implementation weaknesses may be discovered. Check No More Ransom and ID Ransomware immediately before recovery work. Do not assume payment supplies a working key: the FBI and Microsoft both state that payment does not guarantee restoration or removal of attacker access.

Rank #4
Sale
McAfee Total Protection 2027 Antivirus Software for 5 Devices | Auto-Renews
  • THREAT DETECTION – Stay one step ahead. Suspicious links, risky sites, viruses, and scams, caught automatically before they reach you.
  • PERSONAL INFO PROTECTION – Keep your personal info safer. Identity monitoring watches for your exposed info and tells you what to do about it.
  • SECURE CONNECTIONS – Just a few easy clicks, and we'll automatically protect your info on public Wi‑Fi, every time you connect.
  • GUIDED ACTION – Know what matters and what to do next. Clear alerts and simple guidance make it easy to take action.
  • MORE THAN ANTIVIRUS – Scam protection, identity monitoring, VPN, web protection, and antivirus work together to protect you, all in one place.

Removal, eradication and rebuilding

  1. Isolate systems and preserve evidence.
  2. Identify the family and likely entry point.
  3. Patch or disable exposed PHP CGI and other vulnerable internet-facing services; investigate ActiveMQ, RDP, VPN and stolen credentials where relevant.
  4. Reset compromised credentials from a clean device and remove unauthorized accounts, web shells and persistence.
  5. Rebuild a server from trusted media when compromise cannot be confidently eradicated.
  6. Restore only after the root cause is fixed, then monitor for reinfection.
  7. Reconnect production systems in stages.

Antivirus removal and file decryption are separate problems. A consumer scan is not a complete response to a compromised web host.

Recovery options, from safest to riskiest

Option How to use it safely Main limitation
Known-good backup Use offline, immutable or versioned copies that predate encryption. Online backups may have been encrypted or deleted.
Snapshots or previous versions Verify their date and that attackers could not alter them. Accessible snapshots may be compromised.
Cloud or SaaS restore Check retention and immutability; treat synchronization as separate from backup. Sync can propagate encrypted files.
Original copies Re-download trusted installers, media, public documents or source data. Unique data may not exist elsewhere.
Forensic recovery Ask a specialist whether deleted originals or shadow copies may remain. Expensive and uncertain.
Verified decryptor Use only a tool matched to the exact family and test on copies. An incorrect tool can damage recoverable files.
Negotiation or payment Consider only after legal, insurance, sanctions and data-theft review. No guaranteed key, complete recovery or removal.

What not to do

  • Do not pay immediately or email criminals from a company account before consulting responders and counsel.
  • Do not rename every .locked file or run multiple unverified decryptors on originals.
  • Do not delete notes, logs or encrypted files.
  • Do not restore onto an infected or still-vulnerable server.
  • Do not reconnect shares before confirming that the threat and stolen credentials are contained.
  • Do not trust recovery services that demand unexplained upfront payment or cannot explain evidence handling.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Reporting and legal issues

U.S. victims can report through the FBI Internet Crime Complaint Center. The FBI asks for the known variant, extension, wallet address, attacker email or URL, demand, payment status and timestamps. Businesses should involve legal counsel, cyber-insurance representatives, privacy officers and applicable regulators. Reporting, breach-notification duties, insurance conditions and sanctions screening vary by jurisdiction.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
WD 1TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0010BBK-WESN
  • Slim durable design to help take your important files with you
  • Vast capacities up to 6TB[1] to store your photos, videos, music, important documents and more
  • Back up smarter with included device management software[2] with defense against ransomware
  • Help secure your important files with password protection and hardware encryption
  • 3-year limited warranty

Preventing a repeat incident

  • Maintain offline, immutable and regularly tested backups.
  • Patch PHP, web servers, ActiveMQ and other exposed software quickly; restrict internet exposure.
  • Use MFA, least privilege, segmented networks and controlled RDP/VPN access.
  • Monitor web roots, administrator accounts, authentication logs and unusual encryption activity.
  • Test restoration and document who can isolate systems during an incident.

The Bottom Line

If .locked files appear with numbered READ_ME*.html notes, TellYouThePass is a credible possibility—not a certainty. Isolate first, preserve evidence, verify the family, fix the entry point and restore from protected backups. Treat any decryptor or payment promise as unverified until independently confirmed.

Quick Recap

SaleBestseller No. 1
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
WD 6TB My Passport, Portable External Hard Drive, Black, Backup Software with Defense Against ransomware, and Password Protection, USB 3.1/USB 3.0 Compatible - WDBR9S0060BBK-WESN
World’s First 6TB 2.5” Portable Hard Drive; Slim durable design to help take your important files with you
$258.90
SaleBestseller No. 2
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
WD 5TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBPKJ0050BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$213.00
SaleBestseller No. 3
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
WD 2TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0020BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$131.00
SaleBestseller No. 5
WD 1TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0010BBK-WESN
WD 1TB My Passport, Portable External Hard Drive, Black, backup software with defense against ransomware, and password protection, USB 3.1/USB 3.0 compatible - WDBYVG0010BBK-WESN
Slim durable design to help take your important files with you; Help secure your important files with password protection and hardware encryption
$132.95

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.