- Home
- Detectable Ransomware
- Zelta Free
Ransomware Research
Zelta Free Ransomware
Zelta Free is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on May 1, 2017, this ransomware has been actively targeting systems worldwide.
Quick Facts
- Ransomware Family
- Zelta Free
- First Seen
- May 1, 2017
How Zelta Free Ransomware Works
Targeted Files
Destroys the content of the files
File Encryption Patterns
Zelta Free modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..locked
Ransom Note and Payment Demands
After encrypting files, Zelta Free displays ransom notes demanding payment for file recovery:
How to recover my files.txt
Ransom message:
notes/How to recover my files.txt
Note locations:
Desktop
Ransom message:
notes/note.txt
Note locations:
Login
Technical Indicators
Associated Executable Files
The following executable files are associated with Zelta Free ransomware:
Zelta - Free Ransomware.exe
B289998E696263EDF2B694E43BBE81B738196EFDCE6D7D571C389868D8BF5D66792A4EA5A72EE13C592E10FD7E2DBE6668B0825DA58D75E5A2455AC69CB29BDB
trash
1.exe
Elastio Can Help You
Don't let Zelta Free ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Zelta Free ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Zelta Free.
Last updated: July 30, 2025