FenixLocker will encrypt a victim's files with AES, and append ".email@example.com!!" to the filename; e.g. "picture.jpg" will become "firstname.lastname@example.org!!". The ransom note left behind is "Cryptolocker.txt" or "Help to decrypt.txt", with the following simple contents.
All of your files are encrypted, to decrypt them write me to email : email@example.com Your key: [redacted]
The name comes from an interesting string Fabian discovered that is encrypted and added to the files.
Fabian has, out of the kindness of his own heart, released a decrypter for this ransomware.
Victims must simply drag one encrypted file of any filetype onto the decrypter, and it will find the password needed to decrypt all other files.