.BLOWER

BLOWER File

Blower Ransomware Encrypted File
Ask a question
QUICK ANSWER

A .blower file is an ordinary document, photo or other file that has been encrypted by the Blower ransomware, an early 2019 variant of the STOP/Djvu family. You cannot open it normally: the contents are scrambled with the Salsa20 cipher and the .blower extension is added to the original name. The only real ways to recover the data are the free Emsisoft STOP Djvu Decryptor (which works when your files were locked with a recoverable offline key), a clean backup, or file-recovery tools such as ShadowExplorer. Removing the malware with an antivirus does not decrypt anything.

Developer: STOP/Djvu ransomware operators (unknown criminal group) Category: Encoded Files MIME: application/octet-stream
OPENS ON Windows
Related: .CRYPT · .SDOC · .AXX · .REM

On this page

19k+ extensions indexed
Last reviewed Jul 18, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the BLOWER file format?

A .blower file is a normal file, such as a document, photo or video, that has been encrypted by the Blower ransomware. Blower appeared in early February 2019 and belongs to the STOP/Djvu ransomware family. When it infects a computer, it scrambles files with the Salsa20 cipher and adds .blower to each name, so report.docx becomes report.docx.blower. Like other STOP/Djvu variants, it encrypts only the first 150 KB of each file, which leaves the tail of large files readable but still unusable.

Alongside the locked files, Blower drops a ransom note named _readme.txt. The note asks for $490 within the first 72 hours, rising to $980, and lists the contact addresses [email protected] and [email protected]. During encryption the malware often shows a fake Windows Update window and edits the Windows hosts file to block security websites. It usually spreads through cracked software, key generators, fake updaters and malicious email attachments.

Security & safety

RISK: HIGH

A .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.

Format details

in a nutshell
FULL NAMEBlower Ransomware Encrypted Fileaka Blower virus file, STOP/Djvu .blower variant
DEVELOPERSTOP/Djvu ransomware operators (unknown criminal group)since 2019 (early February)
MIME TYPEapplication/octet-stream
TYPERansomware-encrypted binary (Salsa20-encrypted original file)

Programs that open BLOWER files

Windows5 apps
Emsisoft STOP Djvu Decryptor Free Run the decryptor to check whether your .blower files were locked with a recoverable offline key, then decrypt them back to their original form in place.
Malwarebytes Freemium Scan and remove the active Blower ransomware and related malware before attempting any recovery, so files are not re-encrypted.
ShadowExplorer Free Browse and restore earlier versions of files from Windows Volume Shadow Copies if the ransomware did not delete them.
Recuva Freemium Attempt to recover deleted original files, since STOP/Djvu often encrypts a copy and removes the source.
Windows System Restore Built-in Roll the system back to a restore point created before the infection, which may return some encrypted files to a clean state.

Technical details

deep spec
EncodingSalsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable.
Byte orderN/A (original file bytes, partially enciphered)
ContainerOriginal file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower)
CompressionNone added by the ransomware; original compression of the source file is preserved in the unencrypted tail
EncryptionSalsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail.
Typical sizeSame as the original file plus a small appended block containing the encryption marker and key/ID
StructureOriginal file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end.
IntegrityNone; no integrity field is added.
PlatformsWindows
NotesDistributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders.
Released2019 (early February)
Specificationwww.emsisoft.com

BLOWER conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with BLOWER files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about BLOWER files.

Frequently asked questions

How do I open a .blower file?
You cannot open it directly because the contents are encrypted. Run the free Emsisoft STOP Djvu Decryptor to check for a recoverable offline key, or restore the original file from a backup. Renaming the file does not remove the encryption.
Can .blower files be decrypted for free?
Sometimes. Blower is an early STOP/Djvu variant, so files locked with an offline key can be recovered with the Emsisoft STOP Djvu Decryptor. Files locked with a unique online key cannot be decrypted without the attackers' private key.
Should I pay the ransom?
No. Paying funds the criminals and offers no guarantee of a working key. Security agencies and researchers advise against it. Try the Emsisoft decryptor, backups, and shadow copies first, and report the attack to local law enforcement.
What is the _readme.txt file that appeared?
That is the Blower ransom note. It demands $490 within 72 hours or $980 afterward and lists the contact emails [email protected] and [email protected]. It is dropped into folders that contain encrypted files.
Is the .blower file itself dangerous?
The encrypted file cannot run on its own, but it signals that ransomware executed on your computer. The actual malware may still be active, so scan and clean the system with an antivirus before recovering data.
How did my files get the .blower extension?
The Blower ransomware usually arrives through cracked software, key generators, fake updaters or malicious email attachments. Once it runs, it encrypts your files with Salsa20 and appends .blower to each name.

References

1PCrisk - .blower Ransomware removal and recoverywww.pcrisk.com
2Emsisoft - STOP Djvu Decryptor (free)www.emsisoft.com

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.BINCD/DVD Disc Image (BIN/CUE)
3.PARTPartial Download File
4.MDMarkdown Document
5.RPMSGRestricted Permission Message
6.CRDOWNLOADChrome Partial Download File
7.NOMEDIAAndroid No-Media Marker File
8.PRDXSoftMaker Presentations Document
9.PRO6XProPresenter 6 Bundle File
10.SWFSmall Web Format (Shockwave Flash)

Related extensions

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z