file

[Content by Gemini 2.5]

It looks like the placeholder {{ $json.extension }} wasn’t replaced with the actual file extension you’re interested in (or you accidentally left the word “file” in place).

Please provide the exact extension that the ransomware appends to encrypted files (for example, .ryk, .npsk, .coot, .mallox, etc.).
Once I have that single piece of information, I can build the full technical breakdown and recovery guide for the correct variant.