¿Qué es el formato de archivo ODIN?
Un archivo .odin es un archivo personal que ha sido cifrado por el ransomware Locky. Locky es una familia de malware para Windows que apareció por primera vez a principios de 2016 y bloquea documentos, fotos, bases de datos y archivos comprimidos, para luego exigir un pago por su devolución. Alrededor de septiembre de 2016, los operadores cambiaron la extensión que añadían de .zepto a .odin, nombrando a la variante en honor al dios nórdico. Investigadores de Fortinet descubrieron que el código de .odin era idéntico en un 98-99 % a la versión anterior de .zepto, por lo que se trata del mismo malware con una nueva etiqueta.
Cuando Locky se ejecuta, busca aproximadamente 400 tipos de archivos, cifra cada uno con AES-128 y bloquea la clave AES dentro de un cifrado RSA-2048. Luego renombra cada archivo con un identificador hexadecimal como 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin, descartando el nombre original. También elimina las copias de sombra de volumen de Windows (Shadow Volume Copies) y deja notas de rescate llamadas _HOWDO_text.html y _HOWDO_text.bmp. Encontrar archivos .odin significa que la computadora fue infectada, no que usted posea un formato inusual.
Seguridad y protección
RIESGO: HIGHThe presence of .odin files means the computer was hit by active ransomware. The .odin files themselves are inert encrypted data and cannot execute, but they signal that Locky ran on the system, deleted shadow copies and may still be present. Never pay the ransom without expert advice, and treat the machine as compromised until it is fully cleaned and, ideally, wiped and rebuilt from a trusted backup.
Detalles del formato
en pocas palabras- Samsung Odin firmware package - The Odin flashing tool for Samsung Galaxy devices uses firmware files, but those are typically .tar or .tar.md5 archives rather than a .odin extension. Unrelated to the ransomware.
- ODIN application data - A handful of niche applications have used .odin for internal data or backup files. These are legitimate and unrelated to Locky.
Programas que abren archivos ODIN
.odin files themselves cannot be opened. .odin sample to confirm the exact ransomware family and whether any decryption is currently possible. Detalles técnicos
especificación profunda| Encoding | AES-128 (ECB mode) file encryption with the AES key protected by RSA-2048 |
| Byte order | N/A (encrypted ciphertext) |
| Container | None; the original file is overwritten in place as raw ciphertext with a renamed filename |
| Encryption | RSA-2048 + AES-128. The AES session keys are generated server-side by the attacker's command-and-control infrastructure, so the private key needed for decryption never stays on the victim machine. |
| Typical size | Roughly the same size as the original encrypted file |
| Structure | The plaintext of a targeted document, image, database or archive is replaced by AES-128 ciphertext. The file is then renamed to a hexadecimal identifier of the form [8]-[4]-[4]-[4]-[12] followed by the .odin extension (for example 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin). The original name and extension are not preserved on disk. |
| Platforms | Windows |
| Notes | Locky's .odin variant targets roughly 400 to 460 file types across documents, databases, images and archives. It deletes Windows Shadow Volume Copies to block local recovery and drops ransom notes named _HOWDO_text.html, _HOWDO_text.bmp and _[2-digit-number]_HOWDO_text.html. It is delivered by spam email carrying WSF/JS script attachments or macro-laden Office documents that download an encrypted DLL and run it via rundll32.exe. Despite the name, victims are infected by Locky using the .odin extension, not a separate 'Odin' malware family; code comparison shows a 98-99% match with the earlier .zepto variant. |
| Lanzado | September 2016 |
Conversiones de ODIN
Preguntas y respuestas de la comunidad
preguntado por usuariosAún no hay preguntas; sea el primero en preguntar sobre los archivos ODIN.