.GDCB

GDCB File

GandCrab Ransomware Encrypted File
Ask a question
QUICK ANSWER

A .gdcb file is a file that was encrypted by version 1 of the GandCrab ransomware, which appends .GDCB to the original filename (for example, budget.xlsx.GDCB). It is not a normal file format; the contents are scrambled with AES-256 and cannot be read until they are decrypted. Because GandCrab v1 was cracked, you can recover these files for free using the Bitdefender GandCrab decryption tool from the No More Ransom project rather than paying the ransom.

Developer: GandCrab ransomware operators (cybercriminal group) Category: Encoded Files MIME: application/octet-stream
OPENS ON Windows
Related: .CRYPT · .SDOC · .AXX · .REM

On this page

19k+ extensions indexed
Last reviewed Jun 29, 2026

Not sure what your file is?

Drop any file into our identifier - we read just the first bytes to name the format.

Identify a file

What is the GDCB file format?

A .gdcb file is a document, photo, or other file that was encrypted by version 1 of the GandCrab ransomware. When the malware runs, it scrambles the file's contents and adds .GDCB to the end of the name, so budget.xlsx becomes budget.xlsx.GDCB. It also drops a ransom note called GDCB-DECRYPT.txt into every affected folder.

GandCrab appeared in late January 2018 and spread through the RIG exploit kit. Version 1 encrypted files with AES-256 and protected the key with an RSA-2048 public key, then demanded payment in Dash cryptocurrency through a Tor site. Only version 1 used .GDCB; later versions switched to .CRAB and .KRAB extensions.

Security & safety

RISK: HIGH

A .gdcb file itself is inert encrypted data, but its presence means a machine was compromised by GandCrab ransomware. The malware executable that created it is dangerous and may still be active, so disconnect the device, remove the infection with an anti-malware tool, and only then decrypt. Never pay the Dash ransom; a free decryptor exists for GandCrab v1.

Format details

in a nutshell
FULL NAMEGandCrab Ransomware Encrypted Fileaka GandCrab v1 encrypted file, GDCB virus file
DEVELOPERGandCrab ransomware operators (cybercriminal group)since January 2018
MIME TYPEapplication/octet-stream
TYPERansomware-encrypted binary container

Programs that open GDCB files

Windows4 apps
Bitdefender GandCrab Decryption Tool Free Run the free decryptor to reverse GandCrab v1 encryption and restore the original file from a .gdcb copy; it removes the .GDCB extension once decryption succeeds.
No More Ransom Crypto Sheriff Free Upload a sample .gdcb file and the GDCB-DECRYPT.txt note to confirm the GandCrab variant and get pointed to the correct free decryptor.
Malwarebytes Freemium Scan and remove the active GandCrab infection first so files are not re-encrypted before you attempt to decrypt any .gdcb files.
Windows File History / System Restore Built-in Recover clean copies of affected files from a backup or restore point created before the infection instead of decrypting the .gdcb files.

Technical details

deep spec
EncodingOriginal file contents encrypted with AES-256 (Cipher Block Chaining) in GandCrab v1; the per-file/per-machine AES key is wrapped with an embedded RSA-2048 public key held by the attackers.
Byte orderNot applicable (encrypted ciphertext)
ContainerThe original file is overwritten/replaced with ciphertext and renamed with a trailing .GDCB extension (e.g. photo.jpg becomes photo.jpg.GDCB).
EncryptionAES-256 (CBC) for file data plus RSA-2048 to protect the AES key; later GandCrab versions (v4, v5) switched file encryption to Salsa20.
Typical sizeRoughly the same as the original file plus a small amount of padding/metadata.
StructureRenamed copy of the victim's file containing encrypted bytes; a plain-text ransom note named GDCB-DECRYPT.txt is dropped into every folder that has encrypted files.
IntegrityNone exposed publicly
PlatformsWindows
NotesGandCrab v1 was the first GandCrab release and the only one that used the .GDCB extension. It spread from late January 2018 through the RIG exploit kit via the Seamless malvertising campaign, and demanded payment in Dash cryptocurrency through a Tor payment site. Bitdefender, working with Europol and Romanian police, released a free decryptor for v1 in February 2018.
Ransom NoteGDCB-DECRYPT.txt
Malware FamilyGandCrab (Ransom.GandCrab)
ReleasedJanuary 2018

GDCB conversions

Community Q&A

asked by users
Ask a quick question
Get help from people who work with GDCB files. Be specific - include your system and software version.
No account needed · answers usually within a day

No questions yet - be the first to ask about GDCB files.

Frequently asked questions

How do I open a .gdcb file?
You cannot open it directly because the contents are encrypted. Remove the GandCrab infection, then run the free Bitdefender GandCrab decryptor from No More Ransom to restore the original file, which drops the .GDCB extension.
Can .gdcb files be decrypted for free?
Yes. GandCrab version 1, which uses the .GDCB extension, was cracked in February 2018. Bitdefender and law enforcement released a free tool that decrypts v1 files without paying the ransom.
Should I pay the GandCrab ransom?
No. Paying funds criminals and offers no guarantee of recovery, and it is unnecessary for v1 because a free decryptor exists. Use the No More Ransom tools instead.
Why did my files get a .GDCB extension?
GandCrab ransomware version 1 encrypted them and appended .GDCB to each filename. It also created a ransom note called GDCB-DECRYPT.txt in the affected folders.
Is the .gdcb file itself a virus?
No. The .gdcb file is your encrypted data and cannot run. The actual virus is the separate executable that encrypted it, which should be removed with anti-malware software.
What is GDCB-DECRYPT.txt?
It is the ransom note GandCrab drops into every folder with encrypted files. It explains the demand and links to a Tor payment page, but you should ignore its payment instructions and use a free decryptor.

References

1BleepingComputer: GandCrab Ransomware Appends GDCB Extensionwww.bleepingcomputer.com
2No More Ransom: GandCrab Decryption Tool (technical description)www.nomoreransom.org

Keep exploring

across the database

Top extensions this week

1.AQQAQQ Instant Messenger File
2.BINCD/DVD Disc Image (BIN/CUE)
3.MDMarkdown Document
4.RPMSGRestricted Permission Message
5.PARTPartial Download File
6.CRDOWNLOADChrome Partial Download File
7.NOMEDIAAndroid No-Media Marker File
8.PRDXSoftMaker Presentations Document
9.PRO6XProPresenter 6 Bundle File
10.SWFSmall Web Format (Shockwave Flash)

Related extensions

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

Free file tools

An in-browser file identifier and image converter - everything runs on your device.

Open the toolbox

Browse file extensions A-Z