Qu'est-ce que le format de fichier ADAME ?
Un fichier .adame est un fichier ordinaire, tel qu'un document ou une photo, qui a été chiffré par le ransomware Adame. Adame est une souche de la famille de ransomwares Phobos, documentée pour la première fois en 2019 par les chercheurs Amigo-A et Michael Gillespie. Il ne crée pas ces fichiers volontairement ; il détourne les fichiers que vous possédez déjà.
Lorsque le logiciel malveillant s'exécute, il renomme chaque fichier victime selon un modèle long qui regroupe le nom d'origine, un identifiant unique, l'e-mail de l'attaquant entre crochets et le suffixe. Un fichier nommé report.pdf devient quelque chose comme report.pdf.id[1E857D00-2275].[[email protected]].adame. Sous le capot, Phobos chiffre les données du fichier avec AES-256 en utilisant une clé aléatoire par fichier, puis enveloppe cette clé avec une clé publique RSA-1024 intégrée dans l'échantillon. Les fichiers volumineux ne sont que partiellement chiffrés pour accélérer l'attaque. Deux notes de rançon, info.hta et info.txt, sont déposées pour expliquer la demande de paiement.
Sécurité et sûreté
RISQUE : HIGHThe .adame extension is the direct result of an active ransomware infection. The encrypted files themselves are inert data, but their presence means the Adame/Phobos malware ran on the machine and may still be present. Phobos strains delete shadow copies, disable recovery, and can spread across network shares and RDP connections. Isolate the machine from the network, run a reputable anti-malware scan to remove the payload, and restore data only from a clean backup. Do not pay the ransom; there is no guarantee of recovery and it funds further attacks.
Détails du format
en bref- Adame (Amnesia) ransomware - An older, separate ransomware based on the Amnesia/Globe Imposter family also appended
.adame. It is distinct from the dominant Phobos-based Adame and was documented in earlier 2019 removal guides.
Programmes qui ouvrent les fichiers ADAME
.adame extension. .adame file and a ransom note to confirm the exact ransomware family and learn whether any decryption help is currently listed. .adame copy. Détails techniques
spécifications approfondies| Encoding | AES-256 symmetric encryption of file data; per-file random key and IV |
| Container | Original file wrapped with appended encrypted payload |
| Encryption | Hybrid cryptosystem: file bytes encrypted with AES-256, and the AES key encrypted with RSA-1024 using a hardcoded public key, then stored at the end of the file. Large files are only partially encrypted in selected segments to speed up the attack. |
| Typical size | Slightly larger than the original file due to the appended encrypted key block and metadata |
| Structure | Encrypted original content followed by an RSA-protected key blob. The filename is rewritten to pattern <original>.id[<victim-id>].[<email>].adame, for example document.pdf.id[1E857D00-2275].[[email protected]].adame. |
| Integrity | None; no recovery checksum is stored for the victim |
| Platforms | Windows |
| Notes | Dropped alongside two ransom notes: info.hta (pop-up HTML application) and info.txt. Contact addresses seen include [email protected], [email protected], [email protected] and [email protected]. Phobos deletes shadow copies and disables recovery to prevent restoration. No free decryptor exists for the Phobos-based Adame variant. |
| Publié | 2019 |
Conversions ADAME
Q&R de la communauté
posées par les utilisateursPas encore de questions - soyez le premier à poser une question sur les fichiers ADAME.
Foire aux questions
Comment ouvrir un fichier .adame ?
Existe-t-il un décrypteur gratuit pour les fichiers .adame ?
Dois-je payer la rançon pour récupérer mes fichiers ?
Puis-je récupérer des fichiers .adame en les renommant ?
.adame ne déchiffre rien ; les octets sont toujours chiffrés avec AES-256. Le renommage ne change que l'étiquette, pas le contenu.