Che cos'è il formato di file ADAME?
Un file .adame è un file ordinario, come un documento o una foto, che è stato crittografato dal ransomware Adame. Adame è un ceppo della famiglia di ransomware Phobos, documentato per la prima volta nel 2019 dai ricercatori Amigo-A e Michael Gillespie. Non crea questi file intenzionalmente; dirotta i file già presenti sul sistema.
Quando il malware viene eseguito, rinomina ogni file vittima secondo uno schema lungo che raggruppa il nome originale, un ID univoco, l'email dell'aggressore tra parentesi e il suffisso. Un file chiamato report.pdf diventa qualcosa di simile a report.pdf.id[1E857D00-2275].[[email protected]].adame. Sotto il cofano, Phobos crittografa i dati del file con AES-256 utilizzando una chiave casuale per ogni file, quindi avvolge quella chiave con una chiave pubblica RSA-1024 integrata nel campione. I file di grandi dimensioni vengono crittografati solo parzialmente per accelerare l'attacco. Vengono rilasciate due note di riscatto, info.hta e info.txt, per spiegare la richiesta di pagamento.
Sicurezza e incolumità
RISCHIO: HIGHThe .adame extension is the direct result of an active ransomware infection. The encrypted files themselves are inert data, but their presence means the Adame/Phobos malware ran on the machine and may still be present. Phobos strains delete shadow copies, disable recovery, and can spread across network shares and RDP connections. Isolate the machine from the network, run a reputable anti-malware scan to remove the payload, and restore data only from a clean backup. Do not pay the ransom; there is no guarantee of recovery and it funds further attacks.
Dettagli del formato
in sintesi- Adame (Amnesia) ransomware - An older, separate ransomware based on the Amnesia/Globe Imposter family also appended
.adame. It is distinct from the dominant Phobos-based Adame and was documented in earlier 2019 removal guides.
Programmi che aprono file ADAME
.adame extension. .adame file and a ransom note to confirm the exact ransomware family and learn whether any decryption help is currently listed. .adame copy. Dettagli tecnici
specifiche approfondite| Encoding | AES-256 symmetric encryption of file data; per-file random key and IV |
| Container | Original file wrapped with appended encrypted payload |
| Encryption | Hybrid cryptosystem: file bytes encrypted with AES-256, and the AES key encrypted with RSA-1024 using a hardcoded public key, then stored at the end of the file. Large files are only partially encrypted in selected segments to speed up the attack. |
| Typical size | Slightly larger than the original file due to the appended encrypted key block and metadata |
| Structure | Encrypted original content followed by an RSA-protected key blob. The filename is rewritten to pattern <original>.id[<victim-id>].[<email>].adame, for example document.pdf.id[1E857D00-2275].[[email protected]].adame. |
| Integrity | None; no recovery checksum is stored for the victim |
| Platforms | Windows |
| Notes | Dropped alongside two ransom notes: info.hta (pop-up HTML application) and info.txt. Contact addresses seen include [email protected], [email protected], [email protected] and [email protected]. Phobos deletes shadow copies and disables recovery to prevent restoration. No free decryptor exists for the Phobos-based Adame variant. |
| Rilasciato | 2019 |
Conversioni ADAME
Domande e risposte della community
chiesto dagli utentiAncora nessuna domanda - sii il primo a chiedere informazioni sui file ADAME.
Domande frequenti
Come apro un file .adame?
Esiste un decodificatore gratuito per i file .adame?
Dovrei pagare il riscatto per recuperare i miei file?
Posso recuperare i file .adame rinominandoli?
.adame non decrittografa nulla; i byte sono ancora crittografati con AES-256. La ridenominazione cambia solo l'etichetta, non il contenuto.