.GDCB

File GDCB

GandCrab Ransomware Encrypted File
Fai una domanda
RISPOSTA RAPIDA

Un file .gdcb è un file che è stato crittografato dalla versione 1 del ransomware GandCrab, che aggiunge l'estensione .GDCB al nome del file originale (ad esempio, budget.xlsx.GDCB). Non è un normale formato di file; i contenuti sono rimescolati con AES-256 e non possono essere letti finché non vengono decifrati. Poiché la v1 di GandCrab è stata violata, è possibile recuperare questi file gratuitamente utilizzando lo strumento di decrittazione Bitdefender GandCrab dal progetto No More Ransom invece di pagare il riscatto.

Sviluppatore: GandCrab ransomware operators (cybercriminal group) Categoria: File crittografati MIME: application/octet-stream
SI APRE SU Windows
Correlati: .CRYPT · .SDOC · .AXX · .REM

In questa pagina

19k+ estensioni indicizzate
Ultima revisione Jun 29, 2026

Non sei sicuro di cosa sia il tuo file?

Trascina qualsiasi file nel nostro identificatore - leggiamo solo i primi byte per dare un nome al formato.

Identifica un file

Che cos'è il formato di file GDCB?

Un file .gdcb è un documento, una foto o un altro file che è stato crittografato dalla versione 1 del ransomware GandCrab. Quando il malware viene eseguito, rimescola il contenuto del file e aggiunge .GDCB alla fine del nome, quindi budget.xlsx diventa budget.xlsx.GDCB. Rilascia inoltre una richiesta di riscatto chiamata GDCB-DECRYPT.txt in ogni cartella interessata.

GandCrab è apparso alla fine di gennaio 2018 e si è diffuso attraverso l'exploit kit RIG. La versione 1 crittografava i file con AES-256 e proteggeva la chiave con una chiave pubblica RSA-2048, richiedendo poi il pagamento nella criptovaluta Dash tramite un sito Tor. Solo la versione 1 utilizzava l'estensione .GDCB; le versioni successive sono passate alle estensioni .CRAB e .KRAB.

Sicurezza e incolumità

RISCHIO: HIGH

A .gdcb file itself is inert encrypted data, but its presence means a machine was compromised by GandCrab ransomware. The malware executable that created it is dangerous and may still be active, so disconnect the device, remove the infection with an anti-malware tool, and only then decrypt. Never pay the Dash ransom; a free decryptor exists for GandCrab v1.

Dettagli del formato

in sintesi
NOME COMPLETOGandCrab Ransomware Encrypted Fileanche noto come GandCrab v1 encrypted file, GDCB virus file
SVILUPPATOREGandCrab ransomware operators (cybercriminal group)dal January 2018
TIPO MIMEapplication/octet-stream
TIPORansomware-encrypted binary container

Programmi che aprono file GDCB

Windows4 apps
Bitdefender GandCrab Decryption Tool Gratuito Run the free decryptor to reverse GandCrab v1 encryption and restore the original file from a .gdcb copy; it removes the .GDCB extension once decryption succeeds.
No More Ransom Crypto Sheriff Gratuito Upload a sample .gdcb file and the GDCB-DECRYPT.txt note to confirm the GandCrab variant and get pointed to the correct free decryptor.
Malwarebytes Freemium Scan and remove the active GandCrab infection first so files are not re-encrypted before you attempt to decrypt any .gdcb files.
Windows File History / System Restore Integrato Recover clean copies of affected files from a backup or restore point created before the infection instead of decrypting the .gdcb files.

Dettagli tecnici

specifiche approfondite
EncodingOriginal file contents encrypted with AES-256 (Cipher Block Chaining) in GandCrab v1; the per-file/per-machine AES key is wrapped with an embedded RSA-2048 public key held by the attackers.
Byte orderNot applicable (encrypted ciphertext)
ContainerThe original file is overwritten/replaced with ciphertext and renamed with a trailing .GDCB extension (e.g. photo.jpg becomes photo.jpg.GDCB).
EncryptionAES-256 (CBC) for file data plus RSA-2048 to protect the AES key; later GandCrab versions (v4, v5) switched file encryption to Salsa20.
Typical sizeRoughly the same as the original file plus a small amount of padding/metadata.
StructureRenamed copy of the victim's file containing encrypted bytes; a plain-text ransom note named GDCB-DECRYPT.txt is dropped into every folder that has encrypted files.
IntegrityNone exposed publicly
PlatformsWindows
NotesGandCrab v1 was the first GandCrab release and the only one that used the .GDCB extension. It spread from late January 2018 through the RIG exploit kit via the Seamless malvertising campaign, and demanded payment in Dash cryptocurrency through a Tor payment site. Bitdefender, working with Europol and Romanian police, released a free decryptor for v1 in February 2018.
Ransom NoteGDCB-DECRYPT.txt
Malware FamilyGandCrab (Ransom.GandCrab)
RilasciatoJanuary 2018

Conversioni GDCB

Domande e risposte della community

chiesto dagli utenti
Fai una domanda veloce
Ottieni aiuto da persone che lavorano con i file GDCB. Sii specifico - includi il tuo sistema e la versione del software.
Nessun account necessario · risposte solitamente entro un giorno

Ancora nessuna domanda - sii il primo a chiedere informazioni sui file GDCB.

Domande frequenti

Come si apre un file .gdcb?
Non puoi aprirlo direttamente perché i contenuti sono crittografati. Rimuovi l'infezione GandCrab, quindi esegui il decrittore gratuito Bitdefender GandCrab da No More Ransom per ripristinare il file originale, che eliminerà l'estensione .GDCB.
I file .gdcb possono essere decifrati gratuitamente?
Sì. La versione 1 di GandCrab, che utilizza l'estensione .GDCB, è stata violata nel febbraio 2018. Bitdefender e le forze dell'ordine hanno rilasciato uno strumento gratuito che decifra i file v1 senza pagare il riscatto.
Dovrei pagare il riscatto di GandCrab?
No. Pagare finanzia i criminali e non offre alcuna garanzia di recupero; inoltre non è necessario per la v1 poiché esiste un decrittore gratuito. Usa invece gli strumenti di No More Ransom.
Perché i miei file hanno l'estensione .GDCB?
La versione 1 del ransomware GandCrab li ha crittografati e ha aggiunto .GDCB a ogni nome di file. Ha anche creato una richiesta di riscatto chiamata GDCB-DECRYPT.txt nelle cartelle interessate.
Il file .gdcb è di per sé un virus?
No. Il file .gdcb rappresenta i tuoi dati crittografati e non può essere eseguito. Il virus vero e proprio è l'eseguibile separato che lo ha crittografato, che dovrebbe essere rimosso con un software anti-malware.
Cos'è GDCB-DECRYPT.txt?
È la richiesta di riscatto che GandCrab rilascia in ogni cartella con file crittografati. Spiega la richiesta e rimanda a una pagina di pagamento Tor, ma dovresti ignorare le istruzioni di pagamento e usare un decrittore gratuito.

Riferimenti

1BleepingComputer: GandCrab Ransomware Appends GDCB Extensionwww.bleepingcomputer.com
2No More Ransom: GandCrab Decryption Tool (technical description)www.nomoreransom.org

Continua a esplorare

nel database

Migliori estensioni della settimana

1.AQQAQQ Instant Messenger File
2.BINCD/DVD Disc Image (BIN/CUE)
3.MDMarkdown Document
4.RPMSGRestricted Permission Message
5.PARTPartial Download File
6.CRDOWNLOADChrome Partial Download File
7.NOMEDIAAndroid No-Media Marker File
8.PRDXSoftMaker Presentations Document
9.PRO6XProPresenter 6 Bundle File
10.SWFSmall Web Format (Shockwave Flash)

Estensioni correlate

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

Strumenti file gratuiti

Un identificatore di file e convertitore di immagini nel browser - tutto viene eseguito sul tuo dispositivo.

Apri la cassetta degli attrezzi

Sfoglia le estensioni dei file A-Z