.ADAME

ADAME ファイル

Adame Ransomware Encrypted File
質問する
クイック回答

.adame ファイルは、Phobos ファミリーの一種である Adame ランサムウェアによって暗号化され、身代金の対象となった通常のドキュメント、写真、またはその他のファイルです。これを開くことはできません。内容は AES-256 でスクランブルされており、鍵は攻撃者が保持しています。このバリアントに対する無料の復号ツールは存在しないため、クリーンな復旧方法は、アンチウイルスツールでマルウェアを削除し、感染前に作成されたバックアップからファイルを復元することのみです。

開発元: Unknown cybercriminals (Phobos ransomware operators) カテゴリ: 暗号化されたファイル MIME: application/octet-stream
対応OS Windows
関連: .CRYPT · .SDOC · .AXX · .REM

このページの内容

19k+ 個の拡張子を索引済み
最終確認日:Jul 7, 2026

ファイルの種類がわかりませんか?

ファイルを識別ツールにドロップしてください。最初の数バイトを読み取って形式を特定します。

ファイルを識別する

ADAME ファイル形式とは?

.adame ファイルは、ドキュメントや写真などの普通のファイルが Adame ランサムウェアによって暗号化されたものです。Adame は Phobos ランサムウェアファミリーの一種で、2019年にリサーチャーの Amigo-A 氏と Michael Gillespie 氏によって初めて報告されました。このマルウェアは意図的にこれらのファイルを作成するのではなく、既存のファイルを乗っ取ります。

マルウェアが実行されると、被害に遭った各ファイルの名前を、元の名前、固有 ID、ブラケットで囲まれた攻撃者のメールアドレス、および拡張子を組み合わせた長いパターンに変更します。例えば、report.pdf というファイルは report.pdf.id[1E857D00-2275].[[email protected]].adame のようになります。内部的には、Phobos はファイルごとのランダムな鍵を使用して AES-256 でファイルデータを暗号化し、その鍵を検体に埋め込まれた RSA-1024 公開鍵でラップします。攻撃を高速化するため、大きなファイルは部分的にしか暗号化されません。支払い要求を説明するために、info.htainfo.txt という2つの身代金要求状(ランサムノート)が作成されます。

セキュリティと安全性

リスク: HIGH

The .adame extension is the direct result of an active ransomware infection. The encrypted files themselves are inert data, but their presence means the Adame/Phobos malware ran on the machine and may still be present. Phobos strains delete shadow copies, disable recovery, and can spread across network shares and RDP connections. Isolate the machine from the network, run a reputable anti-malware scan to remove the payload, and restore data only from a clean backup. Do not pay the ransom; there is no guarantee of recovery and it funds further attacks.

形式の詳細

概要
正式名称Adame Ransomware Encrypted File別名 Adame Virus, Adame Phobos Ransomware
開発元Unknown cybercriminals (Phobos ransomware operators)登場時期 2019
MIME タイプapplication/octet-stream
タイプEncrypted binary produced by ransomware
この拡張子は以下でも使用されています…
  • Adame (Amnesia) ransomware - An older, separate ransomware based on the Amnesia/Globe Imposter family also appended .adame. It is distinct from the dominant Phobos-based Adame and was documented in earlier 2019 removal guides.

ADAME ファイルを開くプログラム

Windows5 apps
Malwarebytes フリーミアム Run a full scan to detect and remove the Adame/Phobos payload so it stops encrypting new files; note that removal does not decrypt files already carrying the .adame extension.
Emsisoft Anti-Malware フリーミアム Scan the system to quarantine the ransomware and then check the Emsisoft decryptor catalog to confirm whether a free tool has appeared for this variant.
ID Ransomware 無料 Upload an .adame file and a ransom note to confirm the exact ransomware family and learn whether any decryption help is currently listed.
Kaspersky NoRansom Decryptors 無料 Check the decryptor list for a matching tool; if one becomes available it can rebuild the original file from the .adame copy.
Windows File History / System Restore 標準搭載 After the malware is removed, recover clean copies of affected files from File History, a previous backup, or a restore point created before the infection.

技術的詳細

詳細仕様
EncodingAES-256 symmetric encryption of file data; per-file random key and IV
ContainerOriginal file wrapped with appended encrypted payload
EncryptionHybrid cryptosystem: file bytes encrypted with AES-256, and the AES key encrypted with RSA-1024 using a hardcoded public key, then stored at the end of the file. Large files are only partially encrypted in selected segments to speed up the attack.
Typical sizeSlightly larger than the original file due to the appended encrypted key block and metadata
StructureEncrypted original content followed by an RSA-protected key blob. The filename is rewritten to pattern <original>.id[<victim-id>].[<email>].adame, for example document.pdf.id[1E857D00-2275].[[email protected]].adame.
IntegrityNone; no recovery checksum is stored for the victim
PlatformsWindows
NotesDropped alongside two ransom notes: info.hta (pop-up HTML application) and info.txt. Contact addresses seen include [email protected], [email protected], [email protected] and [email protected]. Phobos deletes shadow copies and disables recovery to prevent restoration. No free decryptor exists for the Phobos-based Adame variant.
リリース日2019

ADAME の変換

コミュニティ Q&A

ユーザーからの質問
質問する
ADAME ファイルを扱うユーザーからヘルプを得られます。OSやソフトウェアのバージョンなど、具体的に記載してください。
アカウント不要 ・ 通常1日以内に回答されます

まだ質問はありません。ADAME ファイルについて最初の質問をしてみましょう。

よくある質問

.adame ファイルを開くにはどうすればよいですか?
暗号化された状態では開くことができません。ファイルの内容は Adame ランサムウェアによってスクランブルされており、攻撃者が保持する復号鍵が必要です。現実的な選択肢は、バックアップから元のファイルを復元するか、この Phobos バリアント用の無料復号ツールがリリースされるのを待つことです。
.adame ファイル用の無料復号ツールはありますか?
現時点では、Phobos ベースの Adame バリアントに対する無料の復号ツールは存在しません。リサーチャーが欠陥を発見したり、鍵サーバーを差し押さえたりした際に復号ツールが登場することがあるため、定期的に ID Ransomware、Emsisoft、Kaspersky NoRansom を確認してください。
ファイルを復旧するために身代金を支払うべきですか?
セキュリティベンダーと File-Extension.info は支払わないようアドバイスしています。支払っても機能する鍵を受け取れる保証はなく、将来の攻撃のターゲットとしてマークされることになり、犯罪者に資金を提供することにもなります。マルウェアの削除とバックアップからの復元に集中してください。
名前を変更することで .adame ファイルを復旧できますか?
いいえ。.adame 拡張子を削除しても何も復号されません。データは依然として AES-256 で暗号化されています。名前の変更はラベルを変えるだけで、内容は変わりません。
コンピュータはどのようにして Adame に感染したのですか?
Adame のような Phobos 系は、通常、公開されているかブルートフォース攻撃を受けたリモートデスクトップ接続、悪意のあるメールの添付ファイル、偽のソフトウェアクラック、トロイの木馬ダウンローダーを通じて侵入します。RDP のセキュリティ強化、パッチの適用、強力なパスワードの使用によりリスクを軽減できます。
出現した info.hta と info.txt ファイルは何ですか?
これらは Adame によって残された身代金要求状です。info.hta は支払い手順と攻撃者のメールアドレスを含むポップアップウィンドウを開き、info.txt は同じ要求の短いテキスト版です。これらはデータの復旧には不要であり、クリーンアップ後に削除しても構いません。

参考文献

1FileInfo - .ADAME filefileinfo.com
2PCrisk - Adame Ransomware removal and recoverywww.pcrisk.com

さらに探索

データベース全体から

今週のトップ拡張子

1.AQQAQQ Instant Messenger File
2.BINCD/DVD Disc Image (BIN/CUE)
3.MDMarkdown Document
4.RPMSGRestricted Permission Message
5.PARTPartial Download File
6.CRDOWNLOADChrome Partial Download File
7.NOMEDIAAndroid No-Media Marker File
8.PRDXSoftMaker Presentations Document
9.PRO6XProPresenter 6 Bundle File
10.SWFSmall Web Format (Shockwave Flash)

関連する拡張子

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

無料ファイルツール

ブラウザで動作するファイル識別および画像変換ツール。すべてお使いのデバイス上で実行されます。

ツールボックスを開く

ファイル拡張子を A-Z で閲覧