.BLOWER

BLOWER ファイル

Blower Ransomware Encrypted File
質問する
クイック回答

.blowerファイルは、2019年初頭に現れたSTOP/Djvuファミリーの亜種であるBlowerランサムウェアによって暗号化された、通常の文書、写真、その他のファイルです。通常の方法で開くことはできません。内容はSalsa20暗号でスクランブルされ、元のファイル名に.blower拡張子が追加されます。データを回復する唯一の現実的な方法は、無料のEmsisoft STOP Djvu Decryptor(ファイルが回復可能なオフラインキーでロックされている場合に機能します)、クリーンなバックアップ、またはShadowExplorerなどのファイル復元ツールを使用することです。ウイルス対策ソフトでマルウェアを削除しても、暗号化は解除されません。

開発元: STOP/Djvu ransomware operators (unknown criminal group) カテゴリ: 暗号化されたファイル MIME: application/octet-stream
対応OS Windows
関連: .CRYPT · .SDOC · .AXX · .REM

このページの内容

19k+ 個の拡張子を索引済み
最終確認日:Jul 18, 2026

ファイルの種類がわかりませんか?

ファイルを識別ツールにドロップしてください。最初の数バイトを読み取って形式を特定します。

ファイルを識別する

BLOWER ファイル形式とは?

.blowerファイルは、Blowerランサムウェアによって暗号化された、文書、写真、ビデオなどの通常のファイルです。Blowerは2019年2月初旬に出現し、STOP/Djvuランサムウェアファミリーに属しています。コンピュータに感染すると、Salsa20暗号を使用してファイルをスクランブルし、各名前に.blowerを追加します。例えば、report.docxはreport.docx.blowerになります。他のSTOP/Djvuの亜種と同様に、各ファイルの最初の150 KBのみを暗号化するため、大きなファイルの末尾は読み取り可能なまま残りますが、依然として使用不可能な状態です。

ロックされたファイルと並んで、Blowerは_readme.txtという名前の身代金要求ノートをドロップします。このノートは、最初の72時間以内に490ドル、その後は980ドルを要求し、連絡先アドレスとして [email protected] と [email protected] を記載しています。暗号化中、このマルウェアはしばしば偽の Windows Update ウィンドウを表示し、セキュリティサイトをブロックするために Windows の hosts ファイルを編集します。通常、ソフトウェアのクラック、キー生成ツール(Keygen)、偽のアップデーター、悪意のあるメールの添付ファイルを通じて拡散します。

セキュリティと安全性

リスク: HIGH

A .blower file is the product of an active ransomware infection. Its presence means malware ran on the machine and may still be resident, re-encrypting new files or spreading. The file itself is encrypted data and cannot execute, but do not run the dropper or open _readme.txt links. Never pay the ransom or email the listed addresses. Isolate the machine, run a reputable antivirus, and attempt recovery only from clean media or the Emsisoft decryptor.

形式の詳細

概要
正式名称Blower Ransomware Encrypted File別名 Blower virus file, STOP/Djvu .blower variant
開発元STOP/Djvu ransomware operators (unknown criminal group)登場時期 2019 (early February)
MIME タイプapplication/octet-stream
タイプRansomware-encrypted binary (Salsa20-encrypted original file)

BLOWER ファイルを開くプログラム

Windows5 apps
Emsisoft STOP Djvu Decryptor 無料 Run the decryptor to check whether your .blower files were locked with a recoverable offline key, then decrypt them back to their original form in place.
Malwarebytes フリーミアム Scan and remove the active Blower ransomware and related malware before attempting any recovery, so files are not re-encrypted.
ShadowExplorer 無料 Browse and restore earlier versions of files from Windows Volume Shadow Copies if the ransomware did not delete them.
Recuva フリーミアム Attempt to recover deleted original files, since STOP/Djvu often encrypts a copy and removes the source.
Windows System Restore 標準搭載 Roll the system back to a restore point created before the infection, which may return some encrypted files to a clean state.

技術的詳細

詳細仕様
EncodingSalsa20 stream cipher; per-file key protected by RSA. Early STOP/Djvu variants such as .blower use an offline key when the command server is unreachable.
Byte orderN/A (original file bytes, partially enciphered)
ContainerOriginal file wrapped in place; extension .blower appended to the full original name (e.g. photo.jpg.blower)
CompressionNone added by the ransomware; original compression of the source file is preserved in the unencrypted tail
EncryptionSalsa20 for file contents, RSA for key protection. Only the first 150 KB of each file is encrypted, so large files retain a readable tail.
Typical sizeSame as the original file plus a small appended block containing the encryption marker and key/ID
StructureOriginal file header and first 150 KB enciphered with Salsa20; remainder of large files left intact; a marker and the encryption ID are appended at the end.
IntegrityNone; no integrity field is added.
PlatformsWindows
NotesDistributed through software cracks, key generators, fake updaters, bundled adware and malicious spam. During encryption it shows a fake Windows Update window and edits the Windows hosts file to block security sites. The ransom note _readme.txt is dropped in affected folders.
リリース日2019 (early February)
仕様書www.emsisoft.com

BLOWER の変換

コミュニティ Q&A

ユーザーからの質問
質問する
BLOWER ファイルを扱うユーザーからヘルプを得られます。OSやソフトウェアのバージョンなど、具体的に記載してください。
アカウント不要 ・ 通常1日以内に回答されます

まだ質問はありません。BLOWER ファイルについて最初の質問をしてみましょう。

よくある質問

.blowerファイルを開くにはどうすればよいですか?
内容が暗号化されているため、直接開くことはできません。無料のEmsisoft STOP Djvu Decryptorを実行して回復可能なオフラインキーがあるか確認するか、バックアップから元のファイルを復元してください。ファイル名を変更しても暗号化は解除されません。
.blowerファイルは無料で復号できますか?
可能な場合があります。Blowerは初期のSTOP/Djvu亜種であるため、オフラインキーでロックされたファイルはEmsisoft STOP Djvu Decryptorで回復できます。固有のオンラインキーでロックされたファイルは、攻撃者のプライベートキーなしでは復号できません。
身代金を支払うべきですか?
いいえ。支払いは犯罪者の資金源となり、有効なキーが提供される保証もありません。セキュリティ機関や研究者は支払わないよう助言しています。まずEmsisoftの復号ツール、バックアップ、シャドウコピーを試し、攻撃を地元の法執行機関に報告してください。
出現した _readme.txt ファイルは何ですか?
それはBlowerの身代金要求ノートです。72時間以内に490ドル、それ以降は980ドルを要求し、連絡先メールアドレスとして [email protected] と [email protected] を記載しています。暗号化されたファイルが含まれるフォルダーに作成されます。
.blowerファイル自体は危険ですか?
暗号化されたファイル自体が実行されることはありませんが、それはランサムウェアがコンピュータで実行されたことを示しています。実際のマルウェアがまだアクティブである可能性があるため、データを回復する前にウイルス対策ソフトでシステムをスキャンし、クリーンアップしてください。
ファイルに .blower 拡張子が付いたのはなぜですか?
Blowerランサムウェアは通常、ソフトウェアのクラック、キー生成ツール、偽のアップデーター、または悪意のあるメールの添付ファイルを通じて侵入します。実行されると、Salsa20でファイルを暗号化し、各名前に .blower を追加します。

参考文献

1PCrisk - .blower Ransomware removal and recoverywww.pcrisk.com
2Emsisoft - STOP Djvu Decryptor (free)www.emsisoft.com

さらに探索

データベース全体から

今週のトップ拡張子

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.BINCD/DVD Disc Image (BIN/CUE)
5.EXEWindows Executable (Portable Executable)
6.RPMSGRestricted Permission Message
7.MDMarkdown Document
8.DATProgram Data File (generic)
9.NOMEDIAAndroid No-Media Marker File
10.TXTPlain Text File

関連する拡張子

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

無料ファイルツール

ブラウザで動作するファイル識別および画像変換ツール。すべてお使いのデバイス上で実行されます。

ツールボックスを開く

ファイル拡張子を A-Z で閲覧