.GDCB

GDCB ファイル

GandCrab Ransomware Encrypted File
質問する
クイック回答

.gdcbファイルは、GandCrabランサムウェアのバージョン1によって暗号化されたファイルであり、元のファイル名の末尾に.GDCBが追加されます(例:budget.xlsx.GDCB)。これは通常のファイル形式ではなく、内容はAES-256でスクランブルされており、復号されるまで読み取ることができません。GandCrab v1は解析されているため、身代金を支払う代わりに、No More RansomプロジェクトのBitdefender GandCrab復号ツールを使用して、これらのファイルを無料で復元できます。

開発元: GandCrab ransomware operators (cybercriminal group) カテゴリ: 暗号化されたファイル MIME: application/octet-stream
対応OS Windows
関連: .CRYPT · .SDOC · .AXX · .REM

このページの内容

19k+ 個の拡張子を索引済み
最終確認日:Jun 29, 2026

ファイルの種類がわかりませんか?

ファイルを識別ツールにドロップしてください。最初の数バイトを読み取って形式を特定します。

ファイルを識別する

GDCB ファイル形式とは?

.gdcbファイルは、GandCrabランサムウェアのバージョン1によって暗号化されたドキュメント、写真、またはその他のファイルです。マルウェアが実行されると、ファイルの内容をスクランブルし、名前の末尾に.GDCBを追加します。そのため、budget.xlsxはbudget.xlsx.GDCBになります。また、影響を受けたすべてのフォルダーにGDCB-DECRYPT.txtという身代金要求メモ(ランサムノート)をドロップします。

GandCrabは2018年1月下旬に登場し、RIGエクスプロイトキットを通じて拡散しました。バージョン1はファイルをAES-256で暗号化し、キーをRSA-2048公開鍵で保護した上で、Torサイトを通じて仮想通貨Dashでの支払いを要求しました。.GDCBを使用したはバージョン1のみで、それ以降のバージョンは.CRABや.KRAB拡張子に切り替わりました。

セキュリティと安全性

リスク: HIGH

A .gdcb file itself is inert encrypted data, but its presence means a machine was compromised by GandCrab ransomware. The malware executable that created it is dangerous and may still be active, so disconnect the device, remove the infection with an anti-malware tool, and only then decrypt. Never pay the Dash ransom; a free decryptor exists for GandCrab v1.

形式の詳細

概要
正式名称GandCrab Ransomware Encrypted File別名 GandCrab v1 encrypted file, GDCB virus file
開発元GandCrab ransomware operators (cybercriminal group)登場時期 January 2018
MIME タイプapplication/octet-stream
タイプRansomware-encrypted binary container

GDCB ファイルを開くプログラム

Windows4 apps
Bitdefender GandCrab Decryption Tool 無料 Run the free decryptor to reverse GandCrab v1 encryption and restore the original file from a .gdcb copy; it removes the .GDCB extension once decryption succeeds.
No More Ransom Crypto Sheriff 無料 Upload a sample .gdcb file and the GDCB-DECRYPT.txt note to confirm the GandCrab variant and get pointed to the correct free decryptor.
Malwarebytes フリーミアム Scan and remove the active GandCrab infection first so files are not re-encrypted before you attempt to decrypt any .gdcb files.
Windows File History / System Restore 標準搭載 Recover clean copies of affected files from a backup or restore point created before the infection instead of decrypting the .gdcb files.

技術的詳細

詳細仕様
EncodingOriginal file contents encrypted with AES-256 (Cipher Block Chaining) in GandCrab v1; the per-file/per-machine AES key is wrapped with an embedded RSA-2048 public key held by the attackers.
Byte orderNot applicable (encrypted ciphertext)
ContainerThe original file is overwritten/replaced with ciphertext and renamed with a trailing .GDCB extension (e.g. photo.jpg becomes photo.jpg.GDCB).
EncryptionAES-256 (CBC) for file data plus RSA-2048 to protect the AES key; later GandCrab versions (v4, v5) switched file encryption to Salsa20.
Typical sizeRoughly the same as the original file plus a small amount of padding/metadata.
StructureRenamed copy of the victim's file containing encrypted bytes; a plain-text ransom note named GDCB-DECRYPT.txt is dropped into every folder that has encrypted files.
IntegrityNone exposed publicly
PlatformsWindows
NotesGandCrab v1 was the first GandCrab release and the only one that used the .GDCB extension. It spread from late January 2018 through the RIG exploit kit via the Seamless malvertising campaign, and demanded payment in Dash cryptocurrency through a Tor payment site. Bitdefender, working with Europol and Romanian police, released a free decryptor for v1 in February 2018.
Ransom NoteGDCB-DECRYPT.txt
Malware FamilyGandCrab (Ransom.GandCrab)
リリース日January 2018

GDCB の変換

コミュニティ Q&A

ユーザーからの質問
質問する
GDCB ファイルを扱うユーザーからヘルプを得られます。OSやソフトウェアのバージョンなど、具体的に記載してください。
アカウント不要 ・ 通常1日以内に回答されます

まだ質問はありません。GDCB ファイルについて最初の質問をしてみましょう。

よくある質問

.gdcbファイルを開くにはどうすればよいですか?
内容が暗号化されているため、直接開くことはできません。GandCrabの感染を除去した後、No More Ransomの無料のBitdefender GandCrab復号ツールを実行して元のファイルを復元してください。復元されると.GDCB拡張子は削除されます。
.gdcbファイルは無料で復号できますか?
はい。.GDCB拡張子を使用するGandCrabバージョン1は、2018年2月に解析されました。Bitdefenderと法執行機関は、身代金を支払わずにv1ファイルを復号する無料ツールをリリースしました。
GandCrabの身代金を支払うべきですか?
いいえ。支払いは犯罪者の資金源となり、回復の保証もありません。また、v1については無料の復号ツールが存在するため不要です。代わりにNo More Ransomのツールを使用してください。
なぜファイルに.GDCB拡張子が付いたのですか?
GandCrabランサムウェアのバージョン1がファイルを暗号化し、各ファイル名の末尾に.GDCBを追加したためです。また、影響を受けたフォルダーにGDCB-DECRYPT.txtという身代金要求メモを作成しました。
.gdcbファイル自体はウイルスですか?
いいえ。.gdcbファイルは暗号化されたデータであり、実行することはできません。実際のウイルスは、ファイルを暗号化した別の実行ファイルであり、アンチマルウェアソフトウェアで削除する必要があります。
GDCB-DECRYPT.txtとは何ですか?
これは、GandCrabが暗号化されたファイルのあるすべてのフォルダーにドロップする身代金要求メモです。要求内容を説明し、Torの支払いページへのリンクを記載していますが、支払い指示は無視して無料の復号ツールを使用してください。

参考文献

1BleepingComputer: GandCrab Ransomware Appends GDCB Extensionwww.bleepingcomputer.com
2No More Ransom: GandCrab Decryption Tool (technical description)www.nomoreransom.org

さらに探索

データベース全体から

今週のトップ拡張子

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.BINCD/DVD Disc Image (BIN/CUE)
5.EXEWindows Executable (Portable Executable)
6.RPMSGRestricted Permission Message
7.MDMarkdown Document
8.DATProgram Data File (generic)
9.NOMEDIAAndroid No-Media Marker File
10.TXTPlain Text File

関連する拡張子

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

無料ファイルツール

ブラウザで動作するファイル識別および画像変換ツール。すべてお使いのデバイス上で実行されます。

ツールボックスを開く

ファイル拡張子を A-Z で閲覧