.ODIN

ODIN ファイル

Locky Ransomware Encrypted File (.odin variant)
質問する
クイック回答

.odinファイルは、Lockyランサムウェアによって暗号化されたドキュメント、写真、データベース、またはその他のファイルです。Lockyは2016年9月にロックしたファイルに.odinを付加し始め、各ファイルをランダムな16進数の文字列にリネームしました。内容はAES-128およびRSA-2048暗号化でスクランブルされており、無料の復号ツールも存在しないため、通常の方法でファイルを開くことはできません。現実的な解決策は、マルウェアを削除し、クリーンなバックアップまたは(残っていれば)シャドウコピーからオリジナルを復元することです。

開発元: Locky ransomware operators (unknown criminal group) カテゴリ: 暗号化されたファイル MIME: application/octet-stream
対応OS Windows
関連: .CRYPT · .SDOC · .AXX · .REM

このページの内容

19k+ 個の拡張子を索引済み
最終確認日:Jun 18, 2026

ファイルの種類がわかりませんか?

ファイルを識別ツールにドロップしてください。最初の数バイトを読み取って形式を特定します。

ファイルを識別する

ODIN ファイル形式とは?

.odinファイルは、Lockyランサムウェアによって暗号化された個人ファイルです。Lockyは2016年初頭に初めて出現したWindowsマルウェアファミリーで、ドキュメント、写真、データベース、アーカイブをロックし、その返還のために支払いを要求します。2016年9月頃、オペレーターは付加する拡張子を.zeptoから北欧の神にちなんだ.odinに変更しました。Fortinetの研究者は、.odinのコードが以前の.zeptoビルドと98〜99%同一であることを発見しており、これは新しいラベルを付けただけの同じマルウェアであることを示しています。

Lockyが実行されると、約400種類のファイルタイプをスキャンし、それぞれをAES-128で暗号化し、そのAESキーをRSA-2048暗号の中にロックします。その後、すべてのファイルを 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin のような16進数の識別子にリネームし、元の名前を破棄します。また、Windowsのシャドウボリュームコピーを削除し、_HOWDO_text.html や _HOWDO_text.bmp という名前の身代金要求ノート(ランサムノート)を配置します。.odinファイルが見つかるということは、コンピュータが感染したことを意味しており、珍しいファイル形式を所有しているわけではありません。

セキュリティと安全性

リスク: HIGH

The presence of .odin files means the computer was hit by active ransomware. The .odin files themselves are inert encrypted data and cannot execute, but they signal that Locky ran on the system, deleted shadow copies and may still be present. Never pay the ransom without expert advice, and treat the machine as compromised until it is fully cleaned and, ideally, wiped and rebuilt from a trusted backup.

形式の詳細

概要
正式名称Locky Ransomware Encrypted File (.odin variant)別名 Odin File Extension Ransomware, Odin virus
開発元Locky ransomware operators (unknown criminal group)登場時期 September 2016
MIME タイプapplication/octet-stream
タイプEncrypted binary (malware output)
この拡張子は以下でも使用されています…
  • Samsung Odin firmware package - The Odin flashing tool for Samsung Galaxy devices uses firmware files, but those are typically .tar or .tar.md5 archives rather than a .odin extension. Unrelated to the ransomware.
  • ODIN application data - A handful of niche applications have used .odin for internal data or backup files. These are legitimate and unrelated to Locky.

ODIN ファイルを開くプログラム

Windows4 apps
Malwarebytes フリーミアム Run a full scan to detect and remove the Locky infection before attempting any recovery, since the encrypted .odin files themselves cannot be opened.
Emsisoft Anti-Malware 有料 Scan the machine to clean out the ransomware, then check Emsisoft's decryptor catalog to confirm whether any tool covers your variant (none exists for Locky .odin).
Windows File Recovery / Shadow Explorer 無料 Browse Volume Shadow Copies to restore earlier unencrypted versions of the files, though Locky usually deletes these.
ID Ransomware 無料 Upload a ransom note and an .odin sample to confirm the exact ransomware family and whether any decryption is currently possible.

技術的詳細

詳細仕様
EncodingAES-128 (ECB mode) file encryption with the AES key protected by RSA-2048
Byte orderN/A (encrypted ciphertext)
ContainerNone; the original file is overwritten in place as raw ciphertext with a renamed filename
EncryptionRSA-2048 + AES-128. The AES session keys are generated server-side by the attacker's command-and-control infrastructure, so the private key needed for decryption never stays on the victim machine.
Typical sizeRoughly the same size as the original encrypted file
StructureThe plaintext of a targeted document, image, database or archive is replaced by AES-128 ciphertext. The file is then renamed to a hexadecimal identifier of the form [8]-[4]-[4]-[4]-[12] followed by the .odin extension (for example 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin). The original name and extension are not preserved on disk.
PlatformsWindows
NotesLocky's .odin variant targets roughly 400 to 460 file types across documents, databases, images and archives. It deletes Windows Shadow Volume Copies to block local recovery and drops ransom notes named _HOWDO_text.html, _HOWDO_text.bmp and _[2-digit-number]_HOWDO_text.html. It is delivered by spam email carrying WSF/JS script attachments or macro-laden Office documents that download an encrypted DLL and run it via rundll32.exe. Despite the name, victims are infected by Locky using the .odin extension, not a separate 'Odin' malware family; code comparison shows a 98-99% match with the earlier .zepto variant.
リリース日September 2016

ODIN の変換

コミュニティ Q&A

ユーザーからの質問
質問する
ODIN ファイルを扱うユーザーからヘルプを得られます。OSやソフトウェアのバージョンなど、具体的に記載してください。
アカウント不要 ・ 通常1日以内に回答されます

まだ質問はありません。ODIN ファイルについて最初の質問をしてみましょう。

よくある質問

.odinファイルはどうやって開けばいいですか?
通常の意味で開くことはできません。ファイルはLockyランサムウェアによって暗号化され、内容はスクランブルされています。使用可能なデータを取り戻す唯一の方法は、マルウェアを削除した後に、バックアップまたはシャドウコピーから元のファイルを復元することです。
.odinファイルを無料で復号できますか?
いいえ。Lockyの.odin亜種に対する無料または公開されている復号ツールはありません。AESキーはRSA-2048で保護され、攻撃者のサーバーに保持されているため、そのプライベートキーなしでの復号は不可能です。
.odinファイル自体は危険ですか?
暗号化された.odinファイル自体は不活性であり、それ自体で実行されたり拡散したりすることはありません。危険なのは、その存在がシステム上でLockyランサムウェアが実行されたことを証明している点です。そのため、すぐにマシンをスキャンしてクリーンアップする必要があります。
.odinファイルを復旧するために身代金を支払うべきですか?
セキュリティの専門家は支払わないようアドバイスしています。支払いは犯罪活動の資金源となり、有効なキーを受け取れる保証もありません。バックアップからの復元が推奨される道です。
なぜファイル名がランダムな文字に変更されたのですか?
Lockyは暗号化した各ファイルを 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin のような16進数の識別子にリネームし、元の名前を破棄します。これはこの亜種の通常の動作であり、どのファイルが何であったかを判別しにくくします。
OdinはLockyとは別のランサムウェアですか?
いいえ。名前に反して、.odinファイルはLockyが.odin拡張子を使用して生成したものです。コード分析により、以前の.zepto Locky亜種と98〜99%一致することが示されており、同じマルウェアファミリーであることが確認されています。

参考文献

1Wikipedia - Lockyen.wikipedia.org
2Bleeping Computer - Locky Ransomware now uses the .ODIN extensionwww.bleepingcomputer.com

さらに探索

データベース全体から

今週のトップ拡張子

1.AQQAQQ Instant Messenger File
2.CRDOWNLOADChrome Partial Download File
3.PARTPartial Download File
4.BINCD/DVD Disc Image (BIN/CUE)
5.EXEWindows Executable (Portable Executable)
6.RPMSGRestricted Permission Message
7.MDMarkdown Document
8.DATProgram Data File (generic)
9.NOMEDIAAndroid No-Media Marker File
10.TXTPlain Text File

関連する拡張子

.CRYPTWhatsApp Encrypted Message Database Backup
.SDOCOracle IRM Sealed Word Document
.AXXAxCrypt Encrypted File
.REMBlackBerry Encrypted Media Card File
.DLCDownload Link Container
.SECPGP Secret Key Ring File

無料ファイルツール

ブラウザで動作するファイル識別および画像変換ツール。すべてお使いのデバイス上で実行されます。

ツールボックスを開く

ファイル拡張子を A-Z で閲覧