ODIN ファイル形式とは?
.odinファイルは、Lockyランサムウェアによって暗号化された個人ファイルです。Lockyは2016年初頭に初めて出現したWindowsマルウェアファミリーで、ドキュメント、写真、データベース、アーカイブをロックし、その返還のために支払いを要求します。2016年9月頃、オペレーターは付加する拡張子を.zeptoから北欧の神にちなんだ.odinに変更しました。Fortinetの研究者は、.odinのコードが以前の.zeptoビルドと98〜99%同一であることを発見しており、これは新しいラベルを付けただけの同じマルウェアであることを示しています。
Lockyが実行されると、約400種類のファイルタイプをスキャンし、それぞれをAES-128で暗号化し、そのAESキーをRSA-2048暗号の中にロックします。その後、すべてのファイルを 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin のような16進数の識別子にリネームし、元の名前を破棄します。また、Windowsのシャドウボリュームコピーを削除し、_HOWDO_text.html や _HOWDO_text.bmp という名前の身代金要求ノート(ランサムノート)を配置します。.odinファイルが見つかるということは、コンピュータが感染したことを意味しており、珍しいファイル形式を所有しているわけではありません。
セキュリティと安全性
リスク: HIGHThe presence of .odin files means the computer was hit by active ransomware. The .odin files themselves are inert encrypted data and cannot execute, but they signal that Locky ran on the system, deleted shadow copies and may still be present. Never pay the ransom without expert advice, and treat the machine as compromised until it is fully cleaned and, ideally, wiped and rebuilt from a trusted backup.
形式の詳細
概要- Samsung Odin firmware package - The Odin flashing tool for Samsung Galaxy devices uses firmware files, but those are typically .tar or .tar.md5 archives rather than a .odin extension. Unrelated to the ransomware.
- ODIN application data - A handful of niche applications have used .odin for internal data or backup files. These are legitimate and unrelated to Locky.
ODIN ファイルを開くプログラム
.odin files themselves cannot be opened. .odin sample to confirm the exact ransomware family and whether any decryption is currently possible. 技術的詳細
詳細仕様| Encoding | AES-128 (ECB mode) file encryption with the AES key protected by RSA-2048 |
| Byte order | N/A (encrypted ciphertext) |
| Container | None; the original file is overwritten in place as raw ciphertext with a renamed filename |
| Encryption | RSA-2048 + AES-128. The AES session keys are generated server-side by the attacker's command-and-control infrastructure, so the private key needed for decryption never stays on the victim machine. |
| Typical size | Roughly the same size as the original encrypted file |
| Structure | The plaintext of a targeted document, image, database or archive is replaced by AES-128 ciphertext. The file is then renamed to a hexadecimal identifier of the form [8]-[4]-[4]-[4]-[12] followed by the .odin extension (for example 5FBZ55IG-S575-7GEF-2C7B-5B22862C2225.odin). The original name and extension are not preserved on disk. |
| Platforms | Windows |
| Notes | Locky's .odin variant targets roughly 400 to 460 file types across documents, databases, images and archives. It deletes Windows Shadow Volume Copies to block local recovery and drops ransom notes named _HOWDO_text.html, _HOWDO_text.bmp and _[2-digit-number]_HOWDO_text.html. It is delivered by spam email carrying WSF/JS script attachments or macro-laden Office documents that download an encrypted DLL and run it via rundll32.exe. Despite the name, victims are infected by Locky using the .odin extension, not a separate 'Odin' malware family; code comparison shows a 98-99% match with the earlier .zepto variant. |
| リリース日 | September 2016 |
ODIN の変換
コミュニティ Q&A
ユーザーからの質問まだ質問はありません。ODIN ファイルについて最初の質問をしてみましょう。