Wat is het ADAME-bestandsformaat?
Een .adame-bestand is een gewoon bestand, zoals een document of foto, dat is versleuteld door de Adame-ransomware. Adame is een variant van de Phobos-ransomwarefamilie, voor het eerst gedocumenteerd in 2019 door onderzoekers Amigo-A en Michael Gillespie. Het maakt deze bestanden niet met opzet aan; het gijzelt bestanden die u al heeft.
Wanneer de malware wordt uitgevoerd, hernoemt deze elk slachtofferbestand naar een lang patroon dat de oorspronkelijke naam, een uniek ID, een e-mailadres van de aanvaller tussen haakjes en het achtervoegsel bundelt. Een bestand met de naam report.pdf wordt iets als report.pdf.id[1E857D00-2275].[[email protected]].adame. Onder de motorkap versleutelt Phobos de bestandsgegevens met AES-256 met behulp van een willekeurige sleutel per bestand, en verpakt die sleutel vervolgens met een openbare RSA-1024-sleutel die in de malware is ingebakken. Grote bestanden worden slechts gedeeltelijk versleuteld om de aanval te versnellen. Er worden twee losgeldberichten, info.hta en info.txt, achtergelaten om de betalingseis toe te lichten.
Beveiliging & veiligheid
RISICO: HIGHThe .adame extension is the direct result of an active ransomware infection. The encrypted files themselves are inert data, but their presence means the Adame/Phobos malware ran on the machine and may still be present. Phobos strains delete shadow copies, disable recovery, and can spread across network shares and RDP connections. Isolate the machine from the network, run a reputable anti-malware scan to remove the payload, and restore data only from a clean backup. Do not pay the ransom; there is no guarantee of recovery and it funds further attacks.
Formaatdetails
in een notendop- Adame (Amnesia) ransomware - An older, separate ransomware based on the Amnesia/Globe Imposter family also appended
.adame. It is distinct from the dominant Phobos-based Adame and was documented in earlier 2019 removal guides.
Programma's die ADAME-bestanden openen
.adame extension. .adame file and a ransom note to confirm the exact ransomware family and learn whether any decryption help is currently listed. .adame copy. Technische details
diepe specificaties| Encoding | AES-256 symmetric encryption of file data; per-file random key and IV |
| Container | Original file wrapped with appended encrypted payload |
| Encryption | Hybrid cryptosystem: file bytes encrypted with AES-256, and the AES key encrypted with RSA-1024 using a hardcoded public key, then stored at the end of the file. Large files are only partially encrypted in selected segments to speed up the attack. |
| Typical size | Slightly larger than the original file due to the appended encrypted key block and metadata |
| Structure | Encrypted original content followed by an RSA-protected key blob. The filename is rewritten to pattern <original>.id[<victim-id>].[<email>].adame, for example document.pdf.id[1E857D00-2275].[[email protected]].adame. |
| Integrity | None; no recovery checksum is stored for the victim |
| Platforms | Windows |
| Notes | Dropped alongside two ransom notes: info.hta (pop-up HTML application) and info.txt. Contact addresses seen include [email protected], [email protected], [email protected] and [email protected]. Phobos deletes shadow copies and disables recovery to prevent restoration. No free decryptor exists for the Phobos-based Adame variant. |
| Uitgebracht | 2019 |
ADAME conversies
Community V&A
gevraagd door gebruikersNog geen vragen - wees de eerste om iets te vragen over ADAME-bestanden.
Veelgestelde vragen
Hoe open ik een .adame-bestand?
Is er een gratis decryptor voor .adame-bestanden?
Moet ik het losgeld betalen om mijn bestanden te herstellen?
Kan ik .adame-bestanden herstellen door ze te hernoemen?
.adame-extensie decodeert niets; de bytes zijn nog steeds versleuteld met AES-256. Hernoemen verandert alleen het label, niet de inhoud.