Co to jest format pliku ADAME?
Plik .adame to zwykły plik, taki jak dokument lub zdjęcie, który został zaszyfrowany przez ransomware Adame. Adame to szczep rodziny ransomware Phobos, po raz pierwszy udokumentowany w 2019 roku przez badaczy Amigo-A i Michaela Gillespiego. Nie tworzy on tych plików celowo; przejmuje pliki, które już posiadasz.
Gdy złośliwe oprogramowanie zostanie uruchomione, zmienia nazwę każdego zaatakowanego pliku na długi ciąg znaków, który łączy oryginalną nazwę, unikalny identyfikator ID, e-mail atakującego w nawiasach oraz sufiks. Plik o nazwie report.pdf zmienia się w coś w rodzaju report.pdf.id[1E857D00-2275].[[email protected]].adame. Pod maską Phobos szyfruje dane plików za pomocą AES-256 przy użyciu losowego klucza dla każdego pliku, a następnie zabezpiecza ten klucz kluczem publicznym RSA-1024 zaszytym w kodzie wirusa. Duże pliki są szyfrowane tylko częściowo, aby przyspieszyć atak. Tworzone są również dwie notatki z żądaniem okupu, info.hta i info.txt, które wyjaśniają żądania płatności.
Bezpieczeństwo
RYZYKO: HIGHThe .adame extension is the direct result of an active ransomware infection. The encrypted files themselves are inert data, but their presence means the Adame/Phobos malware ran on the machine and may still be present. Phobos strains delete shadow copies, disable recovery, and can spread across network shares and RDP connections. Isolate the machine from the network, run a reputable anti-malware scan to remove the payload, and restore data only from a clean backup. Do not pay the ransom; there is no guarantee of recovery and it funds further attacks.
Szczegóły formatu
w pigułce- Adame (Amnesia) ransomware - An older, separate ransomware based on the Amnesia/Globe Imposter family also appended
.adame. It is distinct from the dominant Phobos-based Adame and was documented in earlier 2019 removal guides.
Programy otwierające pliki ADAME
.adame extension. .adame file and a ransom note to confirm the exact ransomware family and learn whether any decryption help is currently listed. .adame copy. Szczegóły techniczne
specyfikacja| Encoding | AES-256 symmetric encryption of file data; per-file random key and IV |
| Container | Original file wrapped with appended encrypted payload |
| Encryption | Hybrid cryptosystem: file bytes encrypted with AES-256, and the AES key encrypted with RSA-1024 using a hardcoded public key, then stored at the end of the file. Large files are only partially encrypted in selected segments to speed up the attack. |
| Typical size | Slightly larger than the original file due to the appended encrypted key block and metadata |
| Structure | Encrypted original content followed by an RSA-protected key blob. The filename is rewritten to pattern <original>.id[<victim-id>].[<email>].adame, for example document.pdf.id[1E857D00-2275].[[email protected]].adame. |
| Integrity | None; no recovery checksum is stored for the victim |
| Platforms | Windows |
| Notes | Dropped alongside two ransom notes: info.hta (pop-up HTML application) and info.txt. Contact addresses seen include [email protected], [email protected], [email protected] and [email protected]. Phobos deletes shadow copies and disables recovery to prevent restoration. No free decryptor exists for the Phobos-based Adame variant. |
| Wydano | 2019 |
Konwersje ADAME
Pytania i odpowiedzi społeczności
pytania użytkownikówBrak pytań - bądź pierwszą osobą, która zapyta o pliki ADAME.
Najczęściej zadawane pytania
Jak otworzyć plik .adame?
Czy istnieje darmowy deszyfrator dla plików .adame?
Czy powinienem zapłacić okup, aby odzyskać pliki?
Czy mogę odzyskać pliki .adame poprzez zmianę ich nazwy?
.adame niczego nie deszyfruje; bajty są nadal zaszyfrowane algorytmem AES-256. Zmiana nazwy zmienia tylko etykietę, a nie zawartość.