Что такое формат файла GDCB?
Файл .gdcb - это документ, фотография или другой файл, зашифрованный первой версией программы-вымогателя GandCrab. Когда вредоносное ПО запускается, оно шифрует содержимое файла и добавляет .GDCB в конец имени, поэтому budget.xlsx превращается в budget.xlsx.GDCB. Оно также оставляет записку с требованием выкупа под названием GDCB-DECRYPT.txt в каждой затронутой папке.
GandCrab появился в конце января 2018 года и распространялся через набор эксплойтов RIG. Версия 1 шифровала файлы с помощью AES-256 и защищала ключ открытым ключом RSA-2048, после чего требовала оплату в криптовалюте Dash через сайт в сети Tor. Только версия 1 использовала расширение .GDCB; более поздние версии перешли на расширения .CRAB и .KRAB.
Безопасность и защита
РИСК: HIGHA .gdcb file itself is inert encrypted data, but its presence means a machine was compromised by GandCrab ransomware. The malware executable that created it is dangerous and may still be active, so disconnect the device, remove the infection with an anti-malware tool, and only then decrypt. Never pay the Dash ransom; a free decryptor exists for GandCrab v1.
Детали формата
в двух словахПрограммы, открывающие файлы GDCB
Технические подробности
глубокая спецификация| Encoding | Original file contents encrypted with AES-256 (Cipher Block Chaining) in GandCrab v1; the per-file/per-machine AES key is wrapped with an embedded RSA-2048 public key held by the attackers. |
| Byte order | Not applicable (encrypted ciphertext) |
| Container | The original file is overwritten/replaced with ciphertext and renamed with a trailing .GDCB extension (e.g. photo.jpg becomes photo.jpg.GDCB). |
| Encryption | AES-256 (CBC) for file data plus RSA-2048 to protect the AES key; later GandCrab versions (v4, v5) switched file encryption to Salsa20. |
| Typical size | Roughly the same as the original file plus a small amount of padding/metadata. |
| Structure | Renamed copy of the victim's file containing encrypted bytes; a plain-text ransom note named GDCB-DECRYPT.txt is dropped into every folder that has encrypted files. |
| Integrity | None exposed publicly |
| Platforms | Windows |
| Notes | GandCrab v1 was the first GandCrab release and the only one that used the .GDCB extension. It spread from late January 2018 through the RIG exploit kit via the Seamless malvertising campaign, and demanded payment in Dash cryptocurrency through a Tor payment site. Bitdefender, working with Europol and Romanian police, released a free decryptor for v1 in February 2018. |
| Ransom Note | GDCB-DECRYPT.txt |
| Malware Family | GandCrab (Ransom.GandCrab) |
| Выпущен | January 2018 |
Конвертации GDCB
Вопросы и ответы сообщества
спрошено пользователямиВопросов пока нет - станьте первым, кто спросит о файлах GDCB.