CuuDuLieuMaHoa.com/ TRecovery by TUNGTEK
Zalo TUNGTEK
🎟️ Ticket #1326 · Ransomware Recovery · SQL Server / BRAVO

The joy of handing over a BRAVO database after encryption with .WEX

For some tickets, the most memorable moment is when the business application opens again, users verify their actual data and the customer says: “we can use it again”. Ticket #1326 was one such case, and it also showed how experience accumulated from Mallox helped TUNGTEK approach WEX with faster assessment and more effective recovery planning and validation.

9.97 GiBMDF sample analyzed
215Altered/encrypted regions recorded
~5%Affected byte-level scope
~95%Size outside encrypted regions
From Mallox to WEX: prior field experience helped TUNGTEK shorten assessment, reduce trial and error and focus early on recovery and validation of business data.
#TUNGTEK#CuuDuLieuMaHoa #WEX#WeaXor#Mallox #SQLServer#MDF#BRAVO
Case Study #1326 — BRAVO .WEX: successful handover of usable data
Case Study #1326 — BRAVO .WEX representative image. A square design for the full article, optimized for desktop and mobile display.
Contents
  1. The final moment of the ticket
  2. From Mallox experience to WEX
  3. Examining Case #1326
  4. RFC: 215 regions and the meaning of 5% / 95%
  5. Why might an MDF still have recovery prospects?
  6. Public recovery workflow
  7. Validation in the actual BRAVO application
  8. Threat Intelligence: WEX / WeaXor / Mallox
  9. IOCs for threat hunting
  10. SQL Server defense lessons
  11. References
01 · Results must be confirmed by users

The joy comes when data returns to work, beyond “the files have been copied”

In Ransomware Recovery, a readable MDF file does not mean the database is usable. Results matter when SQL Server structures are sufficiently stable, business data can be queried, and BRAVO and its users confirm that workflows work again.

“Congratulations and thanks to @TUNGTEK — Tùng Nguyễn and the whole team for recovering the data and reactivating BRAVO!”
Customer feedback during handover — identifying details withheld. Translated from Vietnamese.
Formal confirmation in the acceptance records: BRAVO examined the data and recorded it as “meeting the requirements for work use”; the handover covered BRAVO and file server data, with quality recorded as “meeting requirements and functioning normally”.
01A · From Mallox to WEX

Accumulated experience improves recovery efficiency

“We have a history of experience with Mallox — and that depth makes WEX a familiar technical challenge.”

In practical ransomware recovery for SQL Server, effectiveness comes from more than a tool or decryptor. It depends on quickly reading the current state, identifying impact patterns, understanding business data structures and prioritizing what brings the system back to a verifiable condition.

Earlier field cases involving Mallox / TargetCompany gave TUNGTEK valuable experience: how to examine files such as .mdf/.ldf, assess scattered damaged regions and understand dependencies between pages, metadata, allocation maps and business data, while recognizing that attaching a database does not establish successful recovery.

When facing .WEX, Ticket #1326 was therefore approached with existing expertise. Mallox experience shortened planning, improved RFC and brought early focus to the most valuable path: extraction → reconstruction → application validation in BRAVO.

“WEX is no longer a problem” in this case does not mean every WEX case is easy or recoverable. It means TUNGTEK’s experience made the challenge familiar enough to approach systematically, more quickly and efficiently than starting from zero.
Anonymized Ticket #1326 evidence: customer feedback, acceptance and BRAVO screenshots
Anonymized case evidence from Ticket #1326: customer feedback, handover and BRAVO data verification.

From experience to efficiency

Faster identification: look beyond extensions and prioritize impact patterns on SQL Server and actual data.

More focused RFC: measure affected regions and assess prospects through page/extent structure, beyond file status alone.

Fewer recovery iterations: preserve the source, work on copies and prioritize business data.

Purposeful validation: verify the final results in BRAVO with actual users.

02 · Ticket #1326

Technical case analysis: a large MDF with many scattered damaged regions

Anonymization note: customer and company names, identifiers and potentially identifying filenames have been replaced in this public article. The label ABC is a placeholder used for this case study, rather than the actual company name.

RFC sample details

Data type: Microsoft SQL Server / BRAVO.

Analyzed sample: B8R2_ABC.mdf.wex.

Exact size: 10,708,713,644 bytes ≈ 9.9733 GiB.

Altered/encrypted regions: 215 regions.

Byte-level estimate: ~5% affected, ~95% outside encrypted regions.

Recovery objective

RFC assessed high feasibility for implementing data extraction on working copy, without depending entirely on the attacker’s key.

The service objective was approximately 95–98% usable data, recognized only after actual business validation.

The recovery objective does not guarantee that 95–98% of every record is intact.

Technical summary image

One image with the technical context of Ticket #1326

The image below summarizes the case: BRAVO / SQL Server, a sample of B8R2_ABC.mdf.wex, 215 affected regions, approximately 95% of the size outside encrypted regions and results validated in the application before handover.

Detailed Ticket #1326 BRAVO WEX infographic
Square technical infographic for the full article. Potentially identifying company names and filenames have been replaced or anonymized.
03 · Recovery Feasibility Check

5% affected does not mean “only 5% of data lost” — nor is the other 95% immediately usable

For databases, damage location matters as much as size. A small encrypted region in metadata, allocation maps, page chains, indexes or other critical structures can prevent SQL Server from attaching the entire database. Conversely, scattered damage with mostly valid data pages can make extraction/reconstruction more feasible than waiting for a decryptor.

Ticket #1326 RFC illustration Approximately 95 percent outside encrypted regions and 5 percent affected, spread across multiple regions. RFC MAP · B8R2_ABC.mdf.wex Byte-level illustration — not the sample’s actual offset map ~95% outside encrypted regions ≈ 9.4746 GiB ~5% affected ≈ 0.4987 GiB 215 altered/encrypted regions recorded by RFC tungtek
Outside encrypted regions Affected regions ✦ Public illustration — actual offsets are withheld
04 · SQL Server internals

Why does page / extent structure offer extraction opportunities?

In SQL Server architecture, data files such as .mdf/.ndf are divided into page 8 KiB; an extent contains 8 consecutive pages, totaling 64 KiB. Data, indexes and metadata occupy different pages, so ransomware affecting scattered regions may leave many readable pages. This provides a basis for assessing extraction beyond “SQL Server cannot attach the database”. [5]

Surviving structures must be understood in relation to one another. An intact data page can still lose context when its page chain, allocation metadata, LOB pages or other dependencies are damaged. Readable bytes do not equal usable business data.
05 · Public methodology

Recovery is performed on copies of the original files

Case #1326 describes the workflow at a verifiable public level, while withholding TUNGTEK’s proprietary techniques, internal patterns and tools.

Preserve the current stateCreate a working copy; avoid attaching, repairing or overwriting the original source directly.
Map affected regionsAssess alteration patterns and surviving SQL Server structures.
Selective extractionRead accessible pages/extents, isolate errors and prioritize business data.
ReconstructionReconstruct in a clean SQL Server environment and handle data relationships where feasible.
ValidationVerify through SQL Server, BRAVO and actual workflows before acceptance.
RECOVERY FLOW · TICKET #1326 SOURCEPreserve RFC MAP215 regions EXTRACTPage / Extent REBUILDClean SQL VALIDATEActual BRAVO Principle: recover on working copies · prioritize business data · accept based on usability tungtek
06 · Handover & acceptance

Ticket #1326’s strongest evidence: validation in BRAVO itself

The case required the customer to verify recovered data directly on TUNGTEK’s server before acceptance. For BRAVO, verification involved coordinated temporary installation/licensing and the necessary procedures under the customer’s authorization.

Technical validation

The database must support stable queries in a clean SQL Server environment, beyond the existence of a file.

Business validation

Users / BRAVO representatives verify actual data; the findings provide the basis for handover and acceptance.

This is why TUNGTEK distinguishes between the proportion of usable structure/bytes and the proportion of genuinely usable business data.

Anonymized Ticket #1326 case evidence
Actual evidence: customer feedback, BRAVO screens and the handover/verification process.
Social summary of Ticket #1326
Visual summary: 9.97 GiB, 215 regions, ~95% outside encrypted regions and application validation.
The images have two roles: actual case evidence to establish credibility, and infographic to communicate the technical results quickly.
07 · Threat Intelligence

.WEX is a notable WeaXor/Mallox indicator, but the extension alone cannot establish a family

On 17 April 2025, LevelBlue SpiderLabs reported that WeaXor is a modified version of Mallox and that their collected samples append the suffix .wex to encrypted files. SpiderLabs also recorded C2 infrastructure, “RECOVERY INFO” ransom notes, Onion webchat and sample hashes. [1]

Within the Mallox/TargetCompany ecosystem, Unit 42 and SentinelOne recorded a focus on Internet-exposed Microsoft SQL Server / ODBC, including brute force against weak passwords, PowerShell/WMI after access, attempts to stop SQL services, removal of recovery mechanisms and, in some campaigns, data theft before encryption. [2] [3]

Trend Micro also lists .mdf, .sql, backup files and infrastructure formats among the extensions targeted by TargetCompany/Mallox samples, alongside stopping multiple SQL Server services. [4]

Classification for Ticket #1326: the filename *.mdf.wex strongly matches WeaXor/Mallox indicators described by SpiderLabs, but absolute attribution should not be claimed from the extension alone. Confirming a family requires additional comparison of ransom notes, malware samples/hashes, C2, endpoint logs, process trees and host artifacts.
WEX THREAT INTEL · PUBLIC EVIDENCE WeaXor Mallox revised variant extension: .wex Source: LevelBlue SpiderLabs Mallox / TargetCompany MS-SQL exposure / brute force PowerShell · WMI · service stop Unit 42 · SentinelOne · Trend Micro Ticket #1326 B8R2_ABC.mdf.wex Artifact match Attribution remains unconfirmed tungtek
Compact Ticket #1326 summary for social media
Square Lite version for social media: retains the outcome, core figures and Mallox → WEX message, directing readers to the full article.
08 · Indicators of Compromise

WeaXor IOCs published by SpiderLabs

The indicators below are public IOCs observed by LevelBlue SpiderLabs in the 2025 WeaXor campaign. They are not established as present in Ticket #1326 without comparing logs/malware samples. Use them for threat hunting, SIEM/EDR and retrospective checks.

TypeIOC / ArtefactNotes
Extension.wexAssociated with WeaXor by SpiderLabs.
Ransom noteRECOVERY INFOContains a victim key ID, webchat and email in the public description.
IPv4193.143.1[.]139C2 observed in WeaXor samples.
URL193.143.1[.]139/Ujdu8jjooue/biweax.phpDefanged to avoid accidental access.
Onionweaxorpemwzoxg5cdvvfd77p3qczkxqii37ww4foo2n4jcft3mytbpyd[.]onionWebchat/infrastructure recorded by SpiderLabs.
SHA-2567d1de2f4ab7c35b53154dc490ad3e7ad19ff04cfaa10b1828beba1ffadbaf1abPublic WeaXor sample.
SHA-256d682d5afbbbd9689d5f30db8576b02962af3c733bd01b8f220ff344a9c00abfdPublic WeaXor sample.
SHA-25640b75aa3c781f89d55ebff1784ff7419083210e01379bea4f5ef7e05a8609c38Public WeaXor sample.
SHA-2567f2319f4e340b3877e34d5a06e09365f6356de5706e7a78e367934b8a58ed0e7Public WeaXor sample.

Additional artifacts to hunt on SQL servers

Authentication: unusual failed SQL/remote-service logins, unexpected accounts or out-of-hours access.

Process: PowerShell, WMIC/WMI and shell/batch activity near the incident time.

Impact: stopping SQL services, deleting shadow copies or changing recovery settings.

Network: outbound connections to public IOCs or newly observed infrastructure before the incident.

Forensic: ransom notes and unexpected executables/scripts in TEMP, Desktop or data directories.

Log integrity: cleared Windows logs or interrupted telemetry.

09 · After recovery

Immediate priorities for SQL Server / ERP after .WEX

Reduce the attack surface

Avoid exposing SQL Server/1433 directly without a genuine need; prioritize VPN/ZTNA, IP allowlists and network segmentation.

Review RDP, ODBC, VPN, web administration and other exposed services — ransomware affiliates may change vectors.

Accounts & privileges

Remove weak passwords, shared accounts and unnecessary administrator rights; use MFA for remote access where supported.

Separate backup credentials from everyday domain/SQL production credentials.

Backups that can actually be restored

Maintain offline/immutable backups separate from production; regularly test restoration of both SQL Server and BRAVO.

A NAS sharing the server’s domain/credentials is not a complete ransomware-resistant backup.

Detection

Alert on unexpected SQL service stops, suspicious PowerShell/WMIC, shadow copy deletion or sharp increases in file renaming/writes.

Send important logs to independent storage for DFIR even if server logs are erased.

10 · TUNGTEK’s key message

Assess what ransomware changed before “repairing” original files

A ransomware extension does not necessarily mean every byte of a database became ciphertext. Nor can it be assessed by sight or renaming alone. Preserve the source, create a working copy, perform RFC and measure impact before choosing a recovery path.

TUNGTEK’s final goal goes beyond attaching the database: business data must be checked, compared and returned to use. Experience accumulated from Mallox is one foundation for TUNGTEK’s more efficient approach to WEX.
References

Threat intelligence & technical documentation

  1. LevelBlue SpiderLabs — “Proton66 Part 2: Compromised WordPress Pages and Malware Campaigns”, 17 April 2025. Identifies WeaXor as a modified Mallox variant, appending .wex, and publishes C2, Onion and SHA-256 indicators. Open source.
  2. Palo Alto Networks Unit 42 — “Threat Group Assessment: Mallox Ransomware”. Describes targeting of insecure MS-SQL, brute force, PowerShell, WMI, SQL service stops, shadow copy deletion and double extortion. Open source.
  3. SentinelOne — “Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises”, updated 27 April 2025. Describes RaaS, MS-SQL/ODBC exposure, brute force, PowerShell/WMIC and recent Mallox payloads. Open source.
  4. Trend Micro Threat Encyclopedia — TargetCompany/Mallox. Records .mdf, .sql and multiple infrastructure file formats as targets, along with stopping SQL-related services. Open source.
  5. Microsoft Learn — “Page and Extent Architecture Guide – SQL Server”. Pages are 8 KiB; an extent contains 8 consecutive pages, totaling 64 KiB. Open source.

Case data comes from Ticket #1326 internal records and acceptance documents. Customer identities, accounts, infrastructure, paths and sensitive technical details have been omitted or anonymized. Potentially identifying company names and filenames are replaced with placeholders such as ABC to protect the customer.

Need a rapid assessment of a ransomware-affected MDF/LDF?

TUNGTEK can perform RFC on sample data to assess impact, extraction prospects and a validation approach before deciding on full recovery.

TRecovery by TUNGTEK · CuuDuLieuMaHoa.com
Hotline/Zalo: 0963 509 115

Pay only for usable data. No assessment fee if you do not proceed.

View other case studies