The joy of handing over a BRAVO database after encryption with .WEX
For some tickets, the most memorable moment is when the business application opens again, users verify their actual data and the customer says: “we can use it again”. Ticket #1326 was one such case, and it also showed how experience accumulated from Mallox helped TUNGTEK approach WEX with faster assessment and more effective recovery planning and validation.
- The final moment of the ticket
- From Mallox experience to WEX
- Examining Case #1326
- RFC: 215 regions and the meaning of 5% / 95%
- Why might an MDF still have recovery prospects?
- Public recovery workflow
- Validation in the actual BRAVO application
- Threat Intelligence: WEX / WeaXor / Mallox
- IOCs for threat hunting
- SQL Server defense lessons
- References
The joy comes when data returns to work, beyond “the files have been copied”
In Ransomware Recovery, a readable MDF file does not mean the database is usable. Results matter when SQL Server structures are sufficiently stable, business data can be queried, and BRAVO and its users confirm that workflows work again.
“Congratulations and thanks to @TUNGTEK — Tùng Nguyễn and the whole team for recovering the data and reactivating BRAVO!”
Accumulated experience improves recovery efficiency
“We have a history of experience with Mallox — and that depth makes WEX a familiar technical challenge.”
In practical ransomware recovery for SQL Server, effectiveness comes from more than a tool or decryptor. It depends on quickly reading the current state, identifying impact patterns, understanding business data structures and prioritizing what brings the system back to a verifiable condition.
Earlier field cases involving Mallox / TargetCompany gave TUNGTEK valuable experience: how to examine files such as .mdf/.ldf, assess scattered damaged regions and understand dependencies between pages, metadata, allocation maps and business data, while recognizing that attaching a database does not establish successful recovery.
When facing .WEX, Ticket #1326 was therefore approached with existing expertise. Mallox experience shortened planning, improved RFC and brought early focus to the most valuable path:
extraction → reconstruction → application validation in BRAVO.

From experience to efficiency
Faster identification: look beyond extensions and prioritize impact patterns on SQL Server and actual data.
More focused RFC: measure affected regions and assess prospects through page/extent structure, beyond file status alone.
Fewer recovery iterations: preserve the source, work on copies and prioritize business data.
Purposeful validation: verify the final results in BRAVO with actual users.
Technical case analysis: a large MDF with many scattered damaged regions
RFC sample details
Data type: Microsoft SQL Server / BRAVO.
Analyzed sample: B8R2_ABC.mdf.wex.
Exact size: 10,708,713,644 bytes ≈ 9.9733 GiB.
Altered/encrypted regions: 215 regions.
Byte-level estimate: ~5% affected, ~95% outside encrypted regions.
Recovery objective
RFC assessed high feasibility for implementing data extraction on working copy, without depending entirely on the attacker’s key.
The service objective was approximately 95–98% usable data, recognized only after actual business validation.
The recovery objective does not guarantee that 95–98% of every record is intact.
One image with the technical context of Ticket #1326
The image below summarizes the case: BRAVO / SQL Server, a sample of B8R2_ABC.mdf.wex, 215 affected regions, approximately 95% of the size outside encrypted regions and results validated in the application before handover.

5% affected does not mean “only 5% of data lost” — nor is the other 95% immediately usable
For databases, damage location matters as much as size. A small encrypted region in metadata, allocation maps, page chains, indexes or other critical structures can prevent SQL Server from attaching the entire database. Conversely, scattered damage with mostly valid data pages can make extraction/reconstruction more feasible than waiting for a decryptor.
Why does page / extent structure offer extraction opportunities?
In SQL Server architecture, data files such as .mdf/.ndf are divided into
page 8 KiB; an extent contains 8 consecutive pages, totaling 64 KiB. Data, indexes and metadata occupy different pages, so ransomware affecting scattered regions may leave many readable pages. This provides a basis for assessing extraction beyond “SQL Server cannot attach the database”.
[5]
Recovery is performed on copies of the original files
Case #1326 describes the workflow at a verifiable public level, while withholding TUNGTEK’s proprietary techniques, internal patterns and tools.
Ticket #1326’s strongest evidence: validation in BRAVO itself
The case required the customer to verify recovered data directly on TUNGTEK’s server before acceptance. For BRAVO, verification involved coordinated temporary installation/licensing and the necessary procedures under the customer’s authorization.
Technical validation
The database must support stable queries in a clean SQL Server environment, beyond the existence of a file.
Business validation
Users / BRAVO representatives verify actual data; the findings provide the basis for handover and acceptance.
This is why TUNGTEK distinguishes between the proportion of usable structure/bytes and the proportion of genuinely usable business data.


.WEX is a notable WeaXor/Mallox indicator, but the extension alone cannot establish a family
On 17 April 2025, LevelBlue SpiderLabs reported that WeaXor is a modified version of Mallox
and that their collected samples append the suffix .wex to encrypted files. SpiderLabs also recorded C2 infrastructure, “RECOVERY INFO” ransom notes, Onion webchat and sample hashes. [1]
Within the Mallox/TargetCompany ecosystem, Unit 42 and SentinelOne recorded a focus on Internet-exposed Microsoft SQL Server / ODBC, including brute force against weak passwords, PowerShell/WMI after access, attempts to stop SQL services, removal of recovery mechanisms and, in some campaigns, data theft before encryption. [2] [3]
Trend Micro also lists .mdf, .sql, backup files and infrastructure formats among the extensions targeted by TargetCompany/Mallox samples, alongside stopping multiple SQL Server services. [4]
*.mdf.wex strongly matches WeaXor/Mallox indicators described by SpiderLabs, but absolute attribution should not be claimed from the extension alone. Confirming a family requires additional comparison of ransom notes, malware samples/hashes, C2, endpoint logs, process trees and host artifacts.
WeaXor IOCs published by SpiderLabs
The indicators below are public IOCs observed by LevelBlue SpiderLabs in the 2025 WeaXor campaign. They are not established as present in Ticket #1326 without comparing logs/malware samples. Use them for threat hunting, SIEM/EDR and retrospective checks.
| Type | IOC / Artefact | Notes |
|---|---|---|
| Extension | .wex | Associated with WeaXor by SpiderLabs. |
| Ransom note | RECOVERY INFO | Contains a victim key ID, webchat and email in the public description. |
| IPv4 | 193.143.1[.]139 | C2 observed in WeaXor samples. |
| URL | 193.143.1[.]139/Ujdu8jjooue/biweax.php | Defanged to avoid accidental access. |
| Onion | weaxorpemwzoxg5cdvvfd77p3qczkxqii37ww4foo2n4jcft3mytbpyd[.]onion | Webchat/infrastructure recorded by SpiderLabs. |
| SHA-256 | 7d1de2f4ab7c35b53154dc490ad3e7ad19ff04cfaa10b1828beba1ffadbaf1ab | Public WeaXor sample. |
| SHA-256 | d682d5afbbbd9689d5f30db8576b02962af3c733bd01b8f220ff344a9c00abfd | Public WeaXor sample. |
| SHA-256 | 40b75aa3c781f89d55ebff1784ff7419083210e01379bea4f5ef7e05a8609c38 | Public WeaXor sample. |
| SHA-256 | 7f2319f4e340b3877e34d5a06e09365f6356de5706e7a78e367934b8a58ed0e7 | Public WeaXor sample. |
Additional artifacts to hunt on SQL servers
Authentication: unusual failed SQL/remote-service logins, unexpected accounts or out-of-hours access.
Process: PowerShell, WMIC/WMI and shell/batch activity near the incident time.
Impact: stopping SQL services, deleting shadow copies or changing recovery settings.
Network: outbound connections to public IOCs or newly observed infrastructure before the incident.
Forensic: ransom notes and unexpected executables/scripts in TEMP, Desktop or data directories.
Log integrity: cleared Windows logs or interrupted telemetry.
Immediate priorities for SQL Server / ERP after .WEX
Reduce the attack surface
Avoid exposing SQL Server/1433 directly without a genuine need; prioritize VPN/ZTNA, IP allowlists and network segmentation.
Review RDP, ODBC, VPN, web administration and other exposed services — ransomware affiliates may change vectors.
Accounts & privileges
Remove weak passwords, shared accounts and unnecessary administrator rights; use MFA for remote access where supported.
Separate backup credentials from everyday domain/SQL production credentials.
Backups that can actually be restored
Maintain offline/immutable backups separate from production; regularly test restoration of both SQL Server and BRAVO.
A NAS sharing the server’s domain/credentials is not a complete ransomware-resistant backup.
Detection
Alert on unexpected SQL service stops, suspicious PowerShell/WMIC, shadow copy deletion or sharp increases in file renaming/writes.
Send important logs to independent storage for DFIR even if server logs are erased.
Assess what ransomware changed before “repairing” original files
A ransomware extension does not necessarily mean every byte of a database became ciphertext. Nor can it be assessed by sight or renaming alone. Preserve the source, create a working copy, perform RFC and measure impact before choosing a recovery path.
Threat intelligence & technical documentation
-
LevelBlue SpiderLabs — “Proton66 Part 2: Compromised WordPress Pages and Malware Campaigns”, 17 April 2025. Identifies WeaXor as a modified Mallox variant, appending
.wex, and publishes C2, Onion and SHA-256 indicators. Open source. - Palo Alto Networks Unit 42 — “Threat Group Assessment: Mallox Ransomware”. Describes targeting of insecure MS-SQL, brute force, PowerShell, WMI, SQL service stops, shadow copy deletion and double extortion. Open source.
- SentinelOne — “Mallox Resurrected | Ransomware Attacks Exploiting MS-SQL Continue to Burden Enterprises”, updated 27 April 2025. Describes RaaS, MS-SQL/ODBC exposure, brute force, PowerShell/WMIC and recent Mallox payloads. Open source.
-
Trend Micro Threat Encyclopedia — TargetCompany/Mallox. Records
.mdf,.sqland multiple infrastructure file formats as targets, along with stopping SQL-related services. Open source. - Microsoft Learn — “Page and Extent Architecture Guide – SQL Server”. Pages are 8 KiB; an extent contains 8 consecutive pages, totaling 64 KiB. Open source.
Case data comes from Ticket #1326 internal records and acceptance documents. Customer identities, accounts, infrastructure, paths and sensitive technical details have been omitted or anonymized. Potentially identifying company names and filenames are replaced with placeholders such as ABC to protect the customer.
Need a rapid assessment of a ransomware-affected MDF/LDF?
TUNGTEK can perform RFC on sample data to assess impact, extraction prospects and a validation approach before deciding on full recovery.
TRecovery by TUNGTEK · CuuDuLieuMaHoa.com
Hotline/Zalo: 0963 509 115
Pay only for usable data. No assessment fee if you do not proceed.