Data recovery and disk repair questions and discussions related to old-fashioned SATA, SAS, SCSI, IDE, MFM hard drives - any type of storage device that has moving parts
Post a reply

FARGO (TargetCompany) OR Mallox Ransomware Recovery

May 19th, 2023, 4:52

Guys
Is there any Solution for this sophisticated decryption ? This variant targets vulnerable SQL servers .
One of my customer wants to decrypt SQL MDF file. I have read that some file types can be repaired , don't know whether it is possible for this variant.
Has anyone any solution . Pls. PM cost of recovery as well so as to get customer approval.
Thanks
Attachments
Screenshot 2023-05-19 015239.png

Re: FARGO (TargetCompany) OR Mallox Ransomware Recovery

June 17th, 2023, 12:25

For Ransomware, best address is bleepingcomputer.com/forums

Re: FARGO (TargetCompany) OR Mallox Ransomware Recovery

June 17th, 2023, 13:29

I have read that some file types can be repaired


Some times repair is an option if a file is only partially encrypted. Repair then entails getting rid of encrypted data and make remaining non encrypted data viewable, playable etc.. If encrypted entirely, decryption is only option.

Example, here it turned out GlobeImposter does not encrypt entire file: https://youtu.be/rB5vo02SjD8.
Here PayFast or Zeppelin does not encrypt entire file: https://youtu.be/0gAhaAKshYw
Or STOP DJVU: https://youtu.be/ouSTB6Rg10g

I have no idea about Fargo though, never encountered it.

It does of course depend on type of data if repair is feasible and even desirable.

Quick hint could be to look at file entropy: IF entropy 8.00 bits/byte likely entire file is encrypted.

Re: FARGO (TargetCompany) OR Mallox Ransomware Recovery

June 17th, 2023, 16:25

TargetCompany/Mallox does not encrypt entire file.

Re: FARGO (TargetCompany) OR Mallox Ransomware Recovery

June 18th, 2023, 11:48

it's listed as decrypted here

https://www.nomoreransom.org/en/decryption-tools.html

Re: FARGO (TargetCompany) OR Mallox Ransomware Recovery

June 19th, 2023, 4:10

Yeah, that's for an old version, it won't work for newer infections.
Post a reply