Cybersecurity Incident Response · Data Recovery · Forensics
Ransomware response experts who get your data back
SheMo Noransom specializes in ransomware decryption, data recovery and forensic attribution, covering LockBit, Phobos, Mallox, TellYouThePass and other major families plus dedicated Silver Fox trojan response, with 24/7 remote and on-site incident response nationwide.
If you have been hit, isolate affected systems immediately. Do not reboot, reformat or attempt decryption yourself. It can cause irreversible damage.
Manufacturing·Kingdee K/3 · SQL Server
- Family
- MalloxAnalyzing.mallox
- Affected hosts
- 8
- Encrypted files
- 26,430
Response progress
8%- Isolation & evidence captureActive
- Family identification & triagePending
- Data recoveryPage-level SQL Server datafile repairPending
- Attribution & hardeningPending
24/7
Emergency response
300+
Ransomware families covered
1000+
Incidents resolved
Nationwide
Remote + on-site coverage
Services
The full chain of ransomware response
Identification, decryption and recovery, attribution and hardening. Each stage is owned by a dedicated engineer with a deliverable you can sign off on.
Ransomware Decryption
Identify the family first, then commit to a recoverable scope — without paying a ransom.
For organizations whose servers, databases or virtualization platforms have been encrypted: family identification, recoverability assessment and multi-path data extraction, with no ransom payment.
Incident Response
Round-the-clock intake: contain first, preserve evidence second, recover third.
Emergency handling while an incident is still spreading or the attacker may still have access: contain the blast radius, remove persistence, preserve evidence, and open a safe window for recovery.
Data Recovery
Recovery beyond decryption: backup repair, database repair and remnant extraction.
When direct decryption is not viable, we recover usable production data through backup and snapshot repair, file-level database repair, and extraction of unencrypted remnants and fragments.
Attack Forensics & Attribution
Establish the intrusion path, timeline and impact — in a report usable for police reporting and compliance.
Reconstruct the attack timeline and entry point from logs, images and memory evidence, assess whether data was exfiltrated, and deliver a traceable forensic report.
Security Hardening
Close the handful of paths attackers actually use: exposure, weak credentials, patches, privilege, backups.
Hardening built around the intrusion paths ransomware actually uses: shrink internet exposure, fix credentials and remote access, patch high-risk flaws, reduce privilege, and rebuild backups that cannot be deleted.
Our process
A standard process with a deliverable at every step
The process is transparent. You get the assessment first and decide whether to continue.
Intake & containment
We answer 24/7 and immediately walk you through isolating systems and preserving evidence so the encryption stops spreading.
Sample analysis & family identification
We analyze encrypted samples and the ransom note to confirm the family, the variant and the encryption characteristics.
Recoverability assessment & quote
Weighing decryptors, backups, snapshots and database structure, we document what can realistically be recovered and quote a firm price.
Recovery & business validation
We recover in business-priority order, verify data integrity item by item and validate the systems together with your teams.
Attribution & hardening
We reconstruct the intrusion path, deliver a forensic report, close the entry point and harden accounts and backups against reinfection.
Intake & containment
We answer 24/7 and immediately walk you through isolating systems and preserving evidence so the encryption stops spreading.
Sample analysis & family identification
We analyze encrypted samples and the ransom note to confirm the family, the variant and the encryption characteristics.
Recoverability assessment & quote
Weighing decryptors, backups, snapshots and database structure, we document what can realistically be recovered and quote a firm price.
Recovery & business validation
We recover in business-priority order, verify data integrity item by item and validate the systems together with your teams.
Attribution & hardening
We reconstruct the intrusion path, deliver a forensic report, close the entry point and harden accounts and backups against reinfection.
Common scenarios
These are the systems that get encrypted
Open the matching scenario for typical symptoms, recovery paths and the mistakes that make things worse.
- Microsoft SQL Server
SQL Server Database Encrypted by Ransomware
When SQL Server .mdf / .ldf files are encrypted, the ERP and inventory systems built on them — Yonyou U8, Kingdee K/3, Guanjiapo, Suda — stop completely. This page covers evidence handling, how we judge whether page-level repair is viable, and the conditions for backup-plus-log restore.
- VMware ESXi
ESXi / Hyper-V Virtualization Encrypted by Ransomware
Hypervisor-level encryption causes the widest blast radius of any ransomware event: dozens of production VMs go dark within an hour or two. This page covers what Linux ESXi encryptors actually do — shut down guests, encrypt vmdk, delete snapshots — the recovery value of flat disk files, and how Hyper-V and Proxmox cases differ.
- Synology DSM
Synology NAS Encrypted by Ransomware
Synology incidents come in two shapes: the NAS itself is compromised (DSM exposed to the internet, accounts brute-forced), or an infected Windows host on the LAN encrypts it over SMB. The handling and recovery paths differ completely. This page explains how to tell them apart and what Btrfs snapshots and Hyper Backup can actually do.
- 用友 U8 / NC / 畅捷通 T+
ERP System Encrypted by Ransomware
An encrypted ERP is not a single broken database: the application tier, database, attachments and interfaces fail together, halting finance, procurement, production and inventory. This page covers the vulnerability entry points seen in Chinese ERP deployments, the order in which the four tiers are recovered, and how account sets are reconciled at sign-off.
- Veeam Backup & Replication
Backups Deleted or Destroyed
Modern ransomware follows a fixed sequence: destroy the backups, then encrypt the data — deleting shadow copies, encrypting repositories, disabling jobs, and exploiting backup software flaws to steal credentials. This page covers what can still be inventoried once backups fail, why replication propagates encrypted files off-site, and what offline and immutable copies are really worth.
- Active Directory 域控制器
Domain Controller Compromise and Estate-Wide Encryption
A compromised domain controller hands the attacker a legitimate administrator identity, allowing an encryptor to be pushed to every host at once through Group Policy or remote execution. This page covers how such incidents present, the correct order for Active Directory recovery, and how to decide between cleanup and full rebuild.
Threat library
Identify the family, then decide how to recover
Profiles of the families prevalent in China and the globally active ones, each with identification markers and recoverability.
LockBit
.abcd .lockbit
Some versions decryptablePhobos
.phobos .eking
Free decryptor availableMallox
.mallox .malox
Some versions decryptableTellYouThePass
.locked .locked1
No public decryptorBeijingCrypt
.beijing .360
No public decryptorMakop
.makop .mkp
No public decryptorWeaxor
.rox .weax
No public decryptorAkira
.akira .powerranges
Some versions decryptable
Why us
Professional, compliant, verifiable
We only commit to what we can deliver, and we tell you the assessment as it is.
We never pay the ransom
We do not pay ransoms and do not negotiate with attackers. Recovery comes from decryptors, backups and snapshots, database repair and fragment reconstruction.
Forensic reports you can file
We preserve the evidence chain throughout and deliver incident and attribution reports suitable for internal audit, insurance claims and regulatory filings.
24/7 remote and on-site
We take calls every day of the year and can engage remotely within tens of minutes. When the case is complex or physical storage is involved, engineers come on site.
Core systems come back first
Recovery is sequenced by business impact, bringing production and finance systems back online before secondary data.
Case studies
How similar incidents were recovered
Response records by industry and ransomware family, with the timeline and what was recovered.
- Case study
Medusa encrypts a digital asset platform's operations database
Medusa encrypted the SQL Server backend and file server of a digital asset service provider, appending .MEDUSA, while its leak site ran a countdown threatening to publish KYC material. Cold wallets stayed offline and untouched; core data was recovered through page-level repair and log merging, with exposure scoping delivered in parallel.
- Case study
BrzCrypt encrypts an e-commerce agency's ERP database and NAS share
A SQL Server instance shared by two ERP account sets, together with a mapped NAS share, was encrypted by BrzCrypt and order processing stopped. NAS snapshot rollback plus page-level extraction restored the core data, and the exposed 3389 port was closed.
- Case study
Makop encrypts a university research group's Synology NAS
A lab's Synology NAS, exposed to the internet with weak credentials, was encrypted by Makop, affecting years of research data. Recovery layered NAS snapshots, local copies on workstations and remnant extraction.
FAQ
The questions people ask first
Recoverability, the ransom, timelines and pricing. Start here.
We just found our files encrypted — what is the first thing to do?
Three things, and the order matters more than the speed.
- Isolate. Unplug the affected hosts or isolate their switch ports, and cut every connection to shared drives, virtualization platforms, backup servers and external disks. Isolate, but do not power off or shut down.
- Stop. No reboot, no reinstall, no formatting, no disk check or repair utilities, and no immediate full-disk antivirus cleanup.
- Preserve. Keep the original ransom note, keep encrypted samples, keep firewall and VPN logs, and pause every automated backup or sync job that could overwrite data.
Then make the call. A great deal of irreversible data loss is caused not by the malware but by the rescue attempts made in the hours after discovery.
Why do you keep saying not to reboot?
Rebooting has several consequences that are hard to undo:
- Memory evidence disappears. Some families keep key material or decryption-related structures in memory; once the host is powered down that content is gone, and forensics loses a key source.
- Encryption may continue or accelerate. Some encryptors set themselves to run at startup, so a reboot triggers encryption of whatever is left.
- System writes overwrite remnants. Boot writes logs, temporary files and the page file, potentially overwriting unencrypted remnant data that was still extractable.
- Disk self-check rewrites structures. After an unclean shutdown the system may automatically run a disk check, rewriting filesystem structures and further reducing recoverability.
The right move is to keep the power on and pull the network, then wait for a professional judgement.
Should we delete the ransom note and clean the malware first?
Not yet. The ransom note is one of the most direct inputs to family identification — the filename pattern, wording, contact format and ID encoding all feed into it, and identifying the family and version is what determines whether a decryption path exists at all.
A full antivirus cleanup should also wait. Cleanup can remove key files, configuration files, the note itself and samples of the attacker's tooling — which are both identification inputs and critical forensic evidence. In some cases what gets deleted is precisely the material recovery depended on.
The right order is: isolate, preserve evidence, then eradicate under professional guidance. If your antivirus has already quarantined files, keep the quarantine record and do not empty the quarantine.
The note sets a deadline — should we at least make contact?
We advise against making contact and we do not make it on your behalf. Deadlines, price increases and limited-time discounts are standard scripts designed to create time pressure and push victims past assessment straight into a transaction.
In practice:
- making contact confirms you are a staffed, funded target, which can raise the price and invite further pressure;
- payment does not guarantee a working decryptor, nor that stolen data is deleted;
- moving funds to overseas attackers carries its own compliance exposure.
A better use of that time is inventorying data sources: backups, storage snapshots, hypervisor snapshots, local copies on endpoints, historical exports. In a significant share of cases these overlooked sources are what recovery ultimately rests on.
How can we tell whether encryption is still spreading?
A few signals help:
- New encrypted files. Watch a directory on an already-isolated host; if extensions keep appearing, a process is still running locally.
- Hosts falling one after another. Ransom notes appearing on different machines at different times usually means the actor is still moving through the network rather than having deployed once.
- Anomalous account activity: unfamiliar logons on domain controllers, bulk policy pushes, new scheduled tasks.
- Backup jobs terminating unexpectedly, shadow copies being deleted, antivirus being disabled.
While any of these persists, treat the incident as ongoing: widen isolation, disable suspicious accounts, rotate privileged credentials, and do not return restored systems to the production network until eradication is complete — being encrypted again after a restore is the most common and most avoidable second loss.