Agent-based backup of Windows, Linux, Max, AIX and Solaris machines.
Post Reply
aweber3
Lurker
Posts: 1
Liked: never
Joined: Jun 28, 2023 8:36 am
Full Name: Alois Weber
Contact:

Ransomware encrypted or NOT encrypted? Magic header...

Post by aweber3 »

Hi there at veeam forum, we had an encryption process by ryuk malware some times ago. Because of an strange reason, the big backup files do not have a ending .ryuk and in a hexeditor opened, they seems not to be encrypted, maybe partly because i can read some text there like xml tags.

In all the directories for the jobs, there is one .vbm-File - encrypted with ending .ryk- but one .vbk file (seems to be not encrypted, do not have the ryk-suffix) and some .vib-Files without ryk-suffix, too.

The .vbk-file and the .vib-files seems not to be encrypted, because, if i open this files in an hexeditor, i can read some things like xml-tags and so on.

But if i open the vbk in the veeam backup extraction utility, i see no recoverable machines, the listbox is empty.

My questions would be:
-how is the typical magic header of a vbk-file? the first, lets say, 1000 Bytes?
-do i need the vbm-file for recovery?
-is it possible to "repair" a backup file somehow?

Thanks.
Gostev
Chief Product Officer
Posts: 31561
Liked: 6725 times
Joined: Jan 01, 2006 1:01 am
Location: Baar, Switzerland
Contact:

Re: Ransomware encrypted or NOT encrypted? Magic header...

Post by Gostev »

Hi, Alois.

Unfortunately, we will not be able to assist you with the recovery over forum posts nor are we able to share the requested backup file format information publicly.

Kindly contact our Customer Support, they have the dedicated SWAT team specializing on assisting our customers in recovering from ransomware attacks. They should be able to salvage some data from unencrypted parts of backup files, as long as at least some metadata banks have survived.

To share some good news, VBM file is not essentials for recovery as it's just a metadata cache... VBK and VIB files are what matters.

Thanks and good luck!
Post Reply

Who is online

Users browsing this forum: No registered users and 8 guests