Home / Server Ransomware

Server Ransomware Recovery Bracknell

An estate that woke up encrypted needs a straight answer more than it needs a rescue story. No laboratory breaks modern encryption, so the work here is done on the ground the attacker left behind: snapshots that were missed, guests that were switched off, the interior of files too large to finish, and originals deleted rather than overwritten.

Priced from the hardware, not from the panic. From £500 + VAT for a server, NAS or array and £300 + VAT for a single drive, fixed in writing and settled before the bench starts.

// where an encrypted estate still holds data

The run was fast. Fast leaves gaps

Somebody with domain rights had a few hours, not a few weeks, and a few hours is nowhere near enough to encrypt a whole estate properly. Six gaps show up again and again on the servers that reach this bench from the parks along the A329M and the corridor out towards Slough and Reading.

Guests encrypted at the host rather than inside

A Hyper-V or VMware host presents each guest as one enormous file, and a VHDX or VMDK carrying a database can run to several hundred gigabytes. Writing a fresh cipher stream across a file that size takes real time, so most strains take the header, jump a long way forward, take another slice and move on. The untouched stretches in between are frequently where the database itself lives.

The backup that was reachable from the same account

Whatever was mapped as a share or bolted to the back of the server was visible to the process doing the encrypting, and it went the same way as everything else. The copies that survive a business-wide run are the ones that were physically unplugged, rotated off site or sitting on tape, and establishing which of those exists is the first question asked here.

Volume snapshots deleted in a hurry

Clearing shadow copies sits near the top of nearly every playbook and it usually succeeds. Usually is not always. Volumes the script never reached, a second server that was slower to fall, and appliances running their own snapshot schedule all come through intact more often than anyone expects once somebody with the right tools actually goes looking.

A share rewritten, an appliance never logged into

Where a Synology or QNAP unit was hit across SMB, the files inside the share were rewritten but nobody ever held the administrator login for the box itself. Its own snapshots live outside the share, out of reach of a mapped drive, and where the retention was sensible they are still sitting there waiting to be rolled back.

Anything that happened to be powered down

A test machine, a file server nobody got round to retiring, an appliance parked between projects. A guest that was not running when the host was hit keeps a clean disk, and those disks routinely hold the same records as the encrypted production copy, only some months older. Older beats unreadable in almost every case.

Originals deleted rather than overwritten

A great many strains read a file, write the encrypted version alongside it and then delete the source instead of writing over it in place. Deleted is not gone. The original contents stay on the volume until something else lands on top, which is the whole reason a hit server should be switched off and left alone rather than swept, patched and restored over.

// the honest part, before anything else

Nobody decrypts this, and firms that say they do are selling something else

Current ransomware uses ordinary, published cryptography, and by now it is usually implemented competently. AES with a key held by whoever ran the attack is not a lock that gets picked on a bench, in this laboratory or in any other. It is the same arithmetic that stands behind online banking, and it does not come with a service door for people who own clean rooms and imagers. Anybody who tells you otherwise is describing something that has not happened.

So it is worth looking hard at what a decryption service is actually offering. A small slice of the time it is a free tool published by a police force or a security researcher after a particular family's keys leaked, and you can download that yourself in about five minutes. Most of the rest of the time it is negotiation dressed up as engineering: the ransom is paid on your behalf, a margin is added, and the files come back as though a laboratory had done the work. Some businesses want that arranged for them. It is not what happens here, and it will not be sold to you as a technical achievement.

This bench will not pay anyone, will not act as an intermediary, and will not tell you that paying is the sensible course. That decision belongs to you, your board and your insurer, and none of the recovery work described below depends on which way you go. Report it to Action Fraud, tell your insurer early, and let the technical work run alongside.

What genuinely comes back

Everything recoverable after a serious incident falls into four groups, and the diagnostic exists to work out how much of each you have. Snapshots the attacker missed, on hosts, on volumes or inside an appliance. Guests and volumes that were not online at the time. The unencrypted interior of very large files, which on a virtual disk or a database means the bulk of it. And the remnants of deleted originals, still readable in unallocated space on a server that was shut down promptly rather than tidied up.

Put together, on a mid-sized estate, that is often a good deal more than the first morning suggests. It is also entirely dependent on what has been done since. Reinstalling the host over the top, running removal tools that write across free space, or restoring a partial backup onto the same volumes will each destroy exactly the material listed above, and every one of them is a normal thing for an IT team to try on the day.

// how a hit estate is worked, and what it costs

Nothing gets mounted, everything gets copied

Disks arriving from an incident go straight onto hardware imagers behind write blockers. No volume is mounted read-write at any stage, no repair is attempted on an original, and every image is hashed as it is taken so the copy can be shown to be a copy. All of the searching, carving and snapshot work then happens against those images, and your disks sit on a shelf untouched for the duration.

That approach costs a little more time than working on the originals and it buys two things worth having. The first is that nothing done here can make your position worse. The second is a documented chain of custody, from the moment the parcel is booked in to the moment the recovered data is handed back, with each image and each hash written down. Insurers ask for that. So does anyone who later has to explain to the ICO what was taken, and a firm that mounted the disks and started fixing things has nothing useful to hand over.

The first hour, if you are still in it

Take the estate off the network, including the wireless, rather than shutting machines down one by one from the console. Do not reboot anything that is still running, because the memory of a live host occasionally holds material worth capturing and a reboot throws it away. Do not run cleanup or removal tools yet; they write, and they write over precisely the deleted originals described above. Do not restore a backup onto the same volumes until somebody has looked at what is on them.

Keep the ransom note itself and two or three encrypted files of different sizes. Those identify the family, and the family determines whether the encryption was done in full or in slices, which is the single biggest factor in what can be pulled back. Photograph the screens. Write down the times. Then ring 0800 689 0668 during office hours, Mon–Fri 9:00am–5:30pm, before anybody starts putting things right.

Prices, terms and what to put in the parcel

Ransomware work is priced from the hardware in front of us rather than from the state anybody is in. A server, a NAS or an array starts at £500 + VAT and a single drive is £300 + VAT, with the figure fixed in writing once the free diagnostic closes, 2 working days after the media arrives. Unlike ordinary bench work this is settled before the job starts rather than at the end, for the plain reason that the outcome turns on what the attacker left behind rather than on anything we repair. Where you need the incident documented properly, forensic work with a written report is £800 + VAT, or £400 + VAT without one.

Send the disks, labelled with the bay each came out of, and not the chassis. Post them tracked to Guildford Data Recovery, Building 2, Ground Floor, Guildford Business Park, Guildford GU2 8XH, which is around forty minutes from Bracknell down the A322 and the A3 and next working day by post from anywhere in Berkshire, Surrey or London. Reception takes drop-offs during office hours if a director would rather hand it over. Every level and controller is covered by RAID recovery, appliances by NAS recovery, single workstations by the ransomware recovery page, and the bands behind all of it sit on data recovery cost.

// related pages

Nearby on this site

// straight answers on encrypted servers

Common questions

No, and neither can anybody else once a current strain has finished the job properly. The cipher is standard and the key sits with whoever ran the attack. What this bench does instead is find the data the run never reached: snapshots, guests that were switched off, the untouched interior of very large files, and originals that were deleted rather than written over.
That is not a call this laboratory will make for you or take any part in. We do not negotiate, we do not pass money to anyone and we do not offer a recommendation either way. Speak to your insurer and to Action Fraud early, and let the technical work run in parallel, because nothing recovered here depends on that answer.
From £500 + VAT for a server, a NAS or an array, and £300 + VAT where it comes down to one drive. Ransomware jobs are agreed and settled before the bench starts rather than at the end, because what is recoverable depends on the attacker rather than on any repair we carry out. The figure is fixed in writing after the free diagnostic, which closes 2 working days after the media lands.
Yes. Every disk is imaged behind a write blocker, every image is hashed, and the record runs from booking in to handover so the custody of the media is documented throughout. Where the incident needs a formal write-up, forensic work with a written report is £800 + VAT, or £400 + VAT for the analysis on its own.
The drives on their own, with the bay order marked on them, and the array kept together in one box. Chassis are heavy, expensive to post and almost never needed. Ring 0800 689 0668 first if the controller is an unusual one, and take a note of the make and model of the host before the disks come out.

Encryption cannot be undone. Gaps can be found.

Pull the estate off the network, leave the disks exactly as they are, and let somebody look at what the run never reached.

// getting the media to the bench

Booking a device in — what actually has to happen

Almost every job on this bench arrived as a parcel. Tracked, insured post is the gentlest way to move storage that is already in trouble, and a box handed in around Bracknell, Wokingham or Ascot is normally on the Guildford bench the next working day.

Is the storage still bolted into a machine — laptop, tower, iMac, MacBook, rack server, a DVR under the till? Free it first and send the bare unit. Stripping hardware is not something this lab does, though it is ten minutes' work for any repair shop on your high street. There is a single case with no way round it: memory chips soldered flat onto the mainboard, which is how Apple Silicon machines and certain ultrabooks are built. Where the storage cannot be unbolted, there is no parcel to make up.

  • Pick packaging that holds its shape — a rigid carton or a heavy padded mailer — and pack round the unit so it cannot shift in transit. Leave the caddy, the mains adaptor and the leads at home; none of them are wanted at this end.
  • Print the shipping and booking-in form (PDF), put your name and mobile on it along with a sentence describing how the fault started, and slip it in alongside the media.
  • Send it Special Delivery through the Post Office and it travels tracked and covered. A courier account of your own works just as well. The only thing that matters is that somebody signs for it at this end.
  • If you would sooner deliver it by hand, the Guildford reception on the address card takes devices over the counter, Mon–Fri 9:00am–5:30pm. Neither a Bracknell shopfront nor a pickup van exists — those are the two things we cannot offer.
// write this on the label

Guildford Data Recovery

Building 2, Ground Floor
Guildford Business Park
Guildford, GU2 8XH

↓ Print the shipping & booking-in form (PDF)

The name on the parcel wants to be Guildford Data Recovery. Driving it over from Bracknell is roughly forty minutes on the A322 then the A3; posting it costs you a stamp and a day. Either way, a message goes out to you as soon as it is logged onto the system, and two working days later the diagnostic is finished.

Unsure whether something should go in the box? Ring 0800 689 0668 while the lid is still open, or work through the free online diagnostic and let it tell you.