CLIENT RECOVERED .MDF FILES ENCRYPTED BY ARENA RANSOMWARE USING STELLAR’S HELP
The client, Shri Bankey Behari Foods, an ISO 22000:2005 certified company located in Delhi, had recently suffered the Arena Ransomware attack on their Windows Server machine. The server computer therewith lost all its database files due to encryption.
The Toshiba hard disk drive of the virus infected computer has the model number AL14SEB120N, serial number 95R0A05RF02C, and hard disk space of 1.2 Terabyte.
The company processes, supplies, and exports Syrups, Chutneys, Tomato Ketchup, Jams, Pickles, Pepper, and Salt. All the information related to their products are maintained in SQL Server 2005 in .mdf file format, which was encrypted by the Arena ransomware.
WHAT IS ARENA RANSOMWARE?
Arena ransomware is an encryption virus that encrypts victim’s files using advanced encryption algorithm. The virus infiltrates victim’s computer and encodes all files with .arena file extension. Once the virus completes scanning of the infected system and corrupting its data, the ransomware then leaves a ransom note in a text file. The note has instructions on how to pay the ransom to the attacker, who then provides the tool with decryption key to recover the encrypted data.
INTELLIGENT ACTION BY CLIENT
HELP FROM STELLAR DATA RECOVERY – NEHRU PLACE
Our representative at Stellar Data Recovery–Nehru place branch received a call from the company. The whole incident was explained to our executive, who then requested to send the arena ransomware affected drive to the service center.
A FLAWLESS RECOVERY FROM ARENA RANSOMWARE
After receiving the HDD, our technical expert checked it and found all data in encrypted format. In order to safeguard the drive and its data due to overwriting in the recovery process, the assigned expert created a clone of the entire hard disk drive. Subsequently, the expert decoded the encryption using Stellar’s proprietary tools and techniques to recover the data in its actual format.
After recovery, the client was very happy and satisfied.