HomeSecurityJPCERT shares tips for detecting ransomware attacks

JPCERT shares tips for detecting ransomware attacks

Japan 's Computer Emergency Response Center (JPCERT/CC) has shared tips for detecting attacks by various ransomware gangs based on entries in Windows event logs , providing early detection of ongoing attacks before they spread too far across a network.

See also: Storm-0501 hackers target hybrid cloud environments with ransomware

JPCERT ransomware

JPCERT/CC says the technique can be valuable when responding to ransomware attacks, and identifying the attack vector among the various possibilities is crucial for timely mitigation.

The investigation strategy proposed by JPCERT/CC covers four types of Windows event logs: application, security, system, and installation logs. These logs often contain traces left behind by ransomware attacks that could reveal the entry points used by attackers andtheir “digital identity.”

Here are some examples of ransomware traces highlighted in the organization's report:

Conti : Identified by many logs related to Windows Restart Manager (event IDs: 10000, 10001). Similar events are generated by Akira, Lockbit3.0, HelloKitty, Abysslocker, Avaddon, Bablock , and other malware created by the leaked Lockbit and Conti cryptographers. Phobos: Leaves traces when deleting system backups (event IDs: 612, 524, 753). Similar logs are generated by 8base and Elbie . Midas: Changes network settings to spread infection, leaving event ID 7040 in the logs. BadRabbit: Records event ID 7045 when installing an encryption component. Bisamware: Records the start (1040) and end (1042) of a Windows Installer transaction .



See also: New Linux variant of Mallox ransomware is based on Kryptina code

JPCERT shares tips for detecting ransomware attacks

JPCERT/CC also notes that seemingly unrelated ransomware variants such as Shade, GandCrab, AKO, AvosLocker, BLACKBASTA, and Vice Societyleave behind very similar traces (event IDs: 13, 10016).

Both errors are caused by a lack of permissions when accessing COM applications to delete Volume Shadow Copies, which ransomware typically deletes to prevent easy recovery of encrypted files.

It's important to note that no detection method should be taken as a guarantee of adequate ransomware protection, but monitoring for specific logs can be a game-changer when combined with other measures to detect attacks before they spread too far across a network.

JPCERT/CC notes that older ransomware strains like WannaCry and Petya left no traces in Windows logs, but the situation has changed in modern malware, so the technique is now considered effective.

See also: Ransomware gangs abuse Azure Storage Explorer

Ransomware attacks are a growing threat in cyberspace, targeting individuals and organizations around the world. In a typical ransomware attack, attackers infiltrate a network, install malware, and encrypt critical data, demanding a ransom to restore access. These attacks can cause significant financial losses and disrupt critical operations. protection includes keeping software up to date, educating users to recognize suspicious emails, and regularly backing up data, reducing the risk of serious consequences.

Source: bleepingcomputer

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS