Japan 's Computer Emergency Response Center (JPCERT/CC) has shared tips for detecting attacks by various ransomware gangs based on entries in Windows event logs , providing early detection of ongoing attacks before they spread too far across a network.
See also: Storm-0501 hackers target hybrid cloud environments with ransomware

JPCERT/CC says the technique can be valuable when responding to ransomware attacks, and identifying the attack vector among the various possibilities is crucial for timely mitigation.
The investigation strategy proposed by JPCERT/CC covers four types of Windows event logs: application, security, system, and installation logs. These logs often contain traces left behind by ransomware attacks that could reveal the entry points used by attackers andtheir “digital identity.”
Here are some examples of ransomware traces highlighted in the organization's report:
Conti : Identified by many logs related to Windows Restart Manager (event IDs: 10000, 10001). Similar events are generated by Akira, Lockbit3.0, HelloKitty, Abysslocker, Avaddon, Bablock , and other malware created by the leaked Lockbit and Conti cryptographers. Phobos: Leaves traces when deleting system backups (event IDs: 612, 524, 753). Similar logs are generated by 8base and Elbie . Midas: Changes network settings to spread infection, leaving event ID 7040 in the logs. BadRabbit: Records event ID 7045 when installing an encryption component. Bisamware: Records the start (1040) and end (1042) of a Windows Installer transaction .
See also: New Linux variant of Mallox ransomware is based on Kryptina code

JPCERT/CC also notes that seemingly unrelated ransomware variants such as Shade, GandCrab, AKO, AvosLocker, BLACKBASTA, and Vice Societyleave behind very similar traces (event IDs: 13, 10016).
Both errors are caused by a lack of permissions when accessing COM applications to delete Volume Shadow Copies, which ransomware typically deletes to prevent easy recovery of encrypted files.
It's important to note that no detection method should be taken as a guarantee of adequate ransomware protection, but monitoring for specific logs can be a game-changer when combined with other measures to detect attacks before they spread too far across a network.
JPCERT/CC notes that older ransomware strains like WannaCry and Petya left no traces in Windows logs, but the situation has changed in modern malware, so the technique is now considered effective.
See also: Ransomware gangs abuse Azure Storage Explorer
Ransomware attacks are a growing threat in cyberspace, targeting individuals and organizations around the world. In a typical ransomware attack, attackers infiltrate a network, install malware, and encrypt critical data, demanding a ransom to restore access. These attacks can cause significant financial losses and disrupt critical operations. protection includes keeping software up to date, educating users to recognize suspicious emails, and regularly backing up data, reducing the risk of serious consequences.
Source: bleepingcomputer
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
