JPCERT shares Windows Event Log tips to detect ransomware attacks

Share:

Japan’s Computer Emergency Response Center (JPCERT/CC) has shared tips on detecting different ransomware gang’s attacks based on entries in Windows Event Logs, providing timely detection of ongoing attacks before they spread too far into a network.

JPCERT/CC says the technique can be valuable when responding to ransomware attacks, and identifying the attack vector among various possibilities is crucial for timely mitigation.

Finding ransomware traces in Event Logs

The investigation strategy proposed by JPCERT/CC covers four types of Windows Event Logs: Application, Security, System, and Setup logs.

These logs often contain traces left behind by ransomware attacks that could reveal the entry points used by the attackers and their “digital identity.”

Here are some examples of ransomware traces highlighted in the agency’s report:

  • Conti: Identified by many logs related to the Windows Restart Manager (event IDs: 10000, 10001).
    RestartManage notifications from Conti-based encryptors
    RestartManage notifications from Conti-based encryptors
    Source: JPCERT/CC

    Similar events are generated by Akira, Lockbit3.0, HelloKitty, Abysslocker, Avaddon, Bablock, and other malware created from Lockbit’s and Conti’s leaked encryptor.

  • Phobos: Leaves traces when deleting system backups (event IDs: 612, 524, 753). Similar logs are generated by 8base and Elbie.
  • Midas: Changes network settings to spread infection, leaving event ID 7040 in logs.
  • BadRabbit: Records event ID 7045 when installing an encryption component.
  • Bisamware: Logs a Windows Installer transaction’s start (1040) and end (1042).
Bisamware ransomware logs
Characteristic Bisamware ransomware logs
Source: JPCERT/CC

JPCERT/CC also notes that seemingly unrelated ransomware variants such as Shade, GandCrab, AKO, AvosLocker, BLACKBASTA, and Vice Society, leave behind very similar traces (event IDs: 13, 10016).

Both errors are caused by a lack of permissions when accessing COM applications to delete Volume Shadow Copies, which ransomware typically deletes to prevent easy restoration of encrypted files.

ADVERTISING

It’s important to note that no detection method should be taken as a guarantee for adequate protection against ransomware, but monitoring for specific logs can prove game-changing when combined with other measures to detect attacks before they spread too far into a network.

JPCERT/CC notes that older ransomware strains such as WannaCry and Petya did not leave traces in Windows logs, but the situation has changed on modern malware, so the technique is now considered effective.

In 2022, SANS also shared a guide on detecting different ransomware families using Windows Event Logs.

Bill Toulas

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
3:07 pm, Jan 27, 2025
weather icon 7°C
L: 6° | H: 8°
overcast clouds
Humidity: 86 %
Pressure: 983 mb
Wind: 12 mph SW
Wind Gust: 18 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 95%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:45 am
Sunset: 4:40 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
6° | 8°°C 0.74 mm 74% 18 mph 81 % 983 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
6° | 10°°C 1 mm 100% 20 mph 86 % 994 mb 0 mm/h
Wed Jan 29 9:00 pm
weather icon
6° | 7°°C 1 mm 100% 14 mph 91 % 1008 mb 0 mm/h
Thu Jan 30 9:00 pm
weather icon
4° | 7°°C 1 mm 100% 9 mph 91 % 1030 mb 0 mm/h
Fri Jan 31 9:00 pm
weather icon
2° | 6°°C 0 mm 0% 8 mph 94 % 1035 mb 0 mm/h
Today 6:00 pm
weather icon
7° | 7°°C 0.74 mm 74% 17 mph 81 % 983 mb 0 mm/h
Today 9:00 pm
weather icon
7° | 7°°C 0.2 mm 20% 18 mph 76 % 983 mb 0 mm/h
Tomorrow 12:00 am
weather icon
7° | 7°°C 1 mm 100% 20 mph 86 % 981 mb 0 mm/h
Tomorrow 3:00 am
weather icon
8° | 8°°C 1 mm 100% 19 mph 85 % 980 mb 0 mm/h
Tomorrow 6:00 am
weather icon
8° | 8°°C 1 mm 100% 16 mph 85 % 980 mb 0 mm/h
Tomorrow 9:00 am
weather icon
8° | 8°°C 0.2 mm 20% 15 mph 85 % 980 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
10° | 10°°C 1 mm 100% 10 mph 79 % 979 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
8° | 8°°C 1 mm 100% 10 mph 86 % 982 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€97,170.63
-2.86%
Ethereum(ETH)
€2,991.83
-5.18%
XRP(XRP)
€2.81
-5.34%
Tether(USDT)
€0.95
0.02%
Solana(SOL)
€225.37
-7.28%
USDC(USDC)
€0.95
0.00%
Dogecoin(DOGE)
€0.311431
-7.21%
Shiba Inu(SHIB)
€0.000018
-6.87%
Pepe(PEPE)
€0.000012
-13.11%
Peanut the Squirrel(PNUT)
€0.342091
3.03%
Scroll to Top