-
- Enthusiast
- Posts: 31
- Liked: 3 times
- Joined: Nov 16, 2022 2:18 pm
- Contact:
How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Veeam-Team,
wer are using the KB4632 for investigation Encrypted Data Event.
Now following questions are raised up:
What does the percentage means in the created CVS file?
Is there a list for the different mailware detection types (Encypted Data,Onioub link) available? And is for the different types also an KB available as for the type Encrypted Date (KB 4632) ?
Thanks for your help.
regards,
Oliver
wer are using the KB4632 for investigation Encrypted Data Event.
Now following questions are raised up:
What does the percentage means in the created CVS file?
Is there a list for the different mailware detection types (Encypted Data,Onioub link) available? And is for the different types also an KB available as for the type Encrypted Date (KB 4632) ?
Thanks for your help.
regards,
Oliver
-
- Product Manager
- Posts: 10482
- Liked: 2810 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Oliver
"Percentage" is explained in the KB:
The final column of the CSV report displays the percentage of encryption detected in the first 1MB of the file. As most ransomware encrypts only a portion of each file, the encryption detection tool only checks the first 1MB of the file to maximize investigation performance.
C:\ProgramData\Veeam\Backup\Malware_Detection_Logs\
Other malware activities are logged in the Malware event details in the backup console.
KB4632 for encrypted data is required because Veeam Backup & Replication doesn’t provide a session log itself. The backup server knows from the backup session which blocks on the disk are encrypted.
To find the encrypted files, we need the tool in KB4632 to scan the entire backup file with the information about encrypted blocks the backup server has.
Best,
Fabian
"Percentage" is explained in the KB:
The final column of the CSV report displays the percentage of encryption detected in the first 1MB of the file. As most ransomware encrypts only a portion of each file, the encryption detection tool only checks the first 1MB of the file to maximize investigation performance.
We provide a list of available malware detection methods and the types of malware we can detect in our helpcenter.Is there a list for the different mailware detection types (Encypted Data,Onioub link) available?
No, different types are listed in other places. Suspicious files are logged on the backup server in a separate folder:And is for the different types also an KB available as for the type Encrypted Date (KB 4632) ?
C:\ProgramData\Veeam\Backup\Malware_Detection_Logs\
Other malware activities are logged in the Malware event details in the backup console.
KB4632 for encrypted data is required because Veeam Backup & Replication doesn’t provide a session log itself. The backup server knows from the backup session which blocks on the disk are encrypted.
To find the encrypted files, we need the tool in KB4632 to scan the entire backup file with the information about encrypted blocks the backup server has.
Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Enthusiast
- Posts: 31
- Liked: 3 times
- Joined: Nov 16, 2022 2:18 pm
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Fabian,
please allow me to ask one more question how does it work for an onion link event.
Is there alog file as well?
Regards,
Oliver
please allow me to ask one more question how does it work for an onion link event.
Is there alog file as well?
Regards,
Oliver
-
- Product Manager
- Posts: 10482
- Liked: 2810 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Oliver,
When we detect an onion link, we raise a Malware "Suspicious" alert.
You can open the alert, and it will include a path to a log file on the backup server. This log file will provide you with the exact path of the onion link inside the protected machine.

Best,
Fabian
When we detect an onion link, we raise a Malware "Suspicious" alert.
You can open the alert, and it will include a path to a log file on the backup server. This log file will provide you with the exact path of the onion link inside the protected machine.
Code: Select all
[10.06.2025 11:21:06.071] <48> Warning (3) FK-Win2025-01:441389bc-8091-4780-bdb4-db92e7e0bf9e:c:\_adminfiles\**************************.onion

Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Enthusiast
- Posts: 31
- Liked: 3 times
- Joined: Nov 16, 2022 2:18 pm
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Fabian,
unfortunately the alert does not contain the path to the log. The details part is empty respectively the pathi is missing.
If I take a look into C:\ProgramData\Veeam\Backup\Malware_Detection_Logs\ Logs the log is not up to date. Is there any onther directory whre i can take a look?
Regards,
Oliver
unfortunately the alert does not contain the path to the log. The details part is empty respectively the pathi is missing.
If I take a look into C:\ProgramData\Veeam\Backup\Malware_Detection_Logs\ Logs the log is not up to date. Is there any onther directory whre i can take a look?
Regards,
Oliver
-
- Product Manager
- Posts: 10482
- Liked: 2810 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
The log path should be in the alarm (v12.1.1 and later).
If you can't see the log file, no Onion links were detected or there might be an issue. In that case, I recommend to open a case with customer support.
Or did you change default log location for Veeam Backup & Replication?
Best,
Fabian
If you can't see the log file, no Onion links were detected or there might be an issue. In that case, I recommend to open a case with customer support.
Or did you change default log location for Veeam Backup & Replication?
Best,
Fabian
Product Management Analyst @ Veeam Software
-
- Enthusiast
- Posts: 31
- Liked: 3 times
- Joined: Nov 16, 2022 2:18 pm
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Fabien,
the versioin is 12.3.1.1139. The only info in the details part is : Potential malware activity detected
I´m not aware that anyone changed the log path, where can i do that?
regards,
Oliver
the versioin is 12.3.1.1139. The only info in the details part is : Potential malware activity detected
I´m not aware that anyone changed the log path, where can i do that?
regards,
Oliver
-
- Enthusiast
- Posts: 31
- Liked: 3 times
- Joined: Nov 16, 2022 2:18 pm
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Fabien,
the versioin is 12.3.1.1139. The only info in the details part is : Potential malware activity detected
I´m not aware that anyone changed the log path, where can i do that?
regards,
Oliver
Top
Quick Reply
the versioin is 12.3.1.1139. The only info in the details part is : Potential malware activity detected
I´m not aware that anyone changed the log path, where can i do that?
regards,
Oliver
Top
Quick Reply
-
- Product Manager
- Posts: 10482
- Liked: 2810 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
The default log folder path can be changed by a reg key: https://www.veeam.com/kb1825
Please contact our customer support if you have onion links on your filesystem, but Veeam didn't report it after enabling the "Inline Scan".
Thank you,
Fabian
Please contact our customer support if you have onion links on your filesystem, but Veeam didn't report it after enabling the "Inline Scan".
Thank you,
Fabian
Product Management Analyst @ Veeam Software
-
- Enthusiast
- Posts: 31
- Liked: 3 times
- Joined: Nov 16, 2022 2:18 pm
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Fabian,
Inline Scan is enabled never the less we have a malware detection event type onion link.
Does it mean even though we have that type of malware detection there is no report available where i can find the links?
Regards
Oliver
Inline Scan is enabled never the less we have a malware detection event type onion link.
Does it mean even though we have that type of malware detection there is no report available where i can find the links?
Regards
Oliver
-
- Product Manager
- Posts: 10482
- Liked: 2810 times
- Joined: May 13, 2017 4:51 pm
- Full Name: Fabian K.
- Location: Switzerland
- Contact:
Re: How to Investigate 'Encrypted Data Event' from Malware Detection
Hi Oliver,
If you have the event but no logs are available, please contact customer support.
We cannot investigate your environment through a forum post. Our customer support team must be contacted.
Please share the case number with me after you have opened the support case.
Best,
Fabian
If you have the event but no logs are available, please contact customer support.
We cannot investigate your environment through a forum post. Our customer support team must be contacted.
Please share the case number with me after you have opened the support case.
Best,
Fabian
Product Management Analyst @ Veeam Software
Who is online
Users browsing this forum: No registered users and 50 guests