Hello,
I'm writing in regard to how the malware detection reports details about suspicious files in the Backup & Replication console.
While most of the alerts are straightforward with the extension and a number, sometimes the extension will include text in parentheses.
What is this text meant to convey? Is it an analysis of the associated potential threat (like the name of Ransomware)? Is it the name of a folder/file?
This kind of message doesn't appear consistently and if the details includes a list of extensions, it usually only shows up for one of the extensions.
The info in the parentheses won't appear in the logs on the veeam server itself, as that just lists the suspicious files.
Here are some examples of what I've seen so far:
*.grt(Karmen HiddenTear): 2
*.encrypted(Various/Donald Trump/KeRanger OS X): 1
I appreciate any insight you can provide.
Many thanks for your time and assistance.
-
- Lurker
- Posts: 2
- Liked: never
- Joined: Jan 26, 2024 7:34 pm
- Contact:
-
- Chief Product Officer
- Posts: 32222
- Liked: 7587 times
- Joined: Jan 01, 2006 1:01 am
- Location: Baar, Switzerland
- Contact:
Re: Malware detection details and occasional text in parentheses next to extension
Hello, these are the names of ransomware strain using such extensions.
-
- Lurker
- Posts: 2
- Liked: never
- Joined: Jan 26, 2024 7:34 pm
- Contact:
-
- Product Manager
- Posts: 14818
- Liked: 1772 times
- Joined: Feb 04, 2013 2:07 pm
- Full Name: Dmitry Popov
- Location: Prague
- Contact:
Re: Malware detection details and occasional text in parentheses next to extension
Hello nqekkudo,
It's stored in the C:\Program Files\Veeam\Backup and Replication\Backup\SuspiciousFiles.xml file. The list is provided to us by the security team, please let us know the extensions in the question and we will investigate if its possible to add the name. Thank you!
It's stored in the C:\Program Files\Veeam\Backup and Replication\Backup\SuspiciousFiles.xml file. The list is provided to us by the security team, please let us know the extensions in the question and we will investigate if its possible to add the name. Thank you!
Who is online
Users browsing this forum: Baidu [Spider] and 110 guests