This rule detects the presence of the VideoLAN Client (VLC) executable, which adversaries may leverage for file staging, media playback during social engineering, or as a living-off-the-land binary to execute payloads. Proactively hunting for this indicator helps identify potential lateral movement or persistence mechanisms that rely on common, trusted applications to blend in with normal user activity.
rule VideoLanClient
{
meta:
author="malware-lu"
strings:
$a0 = { 55 89 E5 83 EC 08 [15] FF FF }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
vlc.exe (or cvlc.exe for command-line usage) when the parent process is an installer (e.g., msiexec.exe, setup.exe) or when the file path matches the standard installation directory (e.g., C:\Program Files\VideoLAN\VLC\).--sout, --input-as-files, --demux) or where the working directory is within a known project folder (e.g., C:\dev\, D:\builds\).NT SERVICE\MediaServerSvc) or when the parent process is a known scheduler (e.g., taskschd.msi, python.exe in a specific service context) and the file path resides in a media storage directory (e.g., \\NAS\Media\, D:\VideoArchive\).