This detection identifies the presence of VProtector anti-cheat components on endpoints, which adversaries may leverage to establish persistence or evade security controls by mimicking legitimate gaming software. A proactive hunt is essential in Azure Sentinel to distinguish these benign processes from malicious actors exploiting similar signatures to mask their activities within the environment.
rule vprotector12vcasm
{
meta:
author="malware-lu"
strings:
$a0 = { EB 0B 5B 56 50 72 6F 74 65 63 74 5D 00 E8 24 00 00 00 8B 44 24 04 8B 00 3D 04 00 00 80 75 08 8B 64 24 08 EB 04 58 EB 0C E9 64 8F 05 00 00 00 00 74 F3 75 F1 EB 24 64 FF 35 00 00 00 00 EB 12 FF 9C 74 03 75 01 E9 81 0C 24 00 01 00 00 9D 90 EB F4 64 89 25 00 }
$a1 = { EB 0B 5B 56 50 72 6F 74 65 63 74 5D 00 E8 24 00 00 00 8B 44 24 04 8B 00 3D 04 00 00 80 75 08 8B 64 24 08 EB 04 58 EB 0C E9 64 8F 05 00 00 00 00 74 F3 75 F1 EB 24 64 FF 35 00 00 00 00 EB 12 FF 9C 74 03 75 01 E9 81 0C 24 00 01 00 00 9D 90 EB F4 64 89 25 00 00 00 00 EB E6 E8 16 00 00 00 8B 5C 24 0C 8B A3 C4 00 00 00 64 8F 05 00 00 00 00 83 C4 04 EB 14 64 FF 35 00 00 00 00 64 89 25 00 00 00 00 33 C9 99 F7 F1 E9 E8 03 00 00 00 C7 84 00 58 EB 01 E9 83 C0 07 50 C3 FF 35 E8 16 00 00 00 8B 5C 24 0C 8B A3 C4 00 00 00 64 8F 05 00 00 00 00 83 C4 04 EB 14 64 FF 35 00 00 00 00 64 89 25 00 00 00 00 33 C9 99 F7 F1 E9 E8 03 00 00 00 C7 84 00 58 EB 01 E9 83 C0 07 50 C3 FF 35 33 F6 E8 10 00 00 00 8B 64 24 08 64 8F 05 00 00 00 00 58 EB 13 C7 83 64 FF 35 00 00 00 00 64 89 25 00 00 00 00 AD CD 20 E8 05 00 00 00 0F 01 EB 05 E8 EB FB 00 00 83 C4 04 E8 08 00 00 00 0F 01 83 C0 }
condition:
$a0 at pe.entry_point or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 5 specific false positive scenarios for the vprotector12vcasm detection rule, including suggested filters and exclusions:
Scenario: The Veeam Backup & Replication service (Veeam.Backup.Service) initiates a scheduled “Full Backup” job during business hours.
vprotector12vcasm module.C:\Program Files\Veeam\Backup and Replication Services\bin\Veeam.Backup.Service.exe on all backup servers, or filter alerts where the parent process is Veeam.Backup.Service.exe.Scenario: The Veeam ONE monitoring agent performs a “Health Check” scan across the vCenter environment.
C:\Program Files\Veeam\ONE\bin\Veeam.One.Service.exe when the command line arguments contain keywords like “HealthCheck” or “PerformanceReport”.Scenario: An administrator manually runs a Veeam “Inventory Scan” via PowerShell to audit existing backup repositories.
Veeam.Backup.Cmdlets.dll is loaded during the script execution, invoking the specific assembly covered by this rule while scanning repository metadata.-Command "Invoke-VBRInventory" or originates from a known admin account (e.g., DOMAIN\veeam-admin) executing PowerShell scripts.