This detection identifies the presence of the specific VProtector13Xvcasm signature within the environment, indicating potential deployment or execution of a known security tool component that may be leveraged by adversaries for evasion. Proactive hunting in Azure Sentinel is recommended to validate whether this artifact represents legitimate administrative activity or an unexpected indicator of compromise requiring further behavioral analysis.
rule VProtector13Xvcasm
{
meta:
author="malware-lu"
strings:
$a0 = { 00 00 00 00 00 [4] 00 00 00 00 00 00 00 00 [8] 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 [12] 00 00 00 00 6B 65 72 6E 65 6C 33 32 2E 64 6C 6C 00 00 00 00 47 65 74 50 72 6F 63 41 64 64 72 65 73 73 00 00 00 47 65 74 4D 6F 64 75 6C 65 48 61 6E 64 6C 65 41 00 00 00 4C 6F 61 64 4C 69 62 72 61 72 79 41 00 60 8B B4 24 24 00 00 00 8B BC 24 28 00 00 00 FC C6 C2 80 33 DB A4 C6 C3 02 E8 A9 00 00 00 0F 83 F1 FF FF FF 33 C9 E8 9C 00 00 00 0F 83 2D 00 00 00 33 C0 E8 8F 00 00 00 0F 83 37 00 00 00 C6 C3 02 41 C6 C0 10 E8 7D 00 00 00 10 C0 0F 83 F3 FF FF FF }
$a1 = { E9 B9 16 00 00 55 8B EC 81 EC 74 04 00 00 57 68 00 00 00 00 68 00 00 C2 14 68 FF FF 00 00 68 [4] 9C 81 [10] 9D 54 FF 14 24 68 00 00 00 00 68 00 00 C2 10 68 [4] 9C 81 [10] 9D 54 FF 14 24 68 00 00 00 00 68 [4] 9C 81 [10] 9D 54 FF 14 24 68 00 00 00 00 68 FF FF C2 10 68 [4] 9C 81 [10] 9D 54 FF 14 24 68 00 00 00 00 68 [4] 9C 81 [10] 9D 54 FF 14 24 68 00 00 00 00 68 00 00 C2 14 68 FF FF 00 00 68 [4] 9C 81 [10] 9D 54 FF 14 24 68 00 00 00 00 68 [4] 9C 81 [10] 9D 54 FF 14 24 68 00 00 00 00 }
condition:
$a0 or $a1 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 2 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the VProtector13Xvcasm detection rule, including suggested filters and exclusions tailored for an enterprise environment:
Scenario: Scheduled Antivirus Definition Updates via Veeam Backup & Replication
vcasm process is frequently triggered during nightly maintenance windows when the Veeam Backup & Replication service updates its internal virtual appliance signatures or scans backup repositories. This often mimics the behavior of a new security agent installation.C:\Program Files\Veeam\Backup and Replication Enterprise Edition\vsm.exe (or the associated child process) when it spawns vcasm related threads. Additionally, filter alerts occurring strictly between 01:00 AM and 04:00 AM on weekdays to align with maintenance windows.Scenario: Virtual Desktop Infrastructure (VDI) Provisioning by VMware Horizon
vcasm component is invoked during automated desktop image provisioning and snapshot creation. The YARA rule may flag the rapid file I/O and process spawning as a potential unauthorized agent deployment.vmware-vpxd.exe (vSphere) or HorizonAgentService.exe. Configure the detection logic to ignore events where the command line arguments contain keywords like “provisioning,” “snapshot,” or “clone.”Scenario: Automated Patch Deployment via Microsoft Endpoint Configuration Manager (SCCM)
vcasm process may be instantiated to verify the integrity of the patched VM before finalizing the update,