This YARA rule detects the presence of VProtect v10, a commercial virtualization-based protection tool often used by adversaries to obfuscate malicious code and evade static analysis. Proactively hunting for this signature in Azure Sentinel allows the SOC to identify potentially hidden or packed payloads that may be executing on endpoints, ensuring that low-severity but high-impact obfuscation techniques are not overlooked in the environment.
rule VProtectorV10Dvcasm
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 CA 31 41 00 68 06 32 41 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 E8 03 00 00 00 C7 84 00 58 EB 01 E9 83 C0 07 50 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
vprot or vprot.exe binary by the VProtect (or similar vendor-specific) endpoint protection agent during a scheduled integrity check or policy update.
C:\Program Files\VProtect\bin\vprot.exe (or vendor-specific path) and the parent process is the service host (e.g., svchost.exe or the vendor’s service manager)./verify, /config, or /license and the parent process is schtasks.exe or powershell.exe running under a known admin account.ccmexec.exe (SCCM) or MsMpEng.exe/IntuneAgent and the working directory is the temporary deployment folder (e.g., C:\Windows\CCM\ or C:\ProgramData\Intune\).conhost.exe or cmd.exe and the user account belongs to a known IT admin group (e.g., IT_Support, Endpoint_Admins).