This detection identifies potential malware activity matching the specific signature of the “yodasProtectorV1033AshkbizDanehkar” YARA rule within Azure Sentinel’s security logs. Although currently flagged with low severity, proactively hunting for this indicator allows the SOC team to validate its presence across endpoints and prevent silent lateral movement before it escalates into a critical incident.
rule yodasProtectorV1033AshkbizDanehkar
{
meta:
author="malware-lu"
strings:
$a0 = { E8 03 00 00 00 EB 01 ?? BB 55 00 00 00 E8 03 00 00 00 EB 01 ?? E8 8E 00 00 00 E8 03 00 00 00 EB 01 ?? E8 81 00 00 00 E8 03 00 00 00 EB 01 ?? E8 B7 00 00 00 E8 03 00 00 00 EB 01 ?? E8 AA 00 00 00 E8 03 00 00 00 EB 01 ?? 83 FB 55 E8 03 00 00 00 EB 01 ?? 75 2D E8 03 00 00 00 EB 01 ?? 60 E8 00 00 00 00 5D 81 ED 07 E2 40 00 8B D5 81 C2 56 E2 40 00 52 E8 01 00 00 00 C3 C3 E8 03 00 00 00 EB 01 ?? E8 0E 00 00 00 E8 D1 FF FF FF C3 E8 03 00 00 00 EB 01 ?? 33 C0 64 FF 30 64 89 20 CC C3 E8 03 00 00 00 EB 01 ?? 33 C0 64 FF 30 64 89 20 4B CC C3 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the yodasProtectorV1033AshkbizDanehkar detection rule in an enterprise environment, along with recommended filters:
Scenario: Scheduled Antivirus Definition Updates via Microsoft Endpoint Configuration Manager (MECM)
yodasProtector executable or its associated process tree. During nightly maintenance windows, MECM pushes updated definition files to endpoints, triggering a new instance of the protector service that matches the detection logic.yodasProtector.exe) combined with the Parent Process being ccmexec.exe (Configuration Manager) or wuauserv.exe (Windows Update), restricted to the specific time window of 01:00–04:00 UTC.Scenario: Enterprise Backup Agent Scanning via Veeam or Commvault
VeeamAgent.exe or CommServe) scan the system directory where the Yodas Protector is installed, they often spawn child processes to verify file integrity. These child processes may inherit attributes that trigger the rule as a “new” or “suspicious” execution of the protector component.VeeamAgent.exe, commagent.exe) and the File Path resides within the standard installation directory (e.g., C:\Program Files\Yodas\Protector).Scenario: Automated Patch Deployment via Ansible or PowerShell DSC