This detection identifies the presence of the VProtector antivirus engine (version 10) on endpoints, signaling potential legacy security software that may lack coverage against modern threats or exhibit performance overhead. A proactive hunt is recommended to assess whether these agents are fully patched and effectively integrated with Azure Sentinel’s data ingestion pipelines to ensure comprehensive visibility across the environment.
rule VProtectorV10Avcasm
{
meta:
author="malware-lu"
strings:
$a0 = { 55 8B EC 6A FF 68 8A 8E 40 00 68 C6 8E 40 00 64 A1 00 00 00 00 50 64 89 25 00 00 00 00 E8 03 00 00 00 C7 84 00 58 EB 01 E9 83 C0 07 50 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
Here are 4 specific false positive scenarios for the VProtectorV10Avcasm detection rule, including suggested filters and exclusions:
Scenario: Automated Antivirus Scanning by Veeam Backup & Replication
VProtector service (part of Veeam) frequently spawns child processes to scan backup repositories or perform integrity checks on virtual machines. These scans often trigger the AVCASM signature when accessing specific VM configuration files (.vmdk, .vmx).Veeam.Backup.Service.exe and its child processes (Veeam.Backup.Avcasm.exe) on hosts running Veeam. Alternatively, create a filter to exclude alerts where the parent process is svchost.exe (specifically the VeeamBackupService service) accessing paths within the backup repository directory (e.g., C:\Veeam\BackupRepository\).Scenario: Scheduled PowerShell Script Execution for Configuration Management
powershell.exe where the command line contains keywords like “VProtector” or “AVCASM”. Additionally, exclude specific scheduled task names such as \Microsoft\Veeam\Backup\PolicyUpdate if they are known to trigger this behavior.Scenario: Third-Party Endpoint Detection and Response (EDR) Integration