This hypothesis targets the execution of the SVKProtectorV13X payload, a known component of the SVKProtector malware family, which adversaries may deploy to establish persistence or execute malicious logic within Azure environments. Proactively hunting for this specific YARA signature allows the SOC team to identify low-severity, potentially stealthy infections that standard behavioral detections might miss, ensuring early containment of targeted threats in Azure Sentinel.
rule SVKProtectorV13XPavolCerven
{
meta:
author="malware-lu"
strings:
$a0 = { 60 E8 00 00 00 00 5D 81 ED 06 00 00 00 EB 05 B8 [2] 42 00 64 A0 23 00 00 00 EB 03 C7 84 E8 84 C0 EB 03 C7 84 E9 75 67 B9 49 00 00 00 8D B5 C5 02 00 00 56 80 06 44 46 E2 FA 8B 8D C1 02 00 00 5E 55 51 6A 00 56 FF 95 0C 61 00 00 59 5D 40 85 C0 75 3C 80 3E 00 74 03 46 EB F8 46 E2 E3 8B C5 8B 4C 24 20 2B 85 BD 02 00 00 89 85 B9 02 00 00 80 BD B4 02 00 00 01 75 06 8B 8D 0C 61 00 00 89 8D B5 02 00 00 8D 85 0E 03 00 00 8B DD FF E0 55 68 10 10 00 00 8D 85 B4 00 00 00 50 8D 85 B4 01 00 00 50 6A 00 FF 95 18 61 00 00 5D 6A FF FF 95 10 61 00 00 44 65 62 75 67 67 65 72 20 6F 72 20 74 6F 6F 6C 20 66 6F 72 20 6D 6F 6E 69 74 6F 72 69 6E 67 20 64 65 74 65 63 74 65 64 21 21 21 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 }
condition:
$a0 at pe.entry_point
}
This YARA rule can be deployed in the following contexts:
This rule contains 1 string patterns in its detection logic.
SVKProtector obfuscator to protect intellectual property or prevent reverse engineering, and the binary is deployed to application servers or developer workstations.
C:\Program Files\InternalTools\, C:\inetpub\wwwroot\) or where the file extension is .exe and the parent process is a known application host (e.g., w3wp.exe, dotnet.exe).Setup.exe or ConfigTool.exe) that has been obfuscated with SVKProtector to hide internal logic or license checks during a scheduled maintenance window.
explorer.exe or cmd.exe and the user account belongs to the IT_Admins or ServiceAccounts security group, specifically for files in temporary directories like %TEMP% or C:\Installers\.jenkins-agent.exe or azure-pipelines-agent.exe) downloads and executes a build artifact or test harness that was obfuscated with SVKProtector to ensure consistent binary behavior across environments.
C:\Jenkins\workspace\, C:\azure-pipelines\) or where the parent process matches known CI/CD agent executables.