False positives? Suspicious Process - Potential AppVLP Proxy Execution

hi, Is anyone else receiving mass of low alerts for “Suspicious Process – Potential AppVLP Proxy Execution”?

"C:\Program Files\Microsoft Office\Root\Client\AppVLp.exe" "C:\Program Files\Microsoft Office\Root\Office16\capture.exe" -Embedding

VT: 0/0

VirusTotal - File - 566561af8b56d658ed83b78ff32e6d94698cd9663b1839e9c3bf237f0c806f6e

VirusTotal - File - e35304cf9801c8e84cc3f5d4c631c040fcc388dcf7c135128e841060129321c4

2 Likes

Sure — here it is in English:

Same here. I manage a couple of tenants and have been receiving these alerts repeatedly since June 6.

I’m not sure what is triggering them yet, and so far I haven’t been able to identify any malicious behavior related to this chain:

"AppVLP.exe" "...\Office16\capture.exe" -Embedding

For now, I’ve decided to exception this specific command chain, since I can’t find clear evidence of malicious activity.

It would be great if Rapid7 could shed some light on this, whether it’s a false positive, a recent change in the detection logic, or expected Office/AppVLP behavior.

Yes. We have a few hundred of these alerts today. They seem to be related to the recent Microsoft Office update from June 25. Seems that as computers install this update we get one of these alerts.

Hi folks, our Threat Intelligence team have reviewed these alerts add added a rule suppression to reduce the noise from this, thanks for raising it @anwe

@david_smith1 any reason why R7 modifications cant be tracked in the Modification History for the detection rule?

By design the Modification History pane is there to illustrate changes made by the customer or end user, rather than the Threat Intel team.

This kind of request to show change history has come up previously, unfortunately it is not on our near term roadmap to expose this functionality.

David

Yes, a recent Office update added a new component that triggered this alert.