
A Simple Ransomware Vaccine

A Simple Ransomware Protection
We see ransomware delete all shadow copies using vssadmin pretty often. What if we could just intercept that request and kill the invoking process? Let's try to create a simple vaccine.

We register a debugger for vssadmin.exe (and wmic.exe), which is our compiled raccine.exe. Raccine is a binary, that first collects all PIDs of the parent processes and then tries to kill all parent processes.
Advantages:
vssadmin.exe or wmic.exe), which could lead to integrity problems and could break our raccination on each patch dayDisadvantages / Blind Spots:
vssadmin.exe delete shadows (or any other blacklisted combination) isn't possible anymorevssadmin.exe delete shadows, which could be a backup processvssadmin.exe (e.g. via schtasks)vssadmin.exe (and wmic.exe) gets intercepted and passed to raccine.exe as debugger (vssadmin.exe delete shadows becomes raccine.exe vssadmin.exe delete shadows)Malicious combinations:
delete and shadows (vssadmin, diskshadow)resize and shadowstorage (vssadmin)delete and shadowstorage (vssadmin)delete and shadowcopy (wmic)delete and catalog and -quiet (wbadmin)win32_shadowcopy or element from a list of encoded commands (powershell)recoveryenabled (bcedit)ignoreallfailures (bcedit)^ outdated list: check the corresponding YARA rule
Powershell list of encoded commands: JAB, SQBFAF, SQBuAH, SUVYI, cwBhA, aWV4I, aQBlAHgA and many more
Emotet without Raccine - Link

Emotet with Raccine - Link (ignore the process activity that is related to the Raccine installation)

The infection gets nipped in the bud.
USE IT AT YOUR OWN RISK!
You won't be able to run commands that use the blacklisted commands on a raccinated machine anymore until you apply the uninstall patch raccine-reg-patch-uninstall.reg. This could break various backup solutions that run that specific command during their work. It will not only block that request but kill all processes in that tree including the backup solution and its invoking process.
If you have a solid security monitoring that logs all process executions, you could check your logs to see if vssadmin.exe delete shadows, vssadmin.exe resize shadowstorage ... or the other blocked command lines are frequently or sporadically used for legitimate purposes in which case you should refrain from using Raccine.
delete and shadows in their command line and otherwise pass all parameters to a new process that invokes vssadmin with its original parametersexplorer.exe from the whitelistwmic method calling delete shadowcopy, no outputs for whitelisted process starts (avoids problems with wmic output processing)delete shadowstorage by @JohnLaTwC, code review by @_hillu, application iconbcdedit.exe /set {default} bootstatuspolicy ignoreallfailures and bcdedit.exe /set {default} recoveryenabled nopowershell.exe and win32_shadowcopy or a list of encoded commandsC:\ProgramData\Raccine_log.txtdiskshadow.exe delete shadows commandBoth the Visual C++ Redistributable package and the .NET Framework will be automatically installed running install-raccine.bat.
Raccine.zip from the Release sectionraccine-installer.bat as administrator
The batch installer includes an "uninstall" option.
As Administrator do: