Skip to content

Commit

Permalink
docs: README update - FAQ, explorer.exe kill
Browse files Browse the repository at this point in the history
  • Loading branch information
Neo23x0 committed Oct 5, 2020
1 parent 06b3ab2 commit a5d77a8
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -132,6 +132,14 @@ The solution is outlined in this [tweet](https://twitter.com/cyb3rops/status/131

![raccine as debugger](https://raw.githubusercontent.com/Neo23x0/Raccine/main/images/screen-tweet1.png)

## FAQs

### Why did it even kill explorer.exe during its run?

Since malware tends to inject into `explorer.exe`, we thought it would be a good idea to kill even `explorer.exe` in order to avoid malicious code performing other operations on the system. What happens in real world examples is that a user that executed the Ransomware process would loose its windows task bar and desktop, while other programs like Microsoft Word or Outlook would still be running and the user would be able to save his work and close the respective programs before calling the helpdesk or simpy reboot the system. An expericend user could bring up task manager using `CTRL+ALT+Del` and start a new `explorer.exe` or just log off.

![raccine as debugger](https://raw.githubusercontent.com/Neo23x0/Raccine/main/images/screen-explorer-injection.png)

## Other Info

The right pronounciation is "Rax-Een".
Expand Down
Binary file added images/screen-explorer-injection.png
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.

0 comments on commit a5d77a8

Please sign in to comment.