Cyber Scarecrow
cyberscarecrow.com
Cyber Scarecrow
1–10 of 253 posts
Re: Cyber Scarecrow
#2Re: Cyber Scarecrow
#3If you're going to go through the effort of faking honeypot/analysis tools, why not just run them?
Re: Cyber Scarecrow
#4If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.
Re: Cyber Scarecrow
#5Also somewhat surprised the source isn't available. That makes trusting it harder, especially to the people it's aimed at.
Re: Cyber Scarecrow
#6Jokes aside, this is a temporary fix at best, a waste of resources and impression of safety at worst.
Re: Cyber Scarecrow
#7But perhaps I'm wrong
Re: Cyber Scarecrow
#8If you're going to go through the effort of faking honeypot/analysis tools, why not just run them?
Re: Cyber Scarecrow
#9I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name.
But on that note, I wondered the same thing at my last workplace where we'd only run windows in virtual machines. Sometimes these were quite outdated regarding system and browser updates, and some non-tech staff used them to browse random websites. They were never hit by any crypto malware and whatnot, which surprised me a lot at first, but at some point I realized the first thing you do as even a halfway decent malware author is checking whether you run in a virtualized environment.
Re: Cyber Scarecrow
#10Isn't the risk then that they'll first start scanning for "Scarecrow", or is that hidden somehow? Also somewhat surprised the source isn't available. That makes trusting it harder, especially to the people it's aimed at.