Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

11–20 of 253 posts

Re: Cyber Scarecrow

#11
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on?

Here is one on github:

https://github.com/NavyTitanium/Fake-Sandbox-Artifacts

Re: Cyber Scarecrow

#16
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts

The really fun part is when malware authors add detections for "fake sandbox" and then real sandbox authors get to add those indicators.

Re: Cyber Scarecrow

#18
post #3

If you're going to go through the effort of faking honeypot/analysis tools, why not just run them?

Costs a lot of cycles to run those for real, and it’s not super common to get infected with anything, so you’re wasting cycles for a small chance at avoiding it. This could be better since, I assume, it doesn’t do a lot of stuff.

can you nice them?

Re: Cyber Scarecrow

#19
post #6

When is Scarecrow Advanced++ with NextGen Anti-Detection and Cloaking will be released? Jokes aside, this is a temporary fix at best, a waste of resources and impression of safety at worst.

Scarecrow Cloud Native AI with Nextgen Quantum Crypto XR ++

(bingo?)

Re: Cyber Scarecrow

#20

Narrator: and so the arms race continues. I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But on that note, I wondered the same thing at my last workplace where we'd only run windows in virtual machines. Sometimes these were quite outdated regarding system and browser updates, and some non-tech staff used them to browse random websites. They we…

> I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name.

But more sophisticated detection means bigger payload (making the malware easier to detect) and more complexity (making the malware harder to make / maintain), so mission accomplished.

Post reply on HN