I would assume there would be a small intersection of people that would download and install a windows program from an unknown web page and those that are worried about malware. But perhaps I'm wrong
I know people /plural/ that will happily download cracked antivirus software from a torrent site.
Cyber Scarecrow
31–40 of 253 posts
Re: Cyber Scarecrow
#32Re: Cyber Scarecrow
#33Re: Cyber Scarecrow
#34Lol, this website is registered to someone in Iceland, despite the assurance that it is a "security researcher living in the UK". I'm sure the results from this experiment will make a cool blog post about pwning tech savvy folks.
Re: Cyber Scarecrow
#35Re: Cyber Scarecrow
#36Sounds like a very interesting concept. I'd like to see someone actually test this though. Try running this on a Windows PC with Windows Defender off & just Scarecrow running. You could use the MaleX test kit [1] or a set of malware such as the Zoo collection [2] or something more current. I'd be very interested to see how many malware executables stop half way through their installation after seeing a few bogus regi…
Re: Cyber Scarecrow
#37Re: Cyber Scarecrow
#38Narrator: and so the arms race continues. I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But on that note, I wondered the same thing at my last workplace where we'd only run windows in virtual machines. Sometimes these were quite outdated regarding system and browser updates, and some non-tech staff used them to browse random websites. They we…
I am recommending doing this for over 10 years now.
Re: Cyber Scarecrow
#39Earlier quoted context omitted.
Costs a lot of cycles to run those for real, and it’s not super common to get infected with anything, so you’re wasting cycles for a small chance at avoiding it. This could be better since, I assume, it doesn’t do a lot of stuff.
can you nice them?
Re: Cyber Scarecrow
#40Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.
It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts