Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

41–50 of 253 posts

Re: Cyber Scarecrow

#41

i'm confused about the tradeoff of not running the software that your pretending to be running? Most AV definitly feels like malware itself so maybe thats your point? But it would probably be better to run good software than fake bad software?

But there is no good software for defense. They either introduce obstacles while being barely useful or are useful, introduce obstacles for you and are proprietary and thus are malicious by design.

Re: Cyber Scarecrow

#42

I would assume there would be a small intersection of people that would download and install a windows program from an unknown web page and those that are worried about malware. But perhaps I'm wrong

Author of cyber scarecrow here. You are right, its a trust thing. Completly understand if people wouldnt want to install it and thats fine. It's the same for any software really. We just havent built up any confidence or trust like a big established company will have.

Re: Cyber Scarecrow

#43

Narrator: and so the arms race continues. I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But on that note, I wondered the same thing at my last workplace where we'd only run windows in virtual machines. Sometimes these were quite outdated regarding system and browser updates, and some non-tech staff used them to browse random websites. They we…

> I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But more sophisticated detection means bigger payload (making the malware easier to detect) and more complexity (making the malware harder to make / maintain), so mission accomplished.

“Sophisticated” detection can be as simple as checking rss and pcpu, the bullshit decoy processes probably aren’t wasting a lot of CPU and RAM, otherwise might as well run the real things; if they are, well, just avoid, who cares. So no, it’s not going to meaningfully complicate anything.

Re: Cyber Scarecrow

#44
post #6

When is Scarecrow Advanced++ with NextGen Anti-Detection and Cloaking will be released? Jokes aside, this is a temporary fix at best, a waste of resources and impression of safety at worst.

Author of scarecrow here. Were working on an LLM and a blockchain first ;-) (joke)

Re: Cyber Scarecrow

#46

As much as I'd love to see something like this everywhere, the problem is it's useless for everyone who loves to play online games or watch DRM-encumbered content, so the majority of the population... because DRM, anticheat and malware all fear the same set of tools/indicators.

Author of scarecrow here. Very good point, i hadnt thought about that.

Re: Cyber Scarecrow

#47
post #29

Lol, this website is registered to someone in Iceland, despite the assurance that it is a "security researcher living in the UK". I'm sure the results from this experiment will make a cool blog post about pwning tech savvy folks.

That's the WHOIS privacy service enabled by default on .com domains registered through Namecheap.

Re: Cyber Scarecrow

#48
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

Is it possible to fake being from Russia. I heard some malware won't install on computers from Russia or with the Russian language as primary language

Re: Cyber Scarecrow

#49

Earlier quoted context omitted.

> I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But more sophisticated detection means bigger payload (making the malware easier to detect) and more complexity (making the malware harder to make / maintain), so mission accomplished.

Not by much. Probably less effort than you're putting in trying to avoid the malware, so it's a net loss.

The more scarecrow is installed, the easier it gets for real security researchers to hide from these checks and detect viruses. So actually the dynamic helps security research.

Re: Cyber Scarecrow

#50

If you're going to go through the effort of faking honeypot/analysis tools, why not just run them?

Author of scarecrow here. The idea is cyber scarecrow is just super easy and light weight for anyone to use. Honeypot tech tends to need some good tech understanding to use (eg the cli), and can be a bit heavyweight for always running in the background of your computer.
Post reply on HN