i'm confused about the tradeoff of not running the software that your pretending to be running? Most AV definitly feels like malware itself so maybe thats your point? But it would probably be better to run good software than fake bad software?
Cyber Scarecrow
41–50 of 253 posts
Re: Cyber Scarecrow
#42I would assume there would be a small intersection of people that would download and install a windows program from an unknown web page and those that are worried about malware. But perhaps I'm wrong
Re: Cyber Scarecrow
#43Narrator: and so the arms race continues. I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But on that note, I wondered the same thing at my last workplace where we'd only run windows in virtual machines. Sometimes these were quite outdated regarding system and browser updates, and some non-tech staff used them to browse random websites. They we…
> I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But more sophisticated detection means bigger payload (making the malware easier to detect) and more complexity (making the malware harder to make / maintain), so mission accomplished.
Re: Cyber Scarecrow
#44When is Scarecrow Advanced++ with NextGen Anti-Detection and Cloaking will be released? Jokes aside, this is a temporary fix at best, a waste of resources and impression of safety at worst.
Re: Cyber Scarecrow
#45Re: Cyber Scarecrow
#46As much as I'd love to see something like this everywhere, the problem is it's useless for everyone who loves to play online games or watch DRM-encumbered content, so the majority of the population... because DRM, anticheat and malware all fear the same set of tools/indicators.
Re: Cyber Scarecrow
#47Lol, this website is registered to someone in Iceland, despite the assurance that it is a "security researcher living in the UK". I'm sure the results from this experiment will make a cool blog post about pwning tech savvy folks.
Re: Cyber Scarecrow
#48Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.
Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…
Re: Cyber Scarecrow
#49Earlier quoted context omitted.
> I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But more sophisticated detection means bigger payload (making the malware easier to detect) and more complexity (making the malware harder to make / maintain), so mission accomplished.
Not by much. Probably less effort than you're putting in trying to avoid the malware, so it's a net loss.
Re: Cyber Scarecrow
#50If you're going to go through the effort of faking honeypot/analysis tools, why not just run them?