A simple magic is to set system language and locale to Russian.
Cyber Scarecrow
51–60 of 253 posts
Re: Cyber Scarecrow
#52When is Scarecrow Advanced++ with NextGen Anti-Detection and Cloaking will be released? Jokes aside, this is a temporary fix at best, a waste of resources and impression of safety at worst.
Re: Cyber Scarecrow
#53A simple magic is to set system language and locale to Russian.
Re: Cyber Scarecrow
#54Earlier quoted context omitted.
Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…
Is it possible to fake being from Russia. I heard some malware won't install on computers from Russia or with the Russian language as primary language
Re: Cyber Scarecrow
#55A simple magic is to set system language and locale to Russian.
Re: Cyber Scarecrow
#56Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.
It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts
Re: Cyber Scarecrow
#57Re: Cyber Scarecrow
#58Game anti-cheat code makes similar checks (arguably it is malware, but that's besides the point). So, running this might put you at risk of getting banned from your favourite game.
Re: Cyber Scarecrow
#59Earlier quoted context omitted.
> I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But more sophisticated detection means bigger payload (making the malware easier to detect) and more complexity (making the malware harder to make / maintain), so mission accomplished.
“Sophisticated” detection can be as simple as checking rss and pcpu, the bullshit decoy processes probably aren’t wasting a lot of CPU and RAM, otherwise might as well run the real things; if they are, well, just avoid, who cares. So no, it’s not going to meaningfully complicate anything.