Live data from Hacker News

Cyber Scarecrow

cyberscarecrow.com

51–60 of 253 posts

Re: Cyber Scarecrow

#52
post #6

When is Scarecrow Advanced++ with NextGen Anti-Detection and Cloaking will be released? Jokes aside, this is a temporary fix at best, a waste of resources and impression of safety at worst.

ssshhhhh, not so loud, they'll hear you and add scarecrows to the checklist of mandatory runtime security requirements for production services

Re: Cyber Scarecrow

#54

Earlier quoted context omitted.

Author of cyber scarecrow here. Thank you for your feedback, and you are 100% right. We also dont have a code signing certificate yet either, they are expensive for windows. Smartscreen also triggers when you install it. Id be weary of installing it myself as well, especially considering it runs as admin, to be able to create the fake indicators. I have just added a bit of info about us on the website. I'm not sure w…

Is it possible to fake being from Russia. I heard some malware won't install on computers from Russia or with the Russian language as primary language

Great idea. Looking at installing an additional keyboard or language with out it being anoying to the user is next on the feature list.

Re: Cyber Scarecrow

#56
post #4

Fun concept. If the creators read this, I suggest some ways of building trust. There’s no “about us”, no GitHub link, etc. It’s a random webpage that wants my personal details, and sends me a “exe”. The overlap of people who understand what this tool does, and people who would run that “exe” is pretty small.

It is a cat and mouse game. And security by obscurity practice. Not saying it won't work, but if it is open sourced, how long before the malware will catch on? Here is one on github: https://github.com/NavyTitanium/Fake-Sandbox-Artifacts

If windows would have this built in, then it would make malware authors job much more difficult. I like that.

Re: Cyber Scarecrow

#57
I wonder if you can make malware think your language and keyboard layout is Russian without having to endure the setup, that's been known to deter some nasty stuff.

Re: Cyber Scarecrow

#58
> When hackers install malicious software on a compromised victim, they first check to make sure its safe for them to run. They don't want to get caught and avoid computers that have security analysis [...] tools on them.

Game anti-cheat code makes similar checks (arguably it is malware, but that's besides the point). So, running this might put you at risk of getting banned from your favourite game.

Re: Cyber Scarecrow

#59
post #43

Earlier quoted context omitted.

> I guess if this gets enough attention, malware will just add more sophisticated checks and not just look at the exe name. But more sophisticated detection means bigger payload (making the malware easier to detect) and more complexity (making the malware harder to make / maintain), so mission accomplished.

“Sophisticated” detection can be as simple as checking rss and pcpu, the bullshit decoy processes probably aren’t wasting a lot of CPU and RAM, otherwise might as well run the real things; if they are, well, just avoid, who cares. So no, it’s not going to meaningfully complicate anything.

Wouldn't that be more fragile though? CPU usage is not constant in time, so if - again - you're not sophisticated enough, you get more false negatives / positives, depending on which side of the heuristic you err.

Re: Cyber Scarecrow

#60
Get a PTR record for your IP, let it resolve to honeypot087.win.internal.security.example.com, that will make your IP less interesting... To some people
Post reply on HN