ThreateningAdvanced malware can detect virtual machine and analytics environments, cancel execution or change behavior to prevent detection.SolutionScarecrow uses this behavior to protect you. By imitating these environments on your computer, Scarecrow forces malware to show off or shut down and keep your system safe.
How does it work?When hackers install malware on a victim they have seized, they first check to make sure that it is safe to run. They do not want to be caught and avoid computers with security analysis or malware protection tools on them. Scarecrow takes advantage of it by working in the background of your computer and 'imitating' those indicators. It is very lightweight and fools malware into thinking that your computer is not a suitable place for them.
- counterfeit transactions: Scarecrow creates a series of background processes that do nothing but appear to be security research tools.
- Fake registry entries: Scarecrow creates registry entries to make it appear on your computer as if security tools are installed.