Showing posts with label Malicious URL. Show all posts
Showing posts with label Malicious URL. Show all posts

Monday, July 07, 2014

, , , , , ,

virustotal += Rising URL scanner

Rising is a Chinese software company that produces the anti-virus software Rising Antivirus, a firewall, UTM and spam-blocking products. Rising antivirus has been running in virustotal for quite some time, today we are excited to announce the integration of their URL scanner, which will be enhancing virustotal's web checking backbone.

Hopefully this integration will lead to a greater coverage of threats targeting Chinese end-users. This is an example of a Rising detection:
https://www.virustotal.com/en/url/0b03fa909a2cdee2fe197b26fe6ec3880a55cc436e474d50713b8a1fdff3bafa/analysis/

Thank you Rising team!

Friday, February 07, 2014

, , , ,

VirusTotal += CRDF France URL scanner

Many of you may already know CRDF because of their contributions in VirusTotal Community, in their own words:
We observe malicious behavior to develop, understand, inform and fight against scourges. The laboratory actively fights against malware, spam and security risks.
Among other projects, CRDF has built its own threat center and they are very active VirusTotal uploaders. Today we are excited to announce that they have taken this collaboration one step further and started sharing their malicious domains dataset with VirusTotal in order to make it work as a URL scanner.

Here is an example of a URL being detected by CRDF:
https://www.virustotal.com/en/url/57f956398112e14e1c4bf90310d0ad5417535de1ac8d3b7ce9c504d7d65f4153/analysis/1391729258/

Welcome on board CRDF!

Friday, May 03, 2013

, , , ,

VirusTotal += CyberCrime botnet panels tracker

Xylitol has been extremely kind in letting us enrich VirusTotal's URL scanner with his CyberCrime tracker. CyberCrime is a C&C panel tracker, in other words, it lists the administration interfaces of certain in-the-wild botnets. As such, its URL database is inherently smaller than other datasets integrated in VirusTotal.

Nonetheless, one should not neglect the usefulness of this tracker, very often other malware-related infrastructure will be located in the same host as the botnet administration panel, hence, it can prove itself very useful in finding evil.

https://www.virustotal.com/en/url/ba1cee3c6a157232ac8a61b17ff07694acc970e1bae9ced5c9ef2bfc56ae6ea1/analysis/1367596300/

Thank you Xylitol! Keep up the good work!
, , , , ,

VirusTotal += Virus Tracker

Just after Kaspersky joining VirusTotal's aggregate URL scanner, we are excited to announce that Virus Tracker is also becoming part of our family:

https://www.virustotal.com/en/url/82ddbb7eea25e7ce2ca13aed44cac009d9ff6c463e763d22b8b2043f20bd8a52/analysis/1367576071/

Virus Tracker is a service whose mission:
is to provide detailed infection statistics, C&C information and an automatically updated domain blocklist of various botnets to the security community.
The site is non-profit and focuses on banking trojans and financial malware, some of the botnets they track are: multibanker, sinowal, tinybanker, urlzone, zeus, ramnit, etc. This is fantastic news for the average end-user, since they will have a better view of the most perilous threats directly targeting their money.

Yet another URL scanner, one more and we will be in the forties, thank you Virus Tracker team!

Wednesday, November 28, 2012

, , , , , ,

VirusTotal += Malekal

We are back with new inclusions in VirusTotal's URL scanning engine. This time we are excited to add Malekal's malicious URL dataset to our aggregate scanner.

Malekal is a site maintained by one of our most active VirusTotal Community users, @Malekal_morte. The site mostly deals with malware and antivirus but has support forums that help users in many other ICT fields. As a result of the support he gives and the research he conducts, Malekal comes across many malware samples an malicious URLs as we can see in his public listing (21211 documented files since March 2010 at the time of this article).

Malekal's malicious URL dataset is now being used to check whether any URL submitted by a user to VirusTotal is present in it and if so it is flagged accordingly. You should now be able to see these detections in the URL reports, just as an example:

https://www.virustotal.com/url/04d67bdebd8a74eaaac37212e35848203f55823c157aab958ad4415d1b7ba344/analysis/1354089612/

We are extremely grateful to Malekal, welcome on board!

Monday, September 24, 2012

, , , , ,

VirusTotal += Webutation

It has been a while since we last included a domain characterization dataset, we have just added Webutation and we would like to give them a really warm welcome.


The Webutation team describes its service as follows:

Webutation is an open community about Website Reputation and
  • collects user feedback and customer experience about websites.
  • tests websites against spyware, spam and scams with smart scanning technology in realtime.
  • queries
    • Google Safebrowsing against badware and phising fraud (which is used in Firefox as well and updates every half hour).
    • Website Antivirus which scans sites against adware (popups), spyware (outgoing links) and viruses.
    • WOT which collects some reviews about websites.
    • Norton Safe Web
    • as well as many other website feedback resources.
It is clear that this will surely enhance the information rendered in the additional information section of VirusTotal reports, it is precisely there where this tool appears because it characterizes domains rather than URLs, example:

https://www.virustotal.com/url/5ab7fdaa6cc0cbc8e17965044afe3c47266819335a9fa5533004113664bbb4ef/analysis/1348486392/

As it happened with the other domain characterization engines, the data returned by Webutation can be used for building customized scoring systems for full URLs.

Webutation, once again, thanks for your collaboration!