Showing posts with label url scanner. Show all posts
Showing posts with label url scanner. Show all posts

Thursday, June 06, 2019

, , , , , ,

VirusTotal += Segasec URL scanner

We have added Segasec to the assortment of URL scanners on VirusTotal. You can find the results when scanning a URL at https://www.virustotal.com/gui/home/url

In their own words:

Segasec is a Tel-Aviv based cyber-security startup providing end-to-end digital threat protection against consumer phishing attacks that originate in your blind spot - beyond the enterprise perimeter. Segasec’s patent-pending technology provides intelligence of upcoming attacks at the earliest possible preparation stages, running quadrillions of targeted scans that identify even unknown attack patterns. Segasec blocks compromised assets before they become a live risk, because once customer trust is broken, it’s already too late.

If you ask our customers what made them pick us over the competition, this is what they say -  End-to-end solution, in an entirely managed service. Early, proactive detection, both for brand and non-brand related threats. Fast and efficient block and take down, in under 3 hours.   Zero integration and fast onboarding .

If you would like to see a few example detections, checkout these reports:

Tuesday, November 18, 2014

, , , , ,

virustotal += Blueliv URL scanner

We are excited to announce that we have just integrated Blueliv's malicious URL tracker in virustotal, as yet one more URL scanner providing verdicts on URLs submitted by users. In their own words:
Blueliv is a leading provider of cyber threat information and analysis intelligence for large enterprises, service providers, and security vendors. The company’s deep expertise, data sources, and cloud-based platform address a comprehensive range of cyber threats to turn global threat data into real-time actionable intelligence specifically for each client in an easy-to-use dashboard. Blueliv’s clients include leading bank, insurance, telecom, utility, and retail enterprises.
At present, Blueliv's tracker is highly focused on sites used as C&C infrastructure for trojans, URLs distributing malware and sites with exploit kits, an example of their detections can be found in the following reports:
https://www.virustotal.com/en/url/78b30edc4de035348586cd408626009bbc42be366873e65a8bcc4f35f780f783/analysis/1415884660/
https://www.virustotal.com/en/url/885b6e1dc91e1f01413c0316117f294203d643a1ef3ec79c17556956ff08d086/analysis/1415890213/

Hopefully this integration will lead to increased knowledge about threats and will help protect users world-wide.

Welcome Blueliv!

Friday, October 17, 2014

, , , , , ,

virustotal += Baidu-International URL scanner

And we are in our sixties with respect to the number of URL scanning engines integrated in VirusTotal, welcome Baidu-International! Not so long ago we introduced their file scanner and today we are excited to populate the malicious URL dataset with their verdicts.

In their own words:
Baidu Antivirus is a permanently free and easy-to-use antivirus software which offers proactive defense, file protection, USB protection, download protection, browser protection, and other professional security features. 
As part of the browser protection component they offer they come across and have to research many malicious URLs per day, these URLs will now trigger alerts on VirusTotal. An example of their engine in action can be found below:
https://www.virustotal.com/en/url/000feb4703a2f1b3a84ad435c46da9f523ea9daec84747b12bf8345ef2908de8/analysis/1413373146/

Welcome Baidu-International!

Wednesday, September 24, 2014

, , , , , ,

virustotal += PhishLabs URL scanner

Yet another malicious URL dataset is joining virustotal today. Welcome PhishLabs.

In their own words:
PhishLabs provides cybercrime protection and intelligence services that fight back against online threats and reduce the risk posed by phishing, malware, and other cyber-attacks. They fight back against online threats by detecting, analyzing, and proactively dismantling the systems and illicit services cybercriminals depend on to attack businesses and their customers.

As part of the investigations that they conduct and the Intelligence that they gather, PhishLabs comes across many malicious URLs every day, from now on virustotal checks will also run against their blacklist, enhancing users' ability to detect recent threats.

An example of a report containing an PhishLabs report can be found below:
https://www.virustotal.com/en/url/0ec471bc92bb025a95945ba57004d23cc5854bb8ce686a02f92375cdccffa341/analysis/

Welcome PhishLabs!

Tuesday, July 08, 2014

, , , , ,

virustotal += Spam404 URL scanner

Spam404 is a blacklist of abusive domains that engage in shady activities such as scamming, spamming, phishing, etc. As described by its developers:
We are mainly blacklisting websites that are tricking users into completing offers by advertising content that is very desirable but the website doesn't actually have the content and it is just to make the end user complete an offer. From our intense research, these kind of websites are not getting enough attention in terms of blacklisting and we are the only website to offer such a blacklist for these kind of websites but we believe it is in the best interests of all internet users to have these kind of websites blacklisted.
We are also blacklisting other abusive websites including phishing and other kinds of scams.
As of today, Spam404 is producing verdicts for URLs submitted to virustotal, giving yet another notion of maliciousness to users enjoying the service. An example of a Spam404 detection can be found here:
https://www.virustotal.com/en/url/68f2ffc241ee0f1b904ebfa6db49fe3fbf5a39c9a170bfef198400ff26a9969b/analysis/

Welcome Spam404 team!

Monday, July 07, 2014

, , , , , ,

virustotal += Rising URL scanner

Rising is a Chinese software company that produces the anti-virus software Rising Antivirus, a firewall, UTM and spam-blocking products. Rising antivirus has been running in virustotal for quite some time, today we are excited to announce the integration of their URL scanner, which will be enhancing virustotal's web checking backbone.

Hopefully this integration will lead to a greater coverage of threats targeting Chinese end-users. This is an example of a Rising detection:
https://www.virustotal.com/en/url/0b03fa909a2cdee2fe197b26fe6ec3880a55cc436e474d50713b8a1fdff3bafa/analysis/

Thank you Rising team!

Monday, June 23, 2014

, , , , ,

VirusTotal += FraudSense

We are excited to announce the inclusion of FraudSense as a new URL scanning engine in VirusTotal. FraudSense offers services to automate and enable real-time detection of phishing sites and their targeted brands. They have developed their own in-house phishing detection technology, which they describe as:
Based on cognitive concepts, artificial intelligence and active learning, our innovative technology automates what has traditionally been a labor-intensive process and enables real-time detection of phishing sites and their targeted brands.
Key features include:
0-Day Phishing Detection: Early discovery of new, unreported phishing sites.Brand Recognition: Accurate identification of the targeted brand.Language-Independent: Detection of both English and non-English phishing sites.Self-Sufficient: Independent of community-sponsored blacklists.
FraudSense is exposing its phishing feed to VirusTotal, so that users can check whether a given URL is already in their blacklist and hopefully get yet one more second opinion that will help them in keeping their environments safe.

An example of a URL detected by FraudSense:
https://www.virustotal.com/en/url/59c8caddf3295bfb72361d76ccb77f7405c6b4478ed4391eee7a9e80929734a8/analysis/

Welcome FraudSense!

Wednesday, May 21, 2014

, , , ,

VirusTotal += Tencent URL scanner

Just recently my colleague Julio announced the introduction of Tencent as a new antivirus solution in VirusTotal's file scanner. Today we are excited to announce that Tencent has broadened its collaboration and is also sharing its malicious URL dataset in order to enhance our URL scanner.

This is a great addition as it will surely give us a better visibility into the threats targeting the eastern side of the globe. This is an example of showing Tencent's verdicts:
https://www.virustotal.com/en/url/e2387dd5a55e2af20db30d57a7869a3e86faf1e85aa065e3e4e76167e93782dc/analysis/

Welcome on board!

Friday, February 07, 2014

, , , ,

VirusTotal += CRDF France URL scanner

Many of you may already know CRDF because of their contributions in VirusTotal Community, in their own words:
We observe malicious behavior to develop, understand, inform and fight against scourges. The laboratory actively fights against malware, spam and security risks.
Among other projects, CRDF has built its own threat center and they are very active VirusTotal uploaders. Today we are excited to announce that they have taken this collaboration one step further and started sharing their malicious domains dataset with VirusTotal in order to make it work as a URL scanner.

Here is an example of a URL being detected by CRDF:
https://www.virustotal.com/en/url/57f956398112e14e1c4bf90310d0ad5417535de1ac8d3b7ce9c504d7d65f4153/analysis/1391729258/

Welcome on board CRDF!

Friday, May 03, 2013

, , , ,

VirusTotal += CyberCrime botnet panels tracker

Xylitol has been extremely kind in letting us enrich VirusTotal's URL scanner with his CyberCrime tracker. CyberCrime is a C&C panel tracker, in other words, it lists the administration interfaces of certain in-the-wild botnets. As such, its URL database is inherently smaller than other datasets integrated in VirusTotal.

Nonetheless, one should not neglect the usefulness of this tracker, very often other malware-related infrastructure will be located in the same host as the botnet administration panel, hence, it can prove itself very useful in finding evil.

https://www.virustotal.com/en/url/ba1cee3c6a157232ac8a61b17ff07694acc970e1bae9ced5c9ef2bfc56ae6ea1/analysis/1367596300/

Thank you Xylitol! Keep up the good work!

Wednesday, January 23, 2013

, , , , , ,

VirusTotal.url_scanners.extend(Quttera, ESET)

We are pleased to announce that we are including two new URL scanners in VirusTotal: Quttera and ESET. At the same time, we are also updating Trend Micro's and Antiy-AVL's web checkers, the changes should improve their detection rates, enhancing the overall aggregate detection capability of VirusTotal's URL scanning engine.

Quttera describes its technology as follows:
WIS is a BETA version of a cloud based application that utilizes Quttera exploit detection technology. This online URL scanner investigates URLs in order to detect suspicious scripts, malicious media and any other web security threats hidden into legitimate content and located on web sites. 
As to ESET, its URL scanner is usually embedded in their antivirus software, providing a holistic solution:
At ESET, we are dedicated to developing high-performing security solutions for home users and corporate customers, detecting and disabling all known and emerging forms of malware.
We are really excited to announce these changes since we have just reached 37 URL scanners, even though not all of them always show up due to timeout issues. We will soon catch up with the number of file scanners. If your company/team develops a link checker or maintains a malicious URL dataset do not hesitate to contact us, we will be more than happy to integrate your solution/dataset.

Friday, November 30, 2012

, , , , , , ,

VirusTotal += ADMINUSLabs

Continuing the trend of engine inclusions we have just added ADMINUSLabs as a new URL scanner. In words of ADMINUSLabs itself:
ADMINUSLABS has built an incredibly robust and comprehensive binaries and malware collection and analysis set of tools, enabling organizations of all sizes to leverage the data analyzed and threats monitored to build better defense system. With clients and partners in every continent, ADMINUSLABS solutions offer industry leading technology, flexibility, cost effectiveness, and service levels.
ADMINUSLabs has shared its malicious URL dataset with VirusTotal, from now on, whenever a user submits a URL to VirusTotal for scanning it will also get checked against ADMINUSLabs' dataset and flagged as malicious if present in it. This is an example of a report with one such detection:

https://www.virustotal.com/url/0048c271f6c90bc6959c0eb91ed139692a1ec0f0f4b3328a9ad09baad010c7c2/analysis/1354276484/

ADMINUSLabs' dataset is very large and gets updated several times per day with thousands of new URLs, this is an excellent addition, many thanks and welcome on board!

Monday, July 02, 2012

, , , , ,

VirusTotal += SecureBrain URL scanner

Some weeks ago I came across gred, the truth is I had never heard of gred before, however, I did know SecureBrain, the company behind gred. I contacted them to see whether they would be interested in introducing their malicious URL dataset in VirusTotal and they made it possible with utmost diligence.

We are extremely grateful to SecureBrain and very excited to announce that they now appear in our URL reports, just as an example:

https://www.virustotal.com/url/e8750c0b772976de6563aa81162fd319256064c76a00e0d46ab5cc5d7ebe1933/analysis/1341229461/

The SecureBrain team describe their service as follows:

Gred Security Service - Web Check
Web Check is an award winning SaaS service to help ensure you web site content is free from malware often injected by Hackers. By keeping your web content free from un-authorized malicious changes, it will help protect your customer when visiting your web site. 

You may read more about their technology at their product description site.

Welcome on board SecureBrain!

Friday, June 15, 2012

, , , , , , ,

VirusTotal += Sophos URL scanner

Lately we had been introducing many domain characterization datasets/tools in our URL scanning engine, today we are excited to announce that Sophos' fully-fledged URL filtering solution has become part of VirusTotal and will be characterizing both full URLs and domains.

This is an example of the Sophos output with their malicious test domain, do not forget to refer to the additional information section to see the threat information provided:

https://www.virustotal.com/url/d77e1526bbb2941575cd25edfe23bac54caa38969c4d63c9a85f5e09d4d2d01b/analysis/1339745884/

The Sophos team describe their solution as follows:
You can connect your computers to our constantly updated list of millions of infected websites, so your users can’t get to them — even when they're outside your gateway protection. And we keep it updated, adding around 40,000 new sites every day. Sophos Live URL Filtering is included in all of our Endpoint products and suites.  
You may read more about it on their web site.

We would like to give Sophos URL scanner a really warm welcome and thank them for allowing us to keep improving VirusTotal!

Monday, May 28, 2012

, , , ,

VirusTotal URL scanner += Comodo Site Inspector

Today we are integrating Comodo Site Inspector in VirusTotal's URL scanning engine. We have reached 26 URL scanners/datasets and a bunch of domain classifiers/datasets. We intend to keep increasing this figure, thus, if you are the owner of a URL blacklisting service or dataset please do not hesitate to contact us.

As to Comodo Site Inspector, you can find more about it in its home page:

http://siteinspector.comodo.com/

Including the online scanning service itself and a list of recent detections. The Comodo team describes the service as follows:
SiteInspector uses browser instance in sandboxed environment ( a virtual machine) and browses the page at the URL that you submitted. If the browser performs a malicious activity, crashes, downloads a suspicious file, changes registry entries or exhibits behavior consistent with malware activity then its flagged as malicious. This allows regular Internet users to test the safety of a particular website and allows website operators to test the safety of their website from their customers point of view. 
SiteInspector acts as a vulnerable customer by visiting the page and testing whether it launches an attack. If it does, then the scan results will warn you that the website contains malicious content. Each scan takes only a few seconds.  
This description and other details can also be found in their FAQ.

We would like to give Comodo Site Inspector a really warm welcome and thank them for allowing us to keep improving VirusTotal!

Wednesday, April 11, 2012

, , , , ,

Increasing the family

Wednesday, April 11, 2012 Marco de la Vega 7 comments
Today we have released a new VirusTotal version, as usual, we would like to share with you the modifications and enhancements:

  • New URL scanning engines and malicious URL/domain datasets have been integrated in our URL scanner: Antiy-AVLK7AntiVirusMalware Patrol, Minotaur, WoT and zvelo. We want to give a warm welcome to all of them!
  • Whenever a scanned URL is a redirector, the redirected URL is also queued for scanning. The additional information section of the redirector URL will link to the report of the redirected URL. For example, that's exactly what happens when you scan http://www.virustotal.com, since it redirects to https://www.virustotal.com (SSL), you will see the redirected URL report link in the additional information section:
  • The National Software Reference Library information is back on VirusTotal and appears in the additional information section of the file scan reports whenever the analysed file is found in the NSRL database:
  • Many users missed the old interface's VirusTotal Community summary in file and URL reports. The summary box used to detail the number of users that voted a resource as malicious/benign and the aggregated reputation points of these users. In coherence with the requests received, we have added a Votes tab and the end of reports that shows who voted on a given resource and the number of file/URL reputation credits that the vote added to the file/URL's karma. Please note that the file/URL karma is computed via a formula that takes into account user votes, user reputation credits and other heuristics based on the different tools integrated in VirusTotal.
  • Certain tools were acting on the files but were not being displayed in the new interface (yet the old interface did show them), they now are displayed as usual in the additional information section: Clam AV potentially unwanted application file tagging, Symantec suspicious-insight file tagging, F-Secure Deepguard file tagging, Androguard android file analyser, Antiy-AVL unpacker, F-Prot unpacker, PE compilation timestamp, PE entry point, PE target architecture (machine type), PEiD packer identifier. 
  • VirusTotal Community members can now modify their password through their user settings.
  • You may also notice minor styling changes, such as the fact that malicious/benign voting icons have changed for angel/devil emoticons. The idea behind these modifications is to make the interface more intuitive.
In the meanwhile we are cooking very exciting enhancements that we really hope will please the Community, stay tuned. As always, we would love to hear from you.