Showing posts with label web malware. Show all posts
Showing posts with label web malware. Show all posts

Tuesday, July 08, 2014

, , , , ,

virustotal += Spam404 URL scanner

Spam404 is a blacklist of abusive domains that engage in shady activities such as scamming, spamming, phishing, etc. As described by its developers:
We are mainly blacklisting websites that are tricking users into completing offers by advertising content that is very desirable but the website doesn't actually have the content and it is just to make the end user complete an offer. From our intense research, these kind of websites are not getting enough attention in terms of blacklisting and we are the only website to offer such a blacklist for these kind of websites but we believe it is in the best interests of all internet users to have these kind of websites blacklisted.
We are also blacklisting other abusive websites including phishing and other kinds of scams.
As of today, Spam404 is producing verdicts for URLs submitted to virustotal, giving yet another notion of maliciousness to users enjoying the service. An example of a Spam404 detection can be found here:
https://www.virustotal.com/en/url/68f2ffc241ee0f1b904ebfa6db49fe3fbf5a39c9a170bfef198400ff26a9969b/analysis/

Welcome Spam404 team!

Monday, July 07, 2014

, , , , , ,

virustotal += Rising URL scanner

Rising is a Chinese software company that produces the anti-virus software Rising Antivirus, a firewall, UTM and spam-blocking products. Rising antivirus has been running in virustotal for quite some time, today we are excited to announce the integration of their URL scanner, which will be enhancing virustotal's web checking backbone.

Hopefully this integration will lead to a greater coverage of threats targeting Chinese end-users. This is an example of a Rising detection:
https://www.virustotal.com/en/url/0b03fa909a2cdee2fe197b26fe6ec3880a55cc436e474d50713b8a1fdff3bafa/analysis/

Thank you Rising team!

Monday, June 23, 2014

, , , , ,

VirusTotal += FraudSense

We are excited to announce the inclusion of FraudSense as a new URL scanning engine in VirusTotal. FraudSense offers services to automate and enable real-time detection of phishing sites and their targeted brands. They have developed their own in-house phishing detection technology, which they describe as:
Based on cognitive concepts, artificial intelligence and active learning, our innovative technology automates what has traditionally been a labor-intensive process and enables real-time detection of phishing sites and their targeted brands.
Key features include:
0-Day Phishing Detection: Early discovery of new, unreported phishing sites.Brand Recognition: Accurate identification of the targeted brand.Language-Independent: Detection of both English and non-English phishing sites.Self-Sufficient: Independent of community-sponsored blacklists.
FraudSense is exposing its phishing feed to VirusTotal, so that users can check whether a given URL is already in their blacklist and hopefully get yet one more second opinion that will help them in keeping their environments safe.

An example of a URL detected by FraudSense:
https://www.virustotal.com/en/url/59c8caddf3295bfb72361d76ccb77f7405c6b4478ed4391eee7a9e80929734a8/analysis/

Welcome FraudSense!

Wednesday, May 21, 2014

, , , ,

VirusTotal += Tencent URL scanner

Just recently my colleague Julio announced the introduction of Tencent as a new antivirus solution in VirusTotal's file scanner. Today we are excited to announce that Tencent has broadened its collaboration and is also sharing its malicious URL dataset in order to enhance our URL scanner.

This is a great addition as it will surely give us a better visibility into the threats targeting the eastern side of the globe. This is an example of showing Tencent's verdicts:
https://www.virustotal.com/en/url/e2387dd5a55e2af20db30d57a7869a3e86faf1e85aa065e3e4e76167e93782dc/analysis/

Welcome on board!

Friday, February 07, 2014

, , , ,

VirusTotal += CRDF France URL scanner

Many of you may already know CRDF because of their contributions in VirusTotal Community, in their own words:
We observe malicious behavior to develop, understand, inform and fight against scourges. The laboratory actively fights against malware, spam and security risks.
Among other projects, CRDF has built its own threat center and they are very active VirusTotal uploaders. Today we are excited to announce that they have taken this collaboration one step further and started sharing their malicious domains dataset with VirusTotal in order to make it work as a URL scanner.

Here is an example of a URL being detected by CRDF:
https://www.virustotal.com/en/url/57f956398112e14e1c4bf90310d0ad5417535de1ac8d3b7ce9c504d7d65f4153/analysis/1391729258/

Welcome on board CRDF!

Wednesday, November 13, 2013

, , , , ,

VirusTotal += malwares.com URL checker

Many security industry actors build solutions that lie in the perimeter of networks, inspecting traffic and discriminating potentially malicious content. One of these solutions is SIMBA from Saint Security (others include FireEye, Fidelis XPS, Damballa, etc.).

In inspecting traffic, these solutions have a privileged position to perform correlations to discover and characterize malicious patterns, this is what allows these companies to discover thousands of malicious URLs and files every day. Saint Security has made part of their discriminatory logic available at malwares.com:
As a cloud-based malicious codes database system, malwares.com is a one-stop service to collect, analyze and detect various malicious codes or malwares such as Trojans, Viruses, Worms so that customers or end-users can make proper security policies to take countermeasures against security threats.
Today we are excited to announce that malwares.com has been integrated in VirusTotal as a URL checker and as of today URL scans will be enriched with their dataset of malicious verdicts. This inclusion is very interesting as it covers much of the threat landscape seen in South Korea, a clear example of this is the following report:
https://www.virustotal.com/en/url/3625ed7252e98152ad781b3deea92038bc1d416c343f8b7bfe2a3ec8ca5b3727/analysis/

Welcome on board and thanks for joining us!

Thursday, October 31, 2013

, , , ,

VirusTotal += AegisLab WebGuard

Our effort to pump up our URL scanner backbone continues, today we are excited to announce the integration of AegisLab WebGuard, a concise malicious URL database to prevent malicious URLs whose characteristics are described by its developers as:
Fast update and leave less open window for attack. Less false positive than other web filter DBs. Website hijacking prevention. Concise malicious URL database. Including: Drive-by-Downloads, BlackHat SEOFake Anti-Virus, Installer and Updates, Scarewares and etc.
You can read more about the kind of threats that AegisLab WebGuard intercepts in this blog post: http://blog.aegislab.com/?p=78

Welcome on board guys, thanks for joining VirusTotal!
, , ,

VirusTotal += RiskAnalytics AutoShun

What is AutoShunAutoShun is a small appliance that protects your network from attacks. Automatically updates itself within minutes to bidirectionally block new threats. One AutoShun device is able to protect an entire site. Configurable whitelist to ensure business partner communications. Ability to block traffic by geographic regions. Reporting on all blocked threats and traffic.
This is the way the RiskAnalytics team describes its AutoShun solution. As you may infer, in order to be able to bidirectionally block threats, AutoShun works (among other technologies and logistics) with a dataset of online threats. From now onward VirusTotal users will also be able to check their submitted URLs against this dataset, which appears in VirusTotal under the name of AutoShun.

Thank you RiskAnalytics!

Tuesday, October 22, 2013

, , , ,

VirusTotal += StopBadware

StopBadware is a nonprofit anti-malware organization based in Cambridge, Massachusetts. Our work makes the Web safer through the prevention, mitigation, and remediation of badware websites. We protect people and organizations from becoming victims of viruses, spyware, scareware, and other badware.
This is the way the StopBadware team describes itself, a pretty awesome initiative that has managed to bring together many partners. From now onward VirusTotal users will also be able to take advantage of their URL verdicts.

StopBadware numbers are very impressive, since their launch they have managed to:
  • inform over 700,000 website owners about how to remediate their compromised sites and prevent future attack
  • serve more than 10 million Google and Firefox users with content about how to mitigate their risk of badware infection
  • help de-blacklist over 100,000 websites flagged by our data providers for badware
  • enlist more than 50 web hosting providers from 22 countries (and counting) in the We Stop Badware™ Web Host program, which helps those providers respond more quickly and effectively to reports of badware on their networks
Without doubt, this integration will bring great value to VirusTotal, thank you StopBadware!

Monday, October 21, 2013

, , , , ,

VirusTotal += Threathive

ThreatHive is a domain and IP reputation tracking system comprised of data collected from various sources including sandboxing , collecting data from various spampot systems and independent research. 
This is how The Malwarelab describes its ThreatHive initiative which has just been integrated in VirusTotal. With this inclusion we are well over the 40 URL scanners, over the weekend we have integrated some new engines that we will be announcing in the coming days.

Thank you The Malwarelab!

Wednesday, March 06, 2013

, , , , ,

VirusTotal += Fortinet URL Scanner


FortiGuard Labs analyzes events in real time throughout cyberspace, including both the domain (URL) and IP level. If a website or server hosts malware, attack code, or has been used in spam emails these events will be analyzed by the lab. A history of these events, along with additional intelligence data is available through our URL and IP Lookup tool.
This is how Fortinet describes its web filtering solution which has just been integrated in VirusTotal. With this inclusion we reach 38 URL scanners, we want to surpass 40, hence, if you have any interesting malicious URL dataset or URL scanner please do not hesitate to contact us, we will be more than happy to include you!

This is a permalink to a report showing Fortinet's detection of a phishing site:
https://www.virustotal.com/en/url/3b7819d0ced38ed3d754fcf34378a07c6fc6559116353534ac028d6395020197/analysis/1362562630/

Thank you Fortinet team!

Wednesday, January 23, 2013

, , , , , ,

VirusTotal.url_scanners.extend(Quttera, ESET)

We are pleased to announce that we are including two new URL scanners in VirusTotal: Quttera and ESET. At the same time, we are also updating Trend Micro's and Antiy-AVL's web checkers, the changes should improve their detection rates, enhancing the overall aggregate detection capability of VirusTotal's URL scanning engine.

Quttera describes its technology as follows:
WIS is a BETA version of a cloud based application that utilizes Quttera exploit detection technology. This online URL scanner investigates URLs in order to detect suspicious scripts, malicious media and any other web security threats hidden into legitimate content and located on web sites. 
As to ESET, its URL scanner is usually embedded in their antivirus software, providing a holistic solution:
At ESET, we are dedicated to developing high-performing security solutions for home users and corporate customers, detecting and disabling all known and emerging forms of malware.
We are really excited to announce these changes since we have just reached 37 URL scanners, even though not all of them always show up due to timeout issues. We will soon catch up with the number of file scanners. If your company/team develops a link checker or maintains a malicious URL dataset do not hesitate to contact us, we will be more than happy to integrate your solution/dataset.

Friday, November 30, 2012

, , , , , , ,

VirusTotal += ADMINUSLabs

Continuing the trend of engine inclusions we have just added ADMINUSLabs as a new URL scanner. In words of ADMINUSLabs itself:
ADMINUSLABS has built an incredibly robust and comprehensive binaries and malware collection and analysis set of tools, enabling organizations of all sizes to leverage the data analyzed and threats monitored to build better defense system. With clients and partners in every continent, ADMINUSLABS solutions offer industry leading technology, flexibility, cost effectiveness, and service levels.
ADMINUSLabs has shared its malicious URL dataset with VirusTotal, from now on, whenever a user submits a URL to VirusTotal for scanning it will also get checked against ADMINUSLabs' dataset and flagged as malicious if present in it. This is an example of a report with one such detection:

https://www.virustotal.com/url/0048c271f6c90bc6959c0eb91ed139692a1ec0f0f4b3328a9ad09baad010c7c2/analysis/1354276484/

ADMINUSLabs' dataset is very large and gets updated several times per day with thousands of new URLs, this is an excellent addition, many thanks and welcome on board!

Wednesday, November 28, 2012

, , , , , ,

VirusTotal += Malekal

We are back with new inclusions in VirusTotal's URL scanning engine. This time we are excited to add Malekal's malicious URL dataset to our aggregate scanner.

Malekal is a site maintained by one of our most active VirusTotal Community users, @Malekal_morte. The site mostly deals with malware and antivirus but has support forums that help users in many other ICT fields. As a result of the support he gives and the research he conducts, Malekal comes across many malware samples an malicious URLs as we can see in his public listing (21211 documented files since March 2010 at the time of this article).

Malekal's malicious URL dataset is now being used to check whether any URL submitted by a user to VirusTotal is present in it and if so it is flagged accordingly. You should now be able to see these detections in the URL reports, just as an example:

https://www.virustotal.com/url/04d67bdebd8a74eaaac37212e35848203f55823c157aab958ad4415d1b7ba344/analysis/1354089612/

We are extremely grateful to Malekal, welcome on board!

Wednesday, October 10, 2012

, , , , ,

VirusTotal += Netcraft

Netcraft Toolbar is one of the most known antiphishing/antimalware browser toolbars out there. The Netcraft team describes its software as follows:
The Toolbar community is effectively a giant neighbourhood watch scheme, empowering the most alert and most expert members to defend everyone within the community against phishing attacks. Once the first recipients of a phishing mail have reported the target URL, it is blocked for community members as they subsequently access the URL. Widely disseminated attacks (people construct phishing attacks send literally millions of emails in the expectation that some will reach customers of the bank) simply mean that the phishing attack will be reported and blocked sooner.
The Netcraft Toolbar also:

  • Traps suspicious URLs containing characters which have no common purpose other than to deceive.
  • Enforces display of browser navigational controls (toolbar & address bar) in all windows, to defend against pop up windows which attempt to hide the navigational controls.
  • Clearly displays sites' hosting location, including country, helping you to evaluate fraudulent urls (e.g. the real citibank.com or barclays.co.uk sites are unlikely to be hosted in the former Soviet Union).
Taking all of this into account we are really excited to announce that Netcraft has been integrated in VirusTotal, you will now see it as another URL scanner in VirusTotal's URL scanning service.

With this addition we have already over 30 URL scanners and are looking forward to be in the forties as soon as possible, so if you have an interesting malicious URL dataset or URL scanner please do not hesitate to contact us, we will be more than happy to include you!

Thank you Netcraft team!

Thursday, August 30, 2012

, , , , , ,

VirusTotal += Sucuri SiteCheck


It has been a while since we last added some new analyzer to our URL scanning engine, today we are excited to announce that Sucuri SiteCheck has become part of our small family. This is how the Sucuri team describes their service:
Sucuri SiteCheck is highly sophisticated and designed to identify a number of different malware types: Obfuscated JavaScript injections, Cross Site Scripting (XSS), Website Defacements, Hidden & Malicious iFrames, PHP Mailers, Phishing Attempts, Malicious Redirects, Backdoors (e.g., C99, R57, Webshells), Anomalies, Drive-by-Downloads, IP Cloaking, Social Engineering Attacks. There are a number of blacklisting authorities that monitor for malware, SPAM, and phishing attempts. Sucuri SiteCheck leverages the APIs for the following authorities to alert you when you’ve been flagged: Sucuri, Google Safe Browsing, Norton, AVG, Phish Tank (Phishing Specifically), McAfee SiteAdvisor.
We are extremely grateful to Sucuri, you should now see them on our URL reports, just as an example:

https://www.virustotal.com/url/78f6ade26461d84b32b857529613abbd8c9e1306fa3a4e6b9e9c8ff11dd1d82d/analysis/

You may read more about their technology at their services site.

Welcome on board Sucuri!

Friday, June 15, 2012

, , , , , , ,

VirusTotal += Sophos URL scanner

Lately we had been introducing many domain characterization datasets/tools in our URL scanning engine, today we are excited to announce that Sophos' fully-fledged URL filtering solution has become part of VirusTotal and will be characterizing both full URLs and domains.

This is an example of the Sophos output with their malicious test domain, do not forget to refer to the additional information section to see the threat information provided:

https://www.virustotal.com/url/d77e1526bbb2941575cd25edfe23bac54caa38969c4d63c9a85f5e09d4d2d01b/analysis/1339745884/

The Sophos team describe their solution as follows:
You can connect your computers to our constantly updated list of millions of infected websites, so your users can’t get to them — even when they're outside your gateway protection. And we keep it updated, adding around 40,000 new sites every day. Sophos Live URL Filtering is included in all of our Endpoint products and suites.  
You may read more about it on their web site.

We would like to give Sophos URL scanner a really warm welcome and thank them for allowing us to keep improving VirusTotal!

Monday, June 11, 2012

, , , , ,

VirusTotal += Palevo Tracker

It seems that lately it is all about domain scanners/datasets, today we have included Palevo Tracker. Palevo is a worm that spreads using instant messaging, P2P networks and removable drives (like USB sticks), Palevo Tracker records the C&C hosts being used by the worm variants.

Since it is a malicious domain dataset it appears in the additional information section of URL reports, characterizing the hosts of the submitted URLs, you may refer to the additional information tab of this scan in order to see its output:

https://www.virustotal.com/url/7c22fa416c960e715d8b1e9ff6cdd160d676c081136f520d9dca2404706fb007/analysis/1339404171/

It is already the 3rd dataset belonging to abuse.ch that we integrate (the previous ones where Zeus Tracker and SpyEye Tracker), we are really grateful to them and would like to congratulate them for the great work they are doing.

Thursday, June 07, 2012

, , , , ,

VirusTotal += hpHosts

This morning we announced that we had integrated Malware Domain Blocklist in VirusTotal's URL scanning engine. Continuing the trend of including domain scanners and datasets, we have just added hpHosts and we would like to give them a really warm welcome.

hpHosts maintains an online list of domains involved in some sort of malicious activity. The good thing about hpHosts is that it provides a very rich set of classifications for domains:
  • Domains being used for advert or tracking purposes.
  • Domains engaged in the distribution of malware (e.g. adware, spyware, trojans and viruses etc).
  • Sites engaged in or alleged to be engaged in the exploitation of browser and OS vulnerabilities as well as the exploitation of gray-matter.
  • Sites engaged in the selling or distribution of bogus or fraudulent applications.
  • Sites engaged in astroturfing otherwise known as grass roots marketing.
  • Persons caught spamming the hpHosts forums.
  • Sites engaged in browser hijacking or other forms of hijacking (OS services, bandwidth, DNS, etc.).
  • Sites engaged in the use of misleading marketing tactics.
  • Sites engaged in Phishing.
  • Sites engaged in the selling, distribution or provision of warez (including but not limited to keygens, serials etc), where such provisions do not contain malware.
This enhances the information rendered in the additional information section of VirusTotal reports, it is precisely there where this tool appears because it characterizes domains rather than URLs:


This is an example of a report with such information:


We started processing the hpHosts dataset today, hence, all new domains they classify from now onwards should be visible to VirusTotal.

As it happened with the Malware Domain Blocklist information, the data returned by hpHosts can be used for building customized scoring systems for full URLs.

hpHosts, once again, thanks for your collaboration!
, , , ,

VirusTotal += Malware Domain Blocklist

We are happy to announce that Malware Domain Blocklist has been integrated in VirusTotal's URL scanning engine. Malware Domain Blocklist is a dataset of malicious domains rather than a full URL scanner. As such, its results appear in the additional information field of VirusTotal reports:


The network location of any URL you submit will be parsed and compared against this dataset and, in the event that the domain was seen to exhibit some sort of malicious behaviour at some point in time, it will be flagged accordingly. This is an example of a URL report with the new information:

https://www.virustotal.com/url/69c9e6afa0ad42f53df62d517c7afc4d14ef4640d8265b108a2aa7230aa9ded2/analysis/1339060844/

It is an interesting addition since it enriches our set of tools that characterize domains. The information might seem redundant or of little use for users intending to scan full URLs rather than domains, however, it is a very useful piece of information if you want to build scoring systems for URLs. Even if the main URL scanners in VirusTotal do not detect the specific full path URL, you might want to produce your own intelligent system that receives several inputs, among them the results of domain datasets, and decides on the maliciousness of the URL.

We are really grateful to www.malwaredomains.com, keep up the good work!