Tuesday, May 29, 2012

, , , ,

VirusTotal URL scanner += AlienVault

Yesterday we added Comodo Site Inspector to VirusTotal's URL scanning engine, today we are really happy to announce that AlienVault has also become part of our small family. The list of URL scanners has now grown to 27 and a couple of other domain/URL characterization tools/datasets.

AlienVault develops and maintains several security solutions, one of the most famous ones is its OSSIM. In building these tools, the AlienVault team comes across many threats, just as they describe it in their website:
Our people constantly monitor, analyse, reverse engineer and report on sophisticated zero-day threats including malware, botnets, phishing campaigns are more. Through this team of dedicated and renowned security experts, AlienVault contributes code, documentation, analysis and research results in various forms to the security community, to educate it and to make the world a more secure place for all of us.
The AlienVault team has very kindly put one of their malicious URL datasets at our disposal so that VirusTotal's URL scanner can query it, they also publish some statistics about what they are seeing in the wild in their Open Source IP Reputation Portal.

Once again, we would like to thank AlienVault in helping us improve VirusTotal and we look forward to other malicious URL/domain datasets/characterization tools contacting us to be included in VirusTotal.

Monday, May 28, 2012

, , , ,

VirusTotal URL scanner += Comodo Site Inspector

Today we are integrating Comodo Site Inspector in VirusTotal's URL scanning engine. We have reached 26 URL scanners/datasets and a bunch of domain classifiers/datasets. We intend to keep increasing this figure, thus, if you are the owner of a URL blacklisting service or dataset please do not hesitate to contact us.

As to Comodo Site Inspector, you can find more about it in its home page:

http://siteinspector.comodo.com/

Including the online scanning service itself and a list of recent detections. The Comodo team describes the service as follows:
SiteInspector uses browser instance in sandboxed environment ( a virtual machine) and browses the page at the URL that you submitted. If the browser performs a malicious activity, crashes, downloads a suspicious file, changes registry entries or exhibits behavior consistent with malware activity then its flagged as malicious. This allows regular Internet users to test the safety of a particular website and allows website operators to test the safety of their website from their customers point of view. 
SiteInspector acts as a vulnerable customer by visiting the page and testing whether it launches an attack. If it does, then the scan results will warn you that the website contains malicious content. Each scan takes only a few seconds.  
This description and other details can also be found in their FAQ.

We would like to give Comodo Site Inspector a really warm welcome and thank them for allowing us to keep improving VirusTotal!

Wednesday, April 11, 2012

, , , , ,

Increasing the family

Wednesday, April 11, 2012 Marco de la Vega 7 comments
Today we have released a new VirusTotal version, as usual, we would like to share with you the modifications and enhancements:

  • New URL scanning engines and malicious URL/domain datasets have been integrated in our URL scanner: Antiy-AVLK7AntiVirusMalware Patrol, Minotaur, WoT and zvelo. We want to give a warm welcome to all of them!
  • Whenever a scanned URL is a redirector, the redirected URL is also queued for scanning. The additional information section of the redirector URL will link to the report of the redirected URL. For example, that's exactly what happens when you scan http://www.virustotal.com, since it redirects to https://www.virustotal.com (SSL), you will see the redirected URL report link in the additional information section:
  • The National Software Reference Library information is back on VirusTotal and appears in the additional information section of the file scan reports whenever the analysed file is found in the NSRL database:
  • Many users missed the old interface's VirusTotal Community summary in file and URL reports. The summary box used to detail the number of users that voted a resource as malicious/benign and the aggregated reputation points of these users. In coherence with the requests received, we have added a Votes tab and the end of reports that shows who voted on a given resource and the number of file/URL reputation credits that the vote added to the file/URL's karma. Please note that the file/URL karma is computed via a formula that takes into account user votes, user reputation credits and other heuristics based on the different tools integrated in VirusTotal.
  • Certain tools were acting on the files but were not being displayed in the new interface (yet the old interface did show them), they now are displayed as usual in the additional information section: Clam AV potentially unwanted application file tagging, Symantec suspicious-insight file tagging, F-Secure Deepguard file tagging, Androguard android file analyser, Antiy-AVL unpacker, F-Prot unpacker, PE compilation timestamp, PE entry point, PE target architecture (machine type), PEiD packer identifier. 
  • VirusTotal Community members can now modify their password through their user settings.
  • You may also notice minor styling changes, such as the fact that malicious/benign voting icons have changed for angel/devil emoticons. The idea behind these modifications is to make the interface more intuitive.
In the meanwhile we are cooking very exciting enhancements that we really hope will please the Community, stay tuned. As always, we would love to hear from you.

Tuesday, April 03, 2012

100 million files

VirusTotal has reached a remarkable milestone today: 100 million files in it's database. That's more than most countries' population. Really amazing. But even more amazing is that more than 60 millions of those files have been submitted during last year, so we have grown in one year more than ever since VirusTotal's launch in 2004.

As our site grows the challenge is bigger, but we keep our commitment to give a useful service to all of you. And this is just the beginning, a lot more is coming!

Wednesday, March 28, 2012

,

VirusTotal -= PrevX

PrevX engine used at VirusTotal has been removed as that specific product has been EOLd.

Tuesday, February 14, 2012

, , , , ,

VTchromizer version 1.1

VTchromizer is a Google Chrome browser extension for interacting with VirusTotal. We describe its full functionality in its official documentation and you can install it directly from the Chrome Web Store. The extension embeds a new context menu dialog option whenever you right-click on links, this option allows you to scan the target URL with VirusTotal prior to visiting the given site.

The main purpose of VTchromizer is to help the community in securing their systems. Having said this, if we can also collect interesting data to analyse and study, even better. We are interested in malware, obviously, so if you come across any malicious file download link do not hesitate to scan it with VTchromizer. Additionally, have been encouraging users to send us phishing and any other fraud/ecrime related sites. Why? Hopefully these sites will end up being processed by the URL analysis tools integrated in VirusTotal and will improve their efficiency, and thus end-user protection.

A while ago one of VTchromizer's users made a comment on our Chrome Web Store site:
Nice extension! VirusTotal is extremely useful tool to keep you safe on the Internet. One small bug though. When I right-click on the link, I see a simple line in the menu: "Scan with VirusTotal", which works fine. However, after I click on the toolbar VirusTotal icon, the right-click menu changes. I see now the reference to VTchromizer, which points to 2, 3, 4 or more repetitions of the line "Scan with VirusTotal". The number of repetitions of this same line corresponds with the number of times I click on the toolbar icon - it can be 10, 15 and higher. It should be fixed. I use latest Chrome 12.0.742.112.
It was a really stupid bug whereby the toolbar popup kept loading a JavaScript file that added the "Scan with VirusTotal" option to the context menu each time it was loaded. We have corrected this bug and made available a new version of the extension, VTchromizer v1.1. Those of you already using the extension should have transparently received the update.

As usual, we really appreciate your feedback and are really keen to keep improving the functionality of our tools, thus, all your comments regarding VTchromizer are welcome at our contact site.

Sunday, December 25, 2011

, ,

Moving to Google App Engine

Sunday, December 25, 2011 Marco de la Vega 22 comments
We are releasing a new VirusTotal version, most of you will not notice much of a change (other than the new layout), nonetheless, it is full of exciting features.  So as to describe them, we are also launching this new blog.

The most noticeable difference is in its backstage, we have moved to Google App Engine. We expect this to bring transparent scalability and high availability (cross your fingers) to VirusTotal. Some months ago we migrated our private API to Google's infrastructure and we could not be happier with the decision, we have forgotten about administration and we can now focus exclusively on coding.

You will also perceive that very often your file uploads will be immediate, this is because we have made use of HTML5 (in those browsers that support it) to compute the hash of the file on the client-side so as to avoid submissions of files that are already present in our store. Additionally, the maximum allowed file size has been increased to 32MB, in coherence with the App Engine's request handler limits.

Regarding the URL scanner, it is probably the VirusTotal feature that has experienced the greatest number of changes:
  • Thanks to App Engine's services the analysis is much faster than before.
  • We have integrated a couple of new engines (VX Vault, SCUMWARE.org, CLEAN MX, etc.) and the total number of scanners now adds up to 19.
  • We added an extended additional information section to the URL reports which includes detailed information returned by the scanning engines (Trend Micro description, Websense ThreatSeeker category, etc.) and by other services that provide information related to the domain/host of the scanned URL (e.g. EXPOSURE).
  • As its predecessor, the new URL scanner also downloads the files (response content) at the scanned URLs, however, this new version will only enqueue for antivirus scanning those files that are not text or similar content (HTML, XML, etc.).
  • With independence of the nature of the response content, the URL scanner will always record the server response headers, this might prove itself useful in tracking the bad guys since very often they will be making use of customised server setups that return certain headers that may be used for fingerprinting.
Neither have we forgotten about the public API and we are releasing its second version, improving the response format so as to be able to add new information to it in the future without having to change the parsers that you might have in place. This new API provides a closer integration with a new version of the private API, so that moving from one to another is far easier than before.

VirusTotal Community has also been subjected to several modifications. You may now vote a file or URL as malicious or harmless without having to comment on it. These votes are used (along with other notions provided by the tools present in VirusTotal) to build a file/URL reputation index that replaces the old safety score. This new index runs from -100 (unanimously malicious) to 100 (unanimously harmless). At the same time, there are no longer standard tags in comments, it must be you (making use of the hashtag - # - symbol) the one that explicitly defines a tag for the comment. Other changes include a new user reputation system that is detailed in the corresponding VirusTotal documentation section.

But not everything have been improvements, unfortunately, in this very first App Engine release the twitter-like public profile comments have been removed and the statistics section has been considerably reduced. The latter is something we pretend to improve over the coming weeks along with other new features. Our roadmap for the near future would, thus, look something like this:
  • Recover the ability to compact VirusTotal reports or transform them to popular formats such as bbcode, HTML, CSV, etc.
  • Include the NSRL file information, which has not been migrated for this very first App Engine release.
  • Improve the statistics section, including not only file scanning indicators but also URL scanning statistics and VirusTotal Community activity.
  • Expand the number of notions in the VirusTotal Community tab so as to create a greater buzz.
  • Include new URL and domain scanners: Malware Domain Blocklist, Palevo Tracker, Malware Patrol, etc.
  • Allow VirusTotal API users to define a URL where their scan results can be posted back as soon as they are available so as to avoid periodic polling for result retrieving.
  • Appoint VirusTotal Community moderators that may ban offensive comments, track down users faking their own or other users' reputation, and ensure the overall quality of the comments in the Community.
  • Build a malware research board that complements VirusTotal Community.
  • Translate the site to as many languages as possible.
And some other features that must remain confidential for the time being which we are completely sure that will delight software developers and site owners.

As usual, we would love to receive your feedback and suggestions, and we hope the new release results in a better VirusTotal experience.