Thursday, August 30, 2012

, , , , , ,

VirusTotal += Sucuri SiteCheck


It has been a while since we last added some new analyzer to our URL scanning engine, today we are excited to announce that Sucuri SiteCheck has become part of our small family. This is how the Sucuri team describes their service:
Sucuri SiteCheck is highly sophisticated and designed to identify a number of different malware types: Obfuscated JavaScript injections, Cross Site Scripting (XSS), Website Defacements, Hidden & Malicious iFrames, PHP Mailers, Phishing Attempts, Malicious Redirects, Backdoors (e.g., C99, R57, Webshells), Anomalies, Drive-by-Downloads, IP Cloaking, Social Engineering Attacks. There are a number of blacklisting authorities that monitor for malware, SPAM, and phishing attempts. Sucuri SiteCheck leverages the APIs for the following authorities to alert you when you’ve been flagged: Sucuri, Google Safe Browsing, Norton, AVG, Phish Tank (Phishing Specifically), McAfee SiteAdvisor.
We are extremely grateful to Sucuri, you should now see them on our URL reports, just as an example:

https://www.virustotal.com/url/78f6ade26461d84b32b857529613abbd8c9e1306fa3a4e6b9e9c8ff11dd1d82d/analysis/

You may read more about their technology at their services site.

Welcome on board Sucuri!

Wednesday, August 29, 2012

, ,

AV Comparative Analyses, Marketing, and VirusTotal: A Bad Combination


[originally written in 2007 (deprecated & offline blog), I have recovered it because remains a topical issue]

I have read today this piece of news:
"An experiment conducted at the end of March by independent security-industry benchmark website VirusTotal.com attempted to simulate a malicious attack using a long-known source of malicious code on computers. Competing with 32 rivals, only Finjan's Vital Security Web Appliance detected and blocked the malicious code in VirusTotal's tests. The computers running other products were all comprised [sic] - resulting in potential data loss and theft."
This paragraph may lead to confusion, whether that was the result intended or not, and that is why we feel compelled to declare the following at VirusTotal:

  • VirusTotal has not conducted any experiment or test related to AV comparative analyses.
  • VirusTotal has no notice whatsoever of the malicious code they refer to in this piece of news.
  • VirusTotal has never tested nor tried Finjan's security solutions.

Generally speaking, even though it may seem obvious, we must state that all anti-malware products have detection problems due to the tremendous proliferation and diversification of malware nowadays. Likewise, any product may detect a new sample on its own, either because of its heuristics or because they are the first ones to generate a specific signature. This is why it seems totally inadequate and opportunistic to claim the superiority of a product based on the result of a sole malware sample.

We are rather tired of repeating that VirusTotal was not designed as a tool to perform AV comparative analyses, but as a tool that checks suspicious samples with several AV programs and helps AV labs by forwarding them the malware they failed to detect. Those who use VirusTotal to perform AV comparative analyses should know that they are making many implicit errors in the methodology, the most obvious being:

  • VirusTotal AV engines are commandline versions, so depending on the product, they will not behave quite like the desktop versions: for instance, in such cases when desktop solutions use techniques based on behavioral analysis and count on personal firewalls that may decrease entry points and mitigate propagation, etc.
  • In VirusTotal desktop-oriented solutions coexist with perimeter-oriented solutions; heuristics in this latter group may be more aggressive and paranoid, since impact of false positives is less visible in the perimeter. It is simply not fair to compare both groups.

In general, it is not an easy task to perform a responsible and reliable AV comparative analysis; it requires having a malware collection that is both representative (nowadays it should be larger than the In-The-Wild collection) and authentic (ZOO collections are riddled with false viruses and corrupt executables). Besides, given the implementation of new AV technologies, in the case of desktop AV products, it would be necessary to execute those samples one by one in real environments with each of the resident products to see their detection capabilities and their prevention. As of today, there is no AV comparative analysis in the world that meets these basic requirements.

Monday, July 23, 2012

, , , ,

VirusTotal += Behavioural Information

There has already been some Twitter buzz around this even though we have not announced it publicly yet, indeed, some of you have already noticed it:


We have introduced behavioural information in our reports. The idea behind this is that the samples submitted to VirusTotal get executed automatically in a controlled (sandboxed) environment and the actions performed are recorded in order to give the analyst a high level overview of what the sample is doing.

Please note that there are already fantastic sandboxes out there, most noticeably:
We do not intend to compete against any of them, our aim is just to produce complementary reports to the ones generated by these awesome online sandboxes that will further help the security community.

Currently we are just processing new samples (never seen before by VirusTotal) that are Portable Executables (PEs) and are below 8MB in size. The execution is still a best effort operation and it is completely asynchronous, hence, do not expect the VirusTotal reports to have any fancy Ajax informing about the progress of the behavioural data extraction. Once you submit a file, the information will appear at a later moment in time and there are no guarantees about it being generated.

These are just a couple of examples of the reports generated (make sure you scroll down to the tabs below the antivirus verdicts table):
https://www.virustotal.com/file/2f2a645b873a5dfe7985a2c9cbfeff3424e68d9181791c908081c023c2a817b0/analysis/
https://www.virustotal.com/file/bf7ab9dcc69d8e0a1777fcb72e568708450fe32fae4d9cd67a68c27d2a2209cd/analysis/
https://www.virustotal.com/file/e5fbeab009326a5ae129942bd824868ddbdec3efc4cb48404581c290aac1b4c9/analysis/

Malekal has done a far better job than us at explaining the different fields present in the report, you may want to refer to his "VirusTotal: Behavioural information" post to learn more. Please note that the reports just show the fields that are applicable to the binary under consideration, for example, you wont see the Windows Services section if the executable is not interacting with any Windows Services.

We also saw on Twitter that Claudio Guarnieri was wondering what technology were we using to produce these reports, yes, it is your brilliant Cuckoo indeed (or nearly, some tweaks were made), so thank you very much for it, you have done an amazing job, congratulations.

Over the coming weeks we would like to work on the VirusTotal UI in order to make the behavioural information and the rest of the data on the reports (additional information and antivirus reports) more eye-catching, thus easing navigation. We are a team of hardcore engineers and as you may have noticed our taste for design is not all that great, hence, we would really appreciate some suggestions from the community regarding how could we structure our layout in order to make the reports more useful to all of you.

Once this is done we may start thinking about giving feedback to the user regarding the behavioural report generation process so that analysts can take full advantage of this new feature.

Monday, July 02, 2012

, , , , ,

VirusTotal += SecureBrain URL scanner

Some weeks ago I came across gred, the truth is I had never heard of gred before, however, I did know SecureBrain, the company behind gred. I contacted them to see whether they would be interested in introducing their malicious URL dataset in VirusTotal and they made it possible with utmost diligence.

We are extremely grateful to SecureBrain and very excited to announce that they now appear in our URL reports, just as an example:

https://www.virustotal.com/url/e8750c0b772976de6563aa81162fd319256064c76a00e0d46ab5cc5d7ebe1933/analysis/1341229461/

The SecureBrain team describe their service as follows:

Gred Security Service - Web Check
Web Check is an award winning SaaS service to help ensure you web site content is free from malware often injected by Hackers. By keeping your web content free from un-authorized malicious changes, it will help protect your customer when visiting your web site. 

You may read more about their technology at their product description site.

Welcome on board SecureBrain!

Wednesday, June 27, 2012

, , , ,

VirusTotal += Cyscon SIRT URL Scanner


We have just introduced Cyscon SIRT (C-SIRT) malicious URL dataset in VirusTotal's URL scanning engine.

This is an example of the Cyscon (C-SIRT) output, do not forget to refer to the additional information section in order to see the threat information provided:

https://www.virustotal.com/url/252ee025a4a6b57f0b302a97f44ea305863a4cb9419e6f141161cd72b47addb0/analysis/1340792226/

The Cyscon team describe their service as follows:
cyscon & it’s partners/friends provide a “Security Incident Reporting Service” (SIRT) to any network owner, who is interested in receiving automated alerts regarding malware, phishing & other security related issues within his network.
You may read more about it on their web site.

We would like to give the Cyscon team a really warm welcome and thank them for allowing us to keep improving VirusTotal!

Friday, June 15, 2012

, , , , , , ,

VirusTotal += Sophos URL scanner

Lately we had been introducing many domain characterization datasets/tools in our URL scanning engine, today we are excited to announce that Sophos' fully-fledged URL filtering solution has become part of VirusTotal and will be characterizing both full URLs and domains.

This is an example of the Sophos output with their malicious test domain, do not forget to refer to the additional information section to see the threat information provided:

https://www.virustotal.com/url/d77e1526bbb2941575cd25edfe23bac54caa38969c4d63c9a85f5e09d4d2d01b/analysis/1339745884/

The Sophos team describe their solution as follows:
You can connect your computers to our constantly updated list of millions of infected websites, so your users can’t get to them — even when they're outside your gateway protection. And we keep it updated, adding around 40,000 new sites every day. Sophos Live URL Filtering is included in all of our Endpoint products and suites.  
You may read more about it on their web site.

We would like to give Sophos URL scanner a really warm welcome and thank them for allowing us to keep improving VirusTotal!

Monday, June 11, 2012

, , , ,

VirusTotal for Android

Years ago there was much fuzz about mobile malware, yet the devices themselves were so limited that the claims made were considered no more than hypes developed exclusively with marketing purposes so as to sell more mobile phone antivirus solutions.

The rise of smartphones has made what once were deceitful claims a real threat. Attackers are well aware that users are moving to mobile devices and performing most of their online activity on them (ebanking, social networking, etc.), and thus have started to target these platforms. Examples of these threats are the Zeus Mitmo banking trojan, fake Angry Birds or Opfake.

VirusTotal is strongly committed to making the Internet a safer place by helping end-users in securing their systems, be it desktop PCs or mobile phones. This is why we have developed and released VirusTotal for Android, an Android application that lets you check all the applications on your phone/mobile device against VirusTotal.



You can download the application directly from the Google Play store:

https://play.google.com/store/apps/details?id=com.virustotal

The application will perform hash lookups for all the applications installed in your mobile device. If the application was scanned by VirusTotal in the past and detected by one or more antivirus vendors its results icon will be a red droid, green if it was not detected. A blue question mark will appear next to applications that are unknown to VirusTotal.

You can upload to VirusTotal any application that was not seen in the past, in order to do this you will have to provide your VirusTotal Community credentials, the application will then use your API key to perform the uploads. The file will enter a low priority scanning queue and the application will trigger an Android notification whenever the scan ends.

The application has some other features such as rescanning, filtering or detailed results, read more about  them at its documentation site. The application was initially coded as part of a University project supervised by Urko Zurutuza from the University of Mondragon, it was later polished and recoded by Anthony Desnos, the most recent member of our team and our resident Android expert. We hope you find it useful!

Please note that VirusTotal for Android does not prive real-time protection and, so, is no substitute for any antivirus product, just a second opinion regarding your apps.