Monday, September 24, 2012

, , , , ,

VirusTotal += Webutation

It has been a while since we last included a domain characterization dataset, we have just added Webutation and we would like to give them a really warm welcome.


The Webutation team describes its service as follows:

Webutation is an open community about Website Reputation and
  • collects user feedback and customer experience about websites.
  • tests websites against spyware, spam and scams with smart scanning technology in realtime.
  • queries
    • Google Safebrowsing against badware and phising fraud (which is used in Firefox as well and updates every half hour).
    • Website Antivirus which scans sites against adware (popups), spyware (outgoing links) and viruses.
    • WOT which collects some reviews about websites.
    • Norton Safe Web
    • as well as many other website feedback resources.
It is clear that this will surely enhance the information rendered in the additional information section of VirusTotal reports, it is precisely there where this tool appears because it characterizes domains rather than URLs, example:

https://www.virustotal.com/url/5ab7fdaa6cc0cbc8e17965044afe3c47266819335a9fa5533004113664bbb4ef/analysis/1348486392/

As it happened with the other domain characterization engines, the data returned by Webutation can be used for building customized scoring systems for full URLs.

Webutation, once again, thanks for your collaboration!

Wednesday, September 19, 2012

VirusTotal += Kingsoft

We welcome Kingsoft as a new engine working at VirusTotal. Kingsoft Security is a chinese antivirus company that has been in the market since year 2000, and now is the fifth largest Internet software company in that country.

This specific engine we've integrated is heavily based on cloud technology.

Friday, September 07, 2012

An update from VirusTotal

Our goal is simple: to help keep you safe on the web. And we’ve worked hard to ensure that the services we offer continually improve. But as a small, resource-constrained company, that can sometimes be challenging. So we’re delighted that Google, a long-time partner, has acquired VirusTotal. This is great news for you, and bad news for malware generators, because:

  • The quality and power of our malware research tools will keep improving, most likely faster; and
  • Google’s infrastructure will ensure that our tools are always ready, right when you need them.  

VirusTotal will continue to operate independently, maintaining our partnerships with other antivirus companies and security experts. This is an exciting step forward. Google has a long track record working to keep people safe online and we look forward to fighting the good fight together with them.   

VirusTotal Team

For press inquiries, please contact press@google.com.

Thursday, August 30, 2012

, , , , , ,

VirusTotal += Sucuri SiteCheck


It has been a while since we last added some new analyzer to our URL scanning engine, today we are excited to announce that Sucuri SiteCheck has become part of our small family. This is how the Sucuri team describes their service:
Sucuri SiteCheck is highly sophisticated and designed to identify a number of different malware types: Obfuscated JavaScript injections, Cross Site Scripting (XSS), Website Defacements, Hidden & Malicious iFrames, PHP Mailers, Phishing Attempts, Malicious Redirects, Backdoors (e.g., C99, R57, Webshells), Anomalies, Drive-by-Downloads, IP Cloaking, Social Engineering Attacks. There are a number of blacklisting authorities that monitor for malware, SPAM, and phishing attempts. Sucuri SiteCheck leverages the APIs for the following authorities to alert you when you’ve been flagged: Sucuri, Google Safe Browsing, Norton, AVG, Phish Tank (Phishing Specifically), McAfee SiteAdvisor.
We are extremely grateful to Sucuri, you should now see them on our URL reports, just as an example:

https://www.virustotal.com/url/78f6ade26461d84b32b857529613abbd8c9e1306fa3a4e6b9e9c8ff11dd1d82d/analysis/

You may read more about their technology at their services site.

Welcome on board Sucuri!

Wednesday, August 29, 2012

, ,

AV Comparative Analyses, Marketing, and VirusTotal: A Bad Combination


[originally written in 2007 (deprecated & offline blog), I have recovered it because remains a topical issue]

I have read today this piece of news:
"An experiment conducted at the end of March by independent security-industry benchmark website VirusTotal.com attempted to simulate a malicious attack using a long-known source of malicious code on computers. Competing with 32 rivals, only Finjan's Vital Security Web Appliance detected and blocked the malicious code in VirusTotal's tests. The computers running other products were all comprised [sic] - resulting in potential data loss and theft."
This paragraph may lead to confusion, whether that was the result intended or not, and that is why we feel compelled to declare the following at VirusTotal:

  • VirusTotal has not conducted any experiment or test related to AV comparative analyses.
  • VirusTotal has no notice whatsoever of the malicious code they refer to in this piece of news.
  • VirusTotal has never tested nor tried Finjan's security solutions.

Generally speaking, even though it may seem obvious, we must state that all anti-malware products have detection problems due to the tremendous proliferation and diversification of malware nowadays. Likewise, any product may detect a new sample on its own, either because of its heuristics or because they are the first ones to generate a specific signature. This is why it seems totally inadequate and opportunistic to claim the superiority of a product based on the result of a sole malware sample.

We are rather tired of repeating that VirusTotal was not designed as a tool to perform AV comparative analyses, but as a tool that checks suspicious samples with several AV programs and helps AV labs by forwarding them the malware they failed to detect. Those who use VirusTotal to perform AV comparative analyses should know that they are making many implicit errors in the methodology, the most obvious being:

  • VirusTotal AV engines are commandline versions, so depending on the product, they will not behave quite like the desktop versions: for instance, in such cases when desktop solutions use techniques based on behavioral analysis and count on personal firewalls that may decrease entry points and mitigate propagation, etc.
  • In VirusTotal desktop-oriented solutions coexist with perimeter-oriented solutions; heuristics in this latter group may be more aggressive and paranoid, since impact of false positives is less visible in the perimeter. It is simply not fair to compare both groups.

In general, it is not an easy task to perform a responsible and reliable AV comparative analysis; it requires having a malware collection that is both representative (nowadays it should be larger than the In-The-Wild collection) and authentic (ZOO collections are riddled with false viruses and corrupt executables). Besides, given the implementation of new AV technologies, in the case of desktop AV products, it would be necessary to execute those samples one by one in real environments with each of the resident products to see their detection capabilities and their prevention. As of today, there is no AV comparative analysis in the world that meets these basic requirements.

Monday, July 23, 2012

, , , ,

VirusTotal += Behavioural Information

There has already been some Twitter buzz around this even though we have not announced it publicly yet, indeed, some of you have already noticed it:


We have introduced behavioural information in our reports. The idea behind this is that the samples submitted to VirusTotal get executed automatically in a controlled (sandboxed) environment and the actions performed are recorded in order to give the analyst a high level overview of what the sample is doing.

Please note that there are already fantastic sandboxes out there, most noticeably:
We do not intend to compete against any of them, our aim is just to produce complementary reports to the ones generated by these awesome online sandboxes that will further help the security community.

Currently we are just processing new samples (never seen before by VirusTotal) that are Portable Executables (PEs) and are below 8MB in size. The execution is still a best effort operation and it is completely asynchronous, hence, do not expect the VirusTotal reports to have any fancy Ajax informing about the progress of the behavioural data extraction. Once you submit a file, the information will appear at a later moment in time and there are no guarantees about it being generated.

These are just a couple of examples of the reports generated (make sure you scroll down to the tabs below the antivirus verdicts table):
https://www.virustotal.com/file/2f2a645b873a5dfe7985a2c9cbfeff3424e68d9181791c908081c023c2a817b0/analysis/
https://www.virustotal.com/file/bf7ab9dcc69d8e0a1777fcb72e568708450fe32fae4d9cd67a68c27d2a2209cd/analysis/
https://www.virustotal.com/file/e5fbeab009326a5ae129942bd824868ddbdec3efc4cb48404581c290aac1b4c9/analysis/

Malekal has done a far better job than us at explaining the different fields present in the report, you may want to refer to his "VirusTotal: Behavioural information" post to learn more. Please note that the reports just show the fields that are applicable to the binary under consideration, for example, you wont see the Windows Services section if the executable is not interacting with any Windows Services.

We also saw on Twitter that Claudio Guarnieri was wondering what technology were we using to produce these reports, yes, it is your brilliant Cuckoo indeed (or nearly, some tweaks were made), so thank you very much for it, you have done an amazing job, congratulations.

Over the coming weeks we would like to work on the VirusTotal UI in order to make the behavioural information and the rest of the data on the reports (additional information and antivirus reports) more eye-catching, thus easing navigation. We are a team of hardcore engineers and as you may have noticed our taste for design is not all that great, hence, we would really appreciate some suggestions from the community regarding how could we structure our layout in order to make the reports more useful to all of you.

Once this is done we may start thinking about giving feedback to the user regarding the behavioural report generation process so that analysts can take full advantage of this new feature.

Monday, July 02, 2012

, , , , ,

VirusTotal += SecureBrain URL scanner

Some weeks ago I came across gred, the truth is I had never heard of gred before, however, I did know SecureBrain, the company behind gred. I contacted them to see whether they would be interested in introducing their malicious URL dataset in VirusTotal and they made it possible with utmost diligence.

We are extremely grateful to SecureBrain and very excited to announce that they now appear in our URL reports, just as an example:

https://www.virustotal.com/url/e8750c0b772976de6563aa81162fd319256064c76a00e0d46ab5cc5d7ebe1933/analysis/1341229461/

The SecureBrain team describe their service as follows:

Gred Security Service - Web Check
Web Check is an award winning SaaS service to help ensure you web site content is free from malware often injected by Hackers. By keeping your web content free from un-authorized malicious changes, it will help protect your customer when visiting your web site. 

You may read more about their technology at their product description site.

Welcome on board SecureBrain!