Friday, November 30, 2012

, , , , , , ,

VirusTotal += ADMINUSLabs

Continuing the trend of engine inclusions we have just added ADMINUSLabs as a new URL scanner. In words of ADMINUSLabs itself:
ADMINUSLABS has built an incredibly robust and comprehensive binaries and malware collection and analysis set of tools, enabling organizations of all sizes to leverage the data analyzed and threats monitored to build better defense system. With clients and partners in every continent, ADMINUSLABS solutions offer industry leading technology, flexibility, cost effectiveness, and service levels.
ADMINUSLabs has shared its malicious URL dataset with VirusTotal, from now on, whenever a user submits a URL to VirusTotal for scanning it will also get checked against ADMINUSLabs' dataset and flagged as malicious if present in it. This is an example of a report with one such detection:

https://www.virustotal.com/url/0048c271f6c90bc6959c0eb91ed139692a1ec0f0f4b3328a9ad09baad010c7c2/analysis/1354276484/

ADMINUSLabs' dataset is very large and gets updated several times per day with thousands of new URLs, this is an excellent addition, many thanks and welcome on board!

VirusTotal += Malwarebytes

We welcome Malwarebytes (aka MBAM) as a new engine working at VirusTotal. Malwarebytes was first released in 2008.

VirusTotal += NANO

We welcome NANO as a new engine working at VirusTotal. NANO is a russian antivirus company that has been in the market since year 2009.

Wednesday, November 28, 2012

, , , , , ,

VirusTotal += Malekal

We are back with new inclusions in VirusTotal's URL scanning engine. This time we are excited to add Malekal's malicious URL dataset to our aggregate scanner.

Malekal is a site maintained by one of our most active VirusTotal Community users, @Malekal_morte. The site mostly deals with malware and antivirus but has support forums that help users in many other ICT fields. As a result of the support he gives and the research he conducts, Malekal comes across many malware samples an malicious URLs as we can see in his public listing (21211 documented files since March 2010 at the time of this article).

Malekal's malicious URL dataset is now being used to check whether any URL submitted by a user to VirusTotal is present in it and if so it is flagged accordingly. You should now be able to see these detections in the URL reports, just as an example:

https://www.virustotal.com/url/04d67bdebd8a74eaaac37212e35848203f55823c157aab958ad4415d1b7ba344/analysis/1354089612/

We are extremely grateful to Malekal, welcome on board!

Thursday, October 11, 2012

, , ,

Pimping up VTchromizer

Among the goodies offered by VirusTotal to the community we can find VTchromizer. VTchromizer is a Google Chrome browser extension that simplifies the process of scanning Internet resources with VirusTotal. It allows you to scan links (including links to files) directly with VirusTotal's web application. It will scan the submitted URLs with URL scanners and the content downloaded from the scanned site with VirusTotal's antvirus solutions.

Some days ago Kyle Creyts from Lastline sent us an email asking us for permission to publish a small Chrome extension that made use of VirusTotal:

This extension makes a new "Get VT analysis" context menu entry when you select text and right click on it.
It's quite simple to use. You select the text of a hash in your browser, right click on it, and select "Get VT analysis for %s" from the context menu (where %s is the hash). I have it set up to use the selection length to validate that the input is a valid {md5,sha1,sha256} hash. I could easily add the ability to validate the character range (hex).

We love when the community builds tools with VirusTotal, we are absolutely in favour  of promoting third-party altruist efforts that will improve the overall end-user security. Hence, we strongly encourage Kyle to publish his extension, it is a really good idea.

It is such a good idea that we did not hesitate to include that functionality in our own official extension:

https://chrome.google.com/webstore/detail/vtchromizer/efbjojhplkelaegfbieplglfidafgoka

As of version 1.2, whenever you select a text and right-click on it a context menu will appear that allows you to check the selected text with VirusTotal:

  • If the selection is an md5, sha1 or sha256 hash the extension will display the VirusTotal report for the file with that hash.
  • If the selection is any other text the extension will look for any comments in VirusTotal Community tagged with the given term.

This is in addition to the traditional feature that allows you to right-click on any link and submit it for scanning.


Thanks for the idea Kyle! As usual, if you have any suggestions or feature requests please do not hesitate to contact us, we will be more than happy to consider and implement them.

Wednesday, October 10, 2012

, , , , ,

VirusTotal += Netcraft

Netcraft Toolbar is one of the most known antiphishing/antimalware browser toolbars out there. The Netcraft team describes its software as follows:
The Toolbar community is effectively a giant neighbourhood watch scheme, empowering the most alert and most expert members to defend everyone within the community against phishing attacks. Once the first recipients of a phishing mail have reported the target URL, it is blocked for community members as they subsequently access the URL. Widely disseminated attacks (people construct phishing attacks send literally millions of emails in the expectation that some will reach customers of the bank) simply mean that the phishing attack will be reported and blocked sooner.
The Netcraft Toolbar also:

  • Traps suspicious URLs containing characters which have no common purpose other than to deceive.
  • Enforces display of browser navigational controls (toolbar & address bar) in all windows, to defend against pop up windows which attempt to hide the navigational controls.
  • Clearly displays sites' hosting location, including country, helping you to evaluate fraudulent urls (e.g. the real citibank.com or barclays.co.uk sites are unlikely to be hosted in the former Soviet Union).
Taking all of this into account we are really excited to announce that Netcraft has been integrated in VirusTotal, you will now see it as another URL scanner in VirusTotal's URL scanning service.

With this addition we have already over 30 URL scanners and are looking forward to be in the forties as soon as possible, so if you have an interesting malicious URL dataset or URL scanner please do not hesitate to contact us, we will be more than happy to include you!

Thank you Netcraft team!

Monday, September 24, 2012

, , , , ,

VirusTotal += Webutation

It has been a while since we last included a domain characterization dataset, we have just added Webutation and we would like to give them a really warm welcome.


The Webutation team describes its service as follows:

Webutation is an open community about Website Reputation and
  • collects user feedback and customer experience about websites.
  • tests websites against spyware, spam and scams with smart scanning technology in realtime.
  • queries
    • Google Safebrowsing against badware and phising fraud (which is used in Firefox as well and updates every half hour).
    • Website Antivirus which scans sites against adware (popups), spyware (outgoing links) and viruses.
    • WOT which collects some reviews about websites.
    • Norton Safe Web
    • as well as many other website feedback resources.
It is clear that this will surely enhance the information rendered in the additional information section of VirusTotal reports, it is precisely there where this tool appears because it characterizes domains rather than URLs, example:

https://www.virustotal.com/url/5ab7fdaa6cc0cbc8e17965044afe3c47266819335a9fa5533004113664bbb4ef/analysis/1348486392/

As it happened with the other domain characterization engines, the data returned by Webutation can be used for building customized scoring systems for full URLs.

Webutation, once again, thanks for your collaboration!