Tuesday, January 21, 2014

, , , , , ,

VirusTotal += Qihoo-360

We welcome Qihoo-360 as a new engine working at VirusTotal. In the words of the company:

"QVM is Qihoo 360’s proprietary technology that detects malware through an artificial-intelligence algorithm capable of machine learning to recognize new forms of malware. QVM technology offers a robust model for recognizing malware characteristics using the massive amount of data that we have compiled on confirmed malware in our blacklist and verified safe programs files in our whitelist. This model is used as a basis for a detection algorithm which is automatically enhanced and updated with new malware samples submitted by our users to our servers.

Program files that do not appear in our blacklist and whitelist are scanned using QVM, and any ''hits'' returned by this technology are presumed to be malicious and removed or quarantined. As malware is constantly being created or morphing, QVM has the advantage of being able to detect threats that have not been previously identified. According to PC Security Labs, an independent security product test organization, QVM has a detection rate of 74.9% for unknown new malware, which surpasses most heuristic detection technologies."

Wednesday, November 27, 2013

, , ,

VirusTotal += Ad-Aware

We welcome Ad-Aware as a new engine working at VirusTotal. In the words of Lavasoft:

"Ad-Aware 11 is Lavasoft’s next generation anti-malware product that includes behavior based heuristics, generic detection routines and virtual machine analysis for executable files that is capable of detecting zero-day and new/unknown malware. It has support for more than 100 packers and runs full multithreading and concurrent scans."

Wednesday, November 13, 2013

, , , , ,

VirusTotal += malwares.com URL checker

Many security industry actors build solutions that lie in the perimeter of networks, inspecting traffic and discriminating potentially malicious content. One of these solutions is SIMBA from Saint Security (others include FireEye, Fidelis XPS, Damballa, etc.).

In inspecting traffic, these solutions have a privileged position to perform correlations to discover and characterize malicious patterns, this is what allows these companies to discover thousands of malicious URLs and files every day. Saint Security has made part of their discriminatory logic available at malwares.com:
As a cloud-based malicious codes database system, malwares.com is a one-stop service to collect, analyze and detect various malicious codes or malwares such as Trojans, Viruses, Worms so that customers or end-users can make proper security policies to take countermeasures against security threats.
Today we are excited to announce that malwares.com has been integrated in VirusTotal as a URL checker and as of today URL scans will be enriched with their dataset of malicious verdicts. This inclusion is very interesting as it covers much of the threat landscape seen in South Korea, a clear example of this is the following report:
https://www.virustotal.com/en/url/3625ed7252e98152ad781b3deea92038bc1d416c343f8b7bfe2a3ec8ca5b3727/analysis/

Welcome on board and thanks for joining us!

Thursday, October 31, 2013

, , , ,

VirusTotal += AegisLab WebGuard

Our effort to pump up our URL scanner backbone continues, today we are excited to announce the integration of AegisLab WebGuard, a concise malicious URL database to prevent malicious URLs whose characteristics are described by its developers as:
Fast update and leave less open window for attack. Less false positive than other web filter DBs. Website hijacking prevention. Concise malicious URL database. Including: Drive-by-Downloads, BlackHat SEOFake Anti-Virus, Installer and Updates, Scarewares and etc.
You can read more about the kind of threats that AegisLab WebGuard intercepts in this blog post: http://blog.aegislab.com/?p=78

Welcome on board guys, thanks for joining VirusTotal!
, , ,

VirusTotal += RiskAnalytics AutoShun

What is AutoShunAutoShun is a small appliance that protects your network from attacks. Automatically updates itself within minutes to bidirectionally block new threats. One AutoShun device is able to protect an entire site. Configurable whitelist to ensure business partner communications. Ability to block traffic by geographic regions. Reporting on all blocked threats and traffic.
This is the way the RiskAnalytics team describes its AutoShun solution. As you may infer, in order to be able to bidirectionally block threats, AutoShun works (among other technologies and logistics) with a dataset of online threats. From now onward VirusTotal users will also be able to check their submitted URLs against this dataset, which appears in VirusTotal under the name of AutoShun.

Thank you RiskAnalytics!

Monday, October 28, 2013

, , ,

VirusTotal += Emsisoft URL scanner

Emsisoft has been a long-time friend of VirusTotal, enhancing our file scan reports with their antivirus signatures. Its anti-malware product incorporates different protection layers, one of which they describe as follows:
SURF PROTECTION: If you unintentionally try to access a website that spreads trojans or spyware, Emsisoft Anti-Malware will prevent you from doing so. The built-in list of known dangerous and fraudulent websites is automatically updated every hour.
The guys over at Emsisoft are committed to continue making the Internet a safer place, as of today, in addition to their file scanner, VirusTotal URL scan reports will also integrate their threat intelligence regarding malicious URLs.

This is an example of a URL scan report where they produce a malicious verdict:
https://www.virustotal.com/en/url/eddc45e5147f369d37f2146388f3d96a02408ab30cbf9dc3e8f9cd0c896837e5/analysis/1382951589/

We are really grateful for the quick turnaround that the Emsisoft team has had in integrating their solution, thank you!

Thursday, October 24, 2013

, , ,

Sigcheck += VirusTotal

Windows Sysinternals is a part of the Microsoft TechNet website which offers technical resources and utilities to manage, diagnose, troubleshoot, and monitor a Microsoft Windows environment.

The Sysinternals collection includes awesome tools such as Process Explorer, AutoRuns or Sigcheck, among many others. I can still remember the times where I had to investigate remote e-banking user PCs in order to identify the culprit of a fraudulent transaction (Zbot, Sinowal, Ambler, etc.), at the time, I do not know what I would have done without AutoRuns and ProcessExplorer.

What I am trying to say is that at VirusTotal we are great fans of the Sysinternals utilities. It has been a while since we integrated Sigcheck in VirusTotal, providing extremely useful information about PE signatures, data that can be used in goodware vs. malicious scoring systems, to identify the author of a legitimate piece of software or to spot compromised certificates used in signing malware, just a couple of practical use cases.

Today we are delighted to announce that the relationship has become reciprocal and Mark Russinovich has integrated VirusTotal in Sigcheck. With a simple command-line option you are now able to query the results of a given file in VirusTotal, read more about it at the official site: http://technet.microsoft.com/en-us/sysinternals/bb897441

Thank you Mark! It has been a pleasure working together!