VirusTotal explained

VirusTotal
Commercial:No
Type:Internet security, file and URL analyzer
Registration:Optional
Language:Arabic, Bulgarian, Chinese, Chinese (Hong Kong), Chinese (Taiwan), Croatian, Czech, Danish, Dutch, English (US), English (GB), Estonian, Filipino, Finnish, French, German, Greek, Hebrew, Hindi, Hungarian, Indonesian, Italian, Japanese, Korean, Latvian, Lithuanian, Malay, Norwegian, Persian, Polish, Portuguese, Romanian, Russian, Serbian, Slovak, Slovenian, Spanish, Swedish, Thai, Turkish, Ukrainian, Vietnamese
Author:Hispasec Sistemas
Current Status:Active
Location:Dublin
Country:Ireland
Key People:Bernardo Quintero, Emiliano Martínez, Víctor Manuel Álvarez, Karl Hiramoto, Julio Canto, Alejandro Bermúdez, Juan A. Infantes
Area Served:Worldwide
Parent:Google LLC (2012–2018)
Chronicle (2018–present)
Gm:Bernardo Quintero

VirusTotal is a website created by the Spanish security company Hispasec Sistemas. Launched in June 2004, it was acquired by Google in September 2012.[1] [2] The company's ownership switched in January 2018 to Chronicle, a subsidiary of Google.

VirusTotal does multiscanning. It aggregates many antivirus products and online scan engines[3] [4] called Contributors.[5] In November, 2018, the Cyber National Mission Force, a unit subordinate to the U.S. Cyber Command became a Contributor.[6] The aggregated data from these Contributors allows a user to check for viruses that the user's own antivirus software may have missed, or to verify against any false positives.[7] Files up to 650 MB can be uploaded to the website, or sent via email (max. 32MB). Anti-virus software vendors can receive copies of files that were flagged by other scans but passed by their own engine, to help improve their software and, by extension, VirusTotal's own capability. Users can also scan suspect URLs and search through the VirusTotal dataset. VirusTotal uses the Cuckoo sandbox for dynamic analysis of malware.[8] VirusTotal was selected by PC World as one of the best 100 products of 2007.[9]

Products and services

Windows Uploader

VirusTotal's Windows Uploader[10] is a discontinued desktop application which integrates into File Explorer's context menu, under Send To > VirusTotal. The application also launches manually for submitting a URL or a program that is currently running in the OS.

VirusTotal stores the name and various hashes for each scanned file. Already scanned files can be identified by their known (e.g., VT default) SHA256 hash without uploading complete files. The SHA256 query URL has the form <nowiki>https://www.virustotal.com/latest-scan/SHA256</nowiki>. File uploads are normally limited to 650 MB.[11] In 2017 VirusTotal discontinued the Windows Uploader, listing the third party VirusTotalUploader program as an alternative.[12]

Uploader for Mac OS X and Linux

The Mac OS X and Linux uploaders are similar to the Windows app. One can upload a file via the app's UI or context menu and will be given back a result. The Mac OS X app can be downloaded from the VirusTotal website. To use the app on Linux, one needs to compile and build the app using the same core used in the Mac OS X application (provided in the repository).

VirusTotal for Browsers

There are several browser extensions available, such as VT4Browsers for Mozilla Firefox and Google Chrome, and vtExplorer for Internet Explorer.[13] They allow the user to download files directly with VirusTotal's web application prior to storing them in the computer, as well as scanning URLs.[14]

VirusTotal for Mobile

The service also offers an Android app,[15] which employs the public API to search any installed application for VirusTotal's previously scanned ones and show its status. Any application not previously scanned can be submitted, but an API key must be provided and other restrictions to public API usage may apply .

Public API

VirusTotal provides a public API as a free service. It provides automation for some of its online features such as to "upload and scan files, submit and scan URLs, access finished scan reports and make automatic comments on URLs and samples". Some restrictions apply for requests made through the public API, such as requiring an individual API key freely obtained by online signing up, low priority scan queue, and limited number of requests per time frame.[16]

Antivirus products

Antivirus engines used for detection for uploading files.[17]

Website/domain scanning engines and datasets

Antivirus scanning engines used for URL scanning.

File characterization tools & datasets

Utilities used to provide additional info on uploaded files.

Privacy

Files uploaded to VirusTotal may be shared freely with anti-malware companies and will also be retained in a store. The VirusTotal About Page states under VirusTotal and confidentiality:[18]

Files and URLs sent to VirusTotal will be shared with antivirus vendors and security companies so as to help them in improving their services and products. We do this because we believe it will eventually lead to a safer Internet and better end-user protection.

By default any file/URL submitted to VirusTotal which is detected by at least one scanner is freely sent to all those scanners that do not detect the resource. Additionally, all files and URLs enter a private store that may be accessed by premium (mainly security/antimalware companies/organizations) VirusTotal users so as to improve their security products and services.

See also

Notes and References

  1. Web site: Google Acquires Online Virus, Malware and URL Scanner VirusTotal. Lardinois. Frederic. September 7, 2012. TechCrunch. 12 April 2013.
  2. Web site: VirusTotal Team . An update from VirusTotal . Blog.virustotal.com . 7 September 2012 . 3 June 2016.
  3. Web site: Credits & Acknowledgements : About VirusTotal . VirusTotal . 6 July 2014 .
  4. Web site: Example Report . Virustotal.com . 2 April 2014 . 3 June 2016.
  5. Web site: Contributors. VirusTotal.
  6. Web site: New CNMF initiative shares malware samples with cybersecurity industry > U.S. Cyber Command > News . www.cybercom.mil . 22 February 2022 . https://web.archive.org/web/20200930004308/https://www.cybercom.mil/Media/News/Article/1681533/new-cnmf-initiative-shares-malware-samples-with-cybersecurity-industry/ . 30 September 2020 . dead.
  7. Web site: About VirusTotal . Virustotal.com . 3 June 2016 . https://web.archive.org/web/20100812025330/http://www.virustotal.com/sobre.html . 12 August 2010 . dead .
  8. Web site: Credits of VirusTotal . Virustotal.com . November 27, 2021.
  9. Web site: The 100 Best Products of 2007. Dahl. Eric. May 21, 2007. PCWorld. IDG Consumer & SMB. 3 June 2016.
  10. Web site: VirusTotal Windows Desktop Application. VirusTotal. 16 February 2014.
  11. Web site: Should I upload files larger than 650MBs ?. FAQ. VirusTotal. 11 July 2024.
  12. Web site: Desktop Apps . VirusTotal . VirusTotal . December 24, 2018.
  13. Web site: VirusTotal. VirusTotal.
  14. Web site: VTzilla: Mozilla Firefox Browser Extension. VirusTotal. 23 March 2014.
  15. Web site: VirusTotal for Android. VirusTotal. 23 March 2014.
  16. Web site: VirusTotal Public API v2.0. VirusTotal. 23 March 2014.
  17. Web site: Credits & Acknowledgements. Virustotal. Virustotal. 3 June 2016.
  18. Web site: VirusTotal. support.virustotal.com. 2019-10-24.