Pages:
Author

Topic: [Guide] Virustotal scan guideline to detect viruses, trojans, malwares, worms (Read 1107 times)

copper member
Activity: 1582
Merit: 1319
I'm sometimes known as "miniadmin"
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
For xxxx wallet, detection ratio is 0/69, it means no threat found, and the wallet is safely to install on your devices.
I wish it would be so simple. Its very good indication but you can't be 100% sure file is safe.
Especially when wallets from new coins are created by programmers that are capable to hide their malicious functions from virusdetectors. Why?
Because viruses detect mostly already known and reported threats. If its new, they won't detect it unless it contains very common malicious code (copied for example from existing viruses/trojans).

Be safe.
Generally, I mentioned that is only for well-known threats, not newborn ones. Anyway, your reminder makes sense and I know readers will likely forget what you read in my note section, so I added 'well-known' in the phrase you pointed out too.
Thanks.
Because antivirus softwares or internet security softwares only help us from well-known threats.
legendary
Activity: 2296
Merit: 1014
For xxxx wallet, detection ratio is 0/69, it means no threat found, and the wallet is safely to install on your devices.
I wish it would be so simple. Its very good indication but you can't be 100% sure file is safe.
Especially when wallets from new coins are created by programmers that are capable to hide their malicious functions from virusdetectors. Why?
Because viruses detect mostly already known and reported threats. If its new, they won't detect it unless it contains very common malicious code (copied for example from existing viruses/trojans).

Be safe.
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
Appreciated given sites from @TryNinja and MagicByt3. I will look at them further. I might or might not add them into OP.
hero member
Activity: 1194
Merit: 573
OGRaccoon
Great topic I would like to throw into the ring:

https://www.hybrid-analysis.com/

It is a very advanced tool for running programs in VM state and it logs everything the software is doing and gives a nice report back.
I highly recommend the use of this in conjunction with virus total and your own security screening software if you use such.

legendary
Activity: 2758
Merit: 6830
I like using https://any.run/ to check for files. It gives you more understanding on what the file does than VirusTotal.

It basically deploys a temporary VM so you can run the file and see what it is doing (which files is creating, what HTTP requests it is doing, etc...). You can actually grab a lot of information from it.

VirusTotal is cool too, but it is more about checking for heuristics instead of trully analysing the software.
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
I thank you for doing this, it looks good, but I will wait to see confirmations from your locals, merit sources for instance, because I don't know your language and it does not make sense to check the translation's quality by using Google. As a promised, when quality of this translation confirmed, I will add it into OP, and give you my small award. Please wait.
legendary
Activity: 2296
Merit: 1014
By the way, sometimes we get to see false positive and negatives from virustotal.
Results from virustotal should not be taken as final.

All it takes here is experience. You will see in time which is false positive and which are not with close to 100% certainty.
Great guide overall, virustotal helped through the years thousands of people to not get infected.
sr. member
Activity: 896
Merit: 272
OWNR - Store all crypto in one app.
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
< ... >
Thanks, I updated the OP. I knew that having healthy behaviour and habits on Internet is the best way to protect our devices and assets. You are right that any kind of Antivirus softwares or internet security softwares only help us from well-known threats. In reality, hackers always innovate new threats, so maintaining healthy habits / behaviours is key.
- Having and maintaining healthy habits and behaviours on Internet space are the best way to protect your devices and your assets.
Because antivirus softwares or internet security softwares only help us from well-known threats. @Pmalek mentioned about it there:[/color]
Unfortunately Virustotal can only help you with already known threats and viruses by comparing the code to known threats. If you are unlucky and download a file that contains a fresh code with a virus then Virustotal will not be able to help you since it is the first time they see the code. The results can come back as clean while in fact you get infected and if you do a 2nd scan in a few days you see that some antivirus engines are already registering the file as a threat.
bob123's suggestion (click on quote link to see full post):
Using AV's (whether paid ones on your computer, or online services like virustotal) does only protect you against 1) known and very wide-spread malware and 2) malware created by script-kiddies or any other non-commercial cyber criminals.


By the way, I updated this one:
Additionally, there are tips to check Github account's reliabilty first (such as account age, activity, past reputation) before thinking of downloading sources from Github.
https://bitcointalksearch.org/topic/m.50883346


Reference
< ... >
(3) Just because It’s on GitHub. It doesn’t mean it’s safe>
legendary
Activity: 1624
Merit: 2481
Unfortunately Virustotal can only help you with already known threats and viruses by comparing the code to known threats. If you are unlucky and download a file that contains a fresh code with a virus then Virustotal will not be able to help you since it is the first time they see the code. The results can come back as clean while in fact you get infected and if you do a 2nd scan in a few days you see that some antivirus engines are already registering the file as a threat.

This is why I wrote those recommendations.
Notes:
- Please remember that this one is a free online service, it should be used only as substitution of professional antivirus or internet security softwares for someone who don't have those softwares on their devices (lack of money, or anything else).
- You all should protect yourself better by spending money to own antivirus or internet security softwares on your devices.
- It is very cost-effective investment for your assets.

Virustotal, and other online virus scanning sites, should only be used for people who don't have money to buy professional softwares.
For someone, who already own professional softwares, they obviously can use those sites as supplementary stuffs to make pre-scan before downloading files and scan again by their softwares.


Your recommendations do not mentioned what Pmalek said.. in any word.

Virustotal and any other AV software can only recognize malware by 2 approaches:
  • Heuristics
  • Behavior analysis

Regarding Heuristics:
If the malware is either 1) new or 2) modified so that these AV's don't have it in their database yet -> No Heuristic to match the malware with.

Regarding Behavior analysis:
If the malware does not run malicious code when being analyzed (can be done with multiple techniques, e.g. checking whether being run in a sandbox) -> Not triggering the behavior analysis.


Now, if we combine these two statements, it becomes clear that it is quite easy to create malware which is completely undetected from AV's (at least until enough people have been infected with it and AV's have manually reviewed and sigged the malware as such).


Using AV's (whether paid ones on your computer, or online services like virustotal) does only protect you against 1) known and very wide-spread malware and 2) malware created by script-kiddies or any other non-commercial cyber criminals.
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
Prepare as best tools to protect our devices (from computers, laptops to mobile devices) is the first step to protect our wallets from attackers, whom always figure out weaknesses of system and abuse our stupid activities on our devices to steal all of our money.
Today, I found this thread, and you can read it to know better use cases of Virustotal.
Virustotal shows threat in Github App for Windows! (by wwzsocki)
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
Note that you should create a free account on the site in order to have some additional features, for free. However, I always recommend to use professional softwares. It's ridiculous to save small amount of money by using free sites, with less powerful protection for your assets, then eventually your fortune get stolen by bad guys.
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
I really appreciated your help, khaled0111. I knew you because you joined some campaigns managed by Hhampuz, from which you obviously demonstrated that you are one of forum assets. And, you are the first ones left reply in the translation topic, so this is why I asked for your confirmations.
I added his translation into my OP and hope it might be helpful for Arabians.
He did a great job indeed, I vouch for the quality of his work.
legendary
Activity: 2506
Merit: 2832
Top Crypto Casino
< ... >
It seems that you made great works with your translation. Nevertheless, I don't know Arabic, so maybe I need confirmations from some users that you actually translate it well. Maybe khaled0111 can help.
He did a great job indeed, I vouch for the quality of his work.
I would merit him by myself if I could. unfortunately I am in shortage of sMerits right now.

I appreciate your trust in me. It means a lot to me.
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
< ... >
You are welcome. It seems that you made great works with your translation. Nevertheless, I don't know Arabic, so maybe I need confirmations from some users that you actually translate it well. Maybe khaled0111 can help.
Wait till confirmations done, I will send you reward for your work and I will add it into OP, fella.
legendary
Activity: 1708
Merit: 1364
🔃EN>>AR Translator🔃
I translated the topic and post it in my local board (Arabic)
Link to translated topic: https://bitcointalksearch.org/topic/--5133344

Thanks OP for your kindness when i asked your permission to do this.

Keep up the good work Smiley
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
By chance, I saw the following topic, that can be used as an example for the topic.
Please, feel free to visit it and see a case study on potential threats found and warned by using virustotal to scan.
🔴🚀[ANN]🚀🔴 [POS] HYPNOSECOIN (Crex24) ..found VIRUS
legendary
Activity: 2170
Merit: 3858
Farewell o_e_l_e_o
Unfortunately Virustotal can only help you with already known threats and viruses by comparing the code to known threats. If you are unlucky and download a file that contains a fresh code with a virus then Virustotal will not be able to help you since it is the first time they see the code. The results can come back as clean while in fact you get infected and if you do a 2nd scan in a few days you see that some antivirus engines are already registering the file as a threat.
This is why I wrote those recommendations.
GUIDELINE TO USE VIRUSTOTAL.COM TO SECURE YOUR ASSETS FOR FREE


Notes:
- Please remember that this one is a free online service, it should be used only as substitution of professional antivirus or internet security softwares for someone who don't have those softwares on their devices (lack of money, or anything else).
- You all should protect yourself better by spending money to own antivirus or internet security softwares on your devices.
- It is very cost-effective investment for your assets.

Virustotal, and other online virus scanning sites, should only be used for people who don't have money to buy professional softwares.
For someone, who already own professional softwares, they obviously can use those sites as supplementary stuffs to make pre-scan before downloading files and scan again by their softwares.
Pages:
Jump to: