VirusTotal and 100% detection.. Oops.
Like they said, in all case the problem is from the trust of the Crystal Security staff to
VirusTotal.
It's was a default server from DarkComet Remote Administration Tools
(Trojan), lot of companies detect it, it's like
EICAR but VirusTotal has only the hash of the files, that's is
very easy to change, so Crystal Security can detect only VirusTotal scanned files, not real potential infections that you can be infected.
I have already mentioned that on an older post.
People thinks that VirusTotal is the best way for a 100% detection,
it's totally wrong. And my company was accused of use of VT
(Tiranium) due to the detection rate, that's another subject.
Hackers starts sharing them malicious files on all the internet. No one will thinks to scan it on VirusTotal because they trust the web site or them anti-virus.
Lot of anti-virus companies receive suspicious files automatically from them users, for them protection.
And some anti-virus companies uses them security toolbars to logs them users visited web sites to analyze them in deep.
Your anti-virus will detect any undetected attacks more faster than VirusTotal and the scan on VirusTotal of the malicious file is not guaranteed. And the softwares of anti-virus on VirusTotal are not updated quickly like on the users computers.
For malware like the DarkComet Remote Administration Tools servers, companies favorite
HEX detections
(one/two/three or more parts from the codes of the program).
And others companies favorite icon detections too. Others, favorite JMP
(debugg) or Entry Point
(PE, the entry code that the program starts) detections.
(HEX codes from a program)
This system help the companies to detect ALL new created malware from a malicious software or all the variants of a malicious worm or program.
Because the program will change the signature but never the code.
We can take example (not real):
Let's say that:
ABC DEF GEH
are the codes of a malicious program.
when you create a new variant, in the codes, this adds news things like the settings choosen by the user:
ABC %random things%
DEF GEH KeyloggerName CND
But the
ABC DEF and
GEH will be always here at the same entry. This means, the signature will change because the codes in the program changes but some points in the codes will still be always the same.
That's being said, VirusTotal
will never protect any users from real malware that the user can meet on the internet.
And the results on malware detections,
will never be 100 percent.
That's why Crystal Security has difficulties on malware detections.
What i recommend to the Crystal Security staff, is to do like we're doing in Tiranium Staff, to work with a method of better detection than hash (HEX or others) and to recruit malware hunters to create a real and good anti-malware database.
I can understand that is difficult to recruit malware hunters, it's was very hard for us too, but it's the best way. VirusTotal is not a good choose in my opinion for an security product, due to the bad detection rate. You can do better with upgrading your own database.
That's being said, i hope that Crystal Security will become better with the time. And i hope Kardo will understand my suggestion.
Good work and a good project.
Good luck Kardo
Maybe i said something wrong, sorry about. if my post offends anyone, I'm sorry too, it's not my goal.