VirusTotal now has an AI-powered malware analysis feature

Gandalf_The_Grey

Level 76
Thread author
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Apr 24, 2016
6,566
VirusTotal announced on Monday the launch of a new artificial intelligence-based code analysis feature named Code Insight.

The new feature is powered by the Google Cloud Security AI Workbench introduced at the RSA Conference 2023 and which uses the Sec-PaLM large language model (LLM) specifically fine-tuned for security use cases.

VirusTotal Code Insight analyzes potentially harmful files to explain their (malicious) behavior, and it will improve the ability to identify which of them pose actual threats.

"At present, this new functionality is deployed to analyze a subset of PowerShell files uploaded to VirusTotal. The system excludes files that are highly similar to those previously processed, as well as files that are excessively large," VirusTotal founder Bernardo Quintero said.

"This approach allows for the efficient use of analysis resources, ensuring that only the most relevant files (such as PS1 files) are subjected to scrutiny."

Code Insight will also help get insight into false positives and negatives, as its analysis is entirely independent of associated metadata (like antivirus results) since only the file's content is being examined.

It's also important to note that the code analysis LLM model is also prone to errors, and its accuracy may vary. Therefore security analysts should interpret Code Insight-generated information while considering contextual data relevant to the analyzed file.

Despite this, as Quintero said, "the integration of LLMs into the arsenal of code analysis tools is a significant advancement that enables security professionals to gain valuable insights into the structure and behavior of potentially malicious code, improving threat detection and response efficiency."

VirusTotal will add more file formats to the list of supported files in the following days, aiming to expand the scope of this new feature even further.

 

vtqhtr413

Level 26
Verified
Top Poster
Well-known
Aug 17, 2017
1,484
Google has added support for more scripting languages to VirusTotal Code Insight, a recently introduced artificial intelligence-based code analysis feature.

While launched only with support for analyzing a subset of PowerShell files, Code Insight can now also spot malicious Batch (BAT), Command Prompt (CMD), Shell (SH), and VBScript (VBS) scripts.

Besides the list of additions included in Google's announcement, BleepingComputer was also able to discover that the company added support for AutoHotkey (AHK) and Python (PY) scripting languages.

"Code Insight has broadened its support for script formats, moving beyond PowerShell to offer analysis for a variety of scripting languages," VirusTotal founder Bernardo Quintero said.

To facilitate the analysis of larger files, Code Insight has also been updated to have an increased maximum file size limit, doubling the capacity for processing.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top