Which kind of signatures does VirusTotal use?

TheMalwareMaster

Level 21
Thread author
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
Behaviour analysis really? I have never seen that on VirusTotal. Just some artificial intelligence
 
  • Like
Reactions: DracusNarcrym

Dani Santos

From Xvirus
Verified
Top Poster
Developer
Well-known
Jun 3, 2014
1,136
Behaviour analysis really? I have never seen that on VirusTotal. Just some artificial intelligence

Artificial intelligence works based on behavioral analysis. It checks the characteristics and behavior of the file and based on algorithms and deep learning, it classified the "danger level" of the file from 0.0 to 1.0. It is just a word marketing likes to use a lot.
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
Behaviour analysis really? I have never seen that on VirusTotal. Just some artificial intelligence
Yes, sometimes, analyzing a file on VirusTotal we can see some heuristic detection, but this absolutely doesn't imply that all of the heuristic and behavioral technology of a particular antivirus product was included in the on demand scanner because, of course, some technologies can not be included in an on demand scanner.

VirusTotal results do not provide a real and objective assessment of an antivirus product and, moreover, VT can just give a statistically interpreted evaluation of a suspicious file.
If we want to have an objective and interpretable report, we have to analyse this file to online malware analysis services interpreting the obtained results.
 

TheMalwareMaster

Level 21
Thread author
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
Can we say that VirusTotal uses only those components of products which make static analysis, whithout amy dynamic one?
 
W

Wave

Except the sample may be executed for code emulatipn/quick behavioral identification on the backend of the server which we cannot see, like how deepscreen used to work.

Unless we contact VT or the vendors and ask we wont know for sure.
 

TheMalwareMaster

Level 21
Thread author
Verified
Honorary Member
Top Poster
Well-known
Jan 4, 2016
1,022
Avast might have even included DeepScreen (they changed name, not sure what it is called now off the top of my head) in VT scanning, I am not 100% entirely sure on this one. Just a guess
It is now called CyberCapture, but I don't believe it's now included in VirusTotal
 
  • Like
Reactions: Wave

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
Except the sample may be executed for code emulatipn/quick behavioral identification on the backend of the server which we cannot see, like how deepscreen used to work.

Unless we contact VT or the vendors and ask we wont know for sure.
I agree, also because a full dynamic analysis of a sample for 5X antivirus would require a few hours :D
 

Winter Soldier

Level 25
Verified
Top Poster
Well-known
Feb 13, 2017
1,486
From Virustotal FAQ:

"VirusTotal antivirus solutions sometimes are not exactly the same as the public commercial versions. Very often, antivirus companies parametrize their engines specifically for VirusTotal (stronger heuristics, cloud interaction, inclusion of beta signatures, etc.). Therefore, sometimes the antivirus solution in VirusTotal will not behave exactly the same as the equivalent public commercial version of the given product."
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top