Customise Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorised as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyse the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customised advertisements based on the pages you visited previously and to analyse the effectiveness of the ad campaigns.

No cookies to display.

Catching Malware Like Pro – Part 1

Share this post:

Most IT-Pro’s I talk to on this topic have the same answer when it comes to catching a possible virus on a machine.

Important steps to take:

  • Remove the device from the corp network
  • Scan the device with the ‘favorite’ antivirus product
  • If the step above fails to find it, use another antivirus/antimalware product
  • …..
  • clean install the device

There are a few problems with this approach

  • Scanning an entire machine depending on the hardware and amount of files on the system can take hours per product
  • only at the end of the scan you know if you picked the right product to catch the malware
  • you only get 1 opinion at a time

As most know, there’s no perfect antivirus product, though many do a good job.
What if we could get the knowledge of all those vendors combined in one scan action?

The knowledge is out there!

virustotal logo
virustotal logo

https://www.virustotal.com is a website that allows you to upload a suspicious file & check it against most of the known vendor’s engines.

Upload is only needed if the file isn’t already known in their database, if anyone already uploaded the file you want to test a simple file-hash check reveals the latest scan result of the file

screenshot of the interface
screenshot of the interface

press choose file on the file tab & select a file to upload/check

screenshot of the upload file selection
screenshot of the upload file selection

For this demo I used the eicar.org test file a well known test virus

screenshot of the result 56/65 engines triggered a response
screenshot of the result 56/65 engines triggered a response

As this is a know file no scan was needed & the result is instant, you can access the result >here<

If you want to update the result, rescan the file with all those engines (this one was scanned 5 minutes ago at the time of the test) you can press the circle arrow at the top right.

rescan in action
rescan in action
screenshot of 2nd scan result showing even more hits
screenshot of 2nd scan result showing even more hits

The number of used engines can vary from time to time & type of file, some engines do not can certain filetypes

looking at the list in this result you will be able to spot you favorite tools & more.

So now we are able to scan a file with all the possible intel, solving the issue of what engine to use to catch the malware

A good Idea to use this when assessing the use of a new tool

More on how to extend this to more than just 1 file in ‘part 2’

Share this post:

Leave a Reply

Your email address will not be published.

This site uses Akismet to reduce spam. Learn how your comment data is processed.