3.1 Scanning the Suspect Binary with VirusTotal

VirusTotal (http://www.virustotal.com) is a popular web-based malware scanning service. It allows you to upload a file, which is then scanned with various anti-virus scanners, and the scan results are presented in real time on the web page. In addition to uploading files for scanning, the VirusTotal web interface provides you the ability to search their database using hash, URL, domain, or IP address. VirusTotal offers another useful feature called VirusTotal Graph, built on top of the VirusTotal dataset. Using VirusTotal Graph, you can visualize the relationship between the file that you submit and its associated indicators such as domains, IP addresses, and URLs. It also allows you to pivot and navigate over each indicator; this feature is extremely useful if you want to quickly determine the indicators associated with a malicious binary. For more information on VirusTotal Graph, refer to the documentation: https://support.virustotal.com/hc/en-us/articles/115005002585-VirusTotal-Graph.

The following screenshot shows the detection names for a malware binary, and it can be seen that the binary was scanned with 67 Anti-virus engines; 60 of them detected this binary as malicious. If you wish to use the VirusTotal Graph on the binary to visualize indicator relationships, just click on the VirusTotal Graph icon and sign in with your VirusTotal (community) account:

VirusTotal offers different private (paid) services (https://support.virustotal.com/hc/en-us/articles/115003886005-Private-Services), which allow you to perform threat hunting and download samples submitted to it.
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset
18.223.119.17