home.social

#virustotal — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #virustotal, aggregated by home.social.

fetched live
  1. Beyond valid credentials: How exposed AWS keys are tested for Amazon Bedrock access

    Attackers who gain access to AWS credentials perform validation to determine their usefulness, particularly for Amazon Bedrock access. Multiple credential harvesting platforms, including KMON_NOC, have been identified that specifically test stolen AWS keys for LLM capabilities. These platforms validate credentials using GetCallerIdentity, then test Bedrock access through ListFoundationModels and Converse API calls. The validation process helps attackers assess credential value for resale in token-jacking markets, where stolen AI model access is sold below retail price. Scripts analyzed on VirusTotal demonstrate systematic testing across multiple regions, targeting Anthropic Claude models specifically, and enumerating promotional credits to assess financial value. This represents an evolution in credential validation similar to historical patterns observed with AWS SES/SNS services.

    Pulse ID: 6ac52c8896a61ee777d4aee5
    Pulse Link: otx.alienvault.com/pulse/6ac52
    Pulse Author: AlienVault
    Created: 2026-10-06 17:14:48

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Amazon #AWS #CredentialHarvesting #VirusTotal #OTX #AlienVault

  2. Enrich Splunk notable events with VirusTotal via the lookup command. Extract file hashes, query VT v3 API, cache in KV store to respect rate limits. valtersit.com/vault/enriching- #splunk #virustotal #threat

  3. VirusTotal knows about the file virustotal.com/gui/file/a91744

    Sadly, I could get my hands on the malicious MSI file. So if someone has it I would love to look inside

    Edit : Found the sample through the SHA256 hash
    bazaar.abuse.ch/sample/a917441

    Side not: Why is the VirusToal first seen in the wild date after the first submission date???

    #SocialEngineering #VirusTotal

  4. Also back to #VirusTotal saying Microsoft would flag it as Malware too.

    Well just uploaded the file there and it says it doesn't. And "Final determination: Not malware"

    However a local scan with Windows Defender is kinda stupid as it says "No current threats" as well as "1 threat found" but then doesn't do any alarming?!?

    Anyway that's the kind of quality I've come to expect from #Microslop these days...

    #Microsoft

  5. Also #VirusTotal apparently flags an exe that iterates over all available drive letters as "checks-usb-bus". Even though it literally doesn't...

  6. Is it just me or has #VirusTotal become almost entirely useless at this point?

    Currently looking at a file from 2018 and it shows up with 29/69 positive. All just "Unwanted/Win32.Agent.C2359729", "GrayWare/Win32.Creprote", "Unsafe", "Trojan:Win32/Pepatch", "Trojan Horse", "Trojan.Agent/Generic".

    But when I look at the sandbox results it likely tripped because:
    1) starts WER (Windows Error Reporter) aka. the app crashes.
    2) Opens a paypal link
    3) Paypal showing a recaptcha

    #infosec #itsecurity

  7. @hacks4pancakes IDK what #VirusTotal is but when I was in school I used #Brave to get around school firewalls. I highly recommend it. Either use #Tor through that browser, or use its #Tor mode to download the #TorBrowser itself (the school I went to had blocked the #TorBrowser as well).

  8. A #Wordpress site belonging to an friend (I’m not the admin...) was successfully hacked using #wp2shell (17.07.2026; CVE-2026-63030 + CVE-2026-60137), just 5 days after the first exploit published (20.07.). Another 5 days later, the website was abused for SEO spamming and for hosting phishing…

    If you haven't already, update your Wordpress (preferably yesterday…; >=v7.0.2 or >= 6.9.5) and also enable automatic updates for themes and plug-ins!

    I found several PHP backdoors/webshells (see @abuse_ch Malware Bazaar and #VirusTotal (hashes below)). Interestingly, not every sample was detected by the #YARA rules from @cyb3rops and github.com/ruppde/yara_rules.

    tl;dr #wp2shell is being actively exploited, patch immediately and enable automatic updates.

    Hashes:
    1093b4045b45a8498d146e31788c25769f992056c8ffc582b5d8c06598598966
    05e3884a478d3bc8fd7285dabb74107422f1615d2d7f80df9b8438d4beb663da
    bb9136494a546368e7c9b6252c2e1c5af9327c07947908a9ba6fdd78fb4bf4cf
    1e7ca9074cc2eca8d366022629f665d9ffaa79e0621bb579bf5aabe681cb07e8
    8ebaf3ba0be7b62269aaf333cfaf66c1dea6e8ee495a917691beb550b4bbf0ab
    e3fb920aa70c7ad5c67b4d9b8e60954f5e0c1a07c0eba09505816b966f4d1a3c
    165e94c87ef17389c8de25ba2a6c31b348e3c916dab89d0dd3708156414f3de5
    b55cf5af8b57e9d56c69d00e023e2384c7eb184614c2a2a283062ebeaf4a26c6
    a46230a1638b9b341d15a640ead1b885548c1d1e5a149657e8e315540a068be8
    7918f29993383e579ef33bd0d8e766fd2ce047dce83bac51efb5fe17578b6cdf
    ae9ee9db7c41e04c531298782b908766c769a899aa92df3f64f4a83baa77ad09

  9. Grüne Häkchen bei VirusTotal bedeuten nicht, dass eine App garantiert sauber ist. Und rote Warnungen beweisen umgekehrt noch lange keine Malware.

    Unser POC zeigt, wie fragwürdig manche Treffer zustande kommen: Bei einer APK reichte bereits das AndroidManifest.xml mit seinen Metadaten und Berechtigungen für Warnungen - ganz ohne ausführbaren Schadcode. Besonders absurd: Ein Scanner wollte die App nur freigeben, wenn sie im Google Play Store erscheint.

    Scanner liefern lediglich Hinweise. Warum man genauer hinschauen sollte und weshalb der Play Store kein Vertrauensanker sein darf. 👇

    kuketz-blog.de/wie-viel-verlas

    #Android #VirusTotal #FDroid #OpenSource #ITSecurity

    @IzzyOnDroid

  10. Skill Marketplace and the Emerging AI Supply Chain Threat

    Between February and May 2026, researchers identified five malicious skills on ClawHub, OpenClaw's AI agent marketplace, that evaded detection by VirusTotal and ClawScan. The threats included two macOS infostealers communicating with command-and-control infrastructure, one skill using file padding to bypass scanner thresholds, and two novel agentic threats exploiting the AI supply chain for financial gain. The infostealers delivered payloads including AMOS malware through Base64-encoded droppers and paste-site redirects. One skill implemented runtime affiliate injection by forcing agents to recommend products through malicious referral links, while another orchestrated a front-running scheme using coordinated AI agents to manipulate cryptocurrency token launches. These attacks demonstrate how malicious actors exploit semantic instruction hijacking and the lack of isolation between skill logic and agent authority to compromise AI agent ecosystems.

    Pulse ID: 6a3b512e73c8b7fb25b84c38
    Pulse Link: otx.alienvault.com/pulse/6a3b5
    Pulse Author: AlienVault
    Created: 2026-06-24 03:38:22

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AMOS #AWS #CyberSecurity #InfoSec #InfoStealer #Mac #MacOS #Malware #OTX #OpenThreatExchange #RAT #Rust #SupplyChain #VirusTotal #bot #cryptocurrency #AlienVault

  11. Я прошёл крипто-развод до конца и реверснул дрейнер: 12 доменов и не меньше $784k у ~70 жертв

    Самое странное в этом дрейнере - его не видит ни один антивирус. VirusTotal: 0 из 91, а кошельки пустеют. Размотал всю схему: как жертва подписывает свой слив сама и куда уходят деньги.

    habr.com/ru/articles/1050718/

    #расследование #криптовалюты #фишинг #Binance #дрейнер #crypto_drainer #реверсинжиниринг #OSINT #VirusTotal

  12. Я прошёл крипто-развод до конца и реверснул дрейнер: 12 доменов и не меньше $784k у ~70 жертв Самое странное в это...

    #расследование #криптовалюты #фишинг #Binance #дрейнер #crypto #drainer #реверс-инжиниринг #OSINT #VirusTotal

    Origin | Interest | Match
  13. Watch out as scammers abuse GitHub, SourceForge, YouTube, and VirusTotal trust signals to spread a crypto clipper targeting Windows and Mac users.

    Read: hackread.com/scammers-fake-git

    #CyberSecurity #Malware #Crypto #GitHub #YouTube #VirusTotal

  14. I've found some old files way deep in the depths of my NAS and wanted to upload the then-famous NrZuName.dll for #klickTel to the @internetarchive . However, the upload was removed automatically.

    After checking the files on #VirusTotal, it appears that the EXE gets wrongly flagged by several engines, even though the "Code insights" truthfully say:

    The sample is a benign command-line utility named 'nr2name.exe' designed to look up names associated with a given number. It validates command-line arguments, dynamically loads a local helper library 'NrZuName.dll' via LoadLibraryA, and calls the exported function 'SucheNamen' using GetProcAddress. The program features descriptive console output and standard error handling, with no indicators of malicious behavior, evasion techniques, or suspicious API usage.

    Even the DLL itself gets flagged by 2 engines: Cynet (“Malicious (score: 100)”) and Kingsoft (“Malware.kb.a.889”), which both don't seem very trustworthy to me.

    Looks like, this is a recurring problem, too:

    Looks like this piece of software won't be preserved, then.

  15. I appreciate that #virustotal gives you a free API key, but the limitations on looking up files is seriously frustrating. One file every 15 seconds?

    Call me crazy, but for their purposes, wouldn't it be beneficial to have a higher limit?

    Also does anyone know of a virus scanning website with a higher rate API?

  16. It's been a while since I've found a need to do this, and I assume tools have changed a bit, so some #FediHelp would be appreciated...

    What is the most accurate way to find existing #DomainNames , or more specifically, #SubDomains , where I already know the #TLD ?

    #VirusTotal allows me to drill down from the main serving IP address to get to the #ASN - then reference the "Relations" tab for passive #DNS replication -BUT- I suspect the list may only be partially complete and/or 'outdated'.

  17. Operation FlutterBridge: macOS Malvertising Campaign Spreads New FlutterShell Backdoor

    A financially-motivated cybercrime cluster designated CL-CRI-1089 has launched Operation FlutterBridge, deploying FlutterShell backdoor malware targeting macOS systems through malvertising. Built with the Flutter framework, FlutterShell masquerades as legitimate applications including podcast players and PDF viewers, delivering adware with full backdoor capabilities such as shell command execution and file system manipulation. The malware uses a WebView-based architecture with JavaScript-to-native bridge, allowing attackers to dynamically modify behavior without recompiling. Distribution occurs through hundreds of Google-verified advertisements controlled by shell companies including AdsParkPro LTD and Advantage Web Marketing LLC. The campaign primarily targets Anglophone and Western European markets. All samples were signed with valid Apple Developer IDs and successfully passed notarization, achieving zero detections on VirusTotal initially. The malware hijacks Google Chrome browsers, redirecting traffic ...

    Pulse ID: 6a1ee9cdd897e06c7cac14d9
    Pulse Link: otx.alienvault.com/pulse/6a1ee
    Pulse Author: AlienVault
    Created: 2026-06-02 14:33:49

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #Browser #Chrome #CyberCrime #CyberSecurity #Europe #Google #InfoSec #Java #JavaScript #Mac #MacOS #Malvertising #Malware #OTX #OpenThreatExchange #PDF #RAT #Rust #Troll #VirusTotal #WesternEurope #bot #AlienVault

  18. @virustotal maybe it's worth to look into increasing free quota based on quality of reports. If a source reports a lot of malware with unique signatures then perhaps you don't want to enforce the default quota and miss out on reports (on days where the source is busy).

    I bet you already have some sort of usefulness score for sources anyway ?!

    #infosec #dfir #security #cybersecurity #virustotal

  19. 🔥 TRENDING

    📢 VirusTotal APK 病毒检测统计 20220101-20220831

    🔗 blog.trustlook.com/virustotal-

    #Virustotal #GlobalFeed #News #EN

    <i>Automatically posted by Global Feed Bot</i>

  20. 🔥 TRENDING

    📢 VirusTotal APK 病毒检测统计 20220101-20220831

    🔗 blog.trustlook.com/virustotal-

    #Virustotal #GlobalFeed #News #EN

    <i>Automatically posted by Global Feed Bot</i>

  21. Die Virenklatsche hat mal wieder einen erwischt, den der Spamfilter nicht auf dem Schirm hatte. 13 von 63 Scannern bei #Virustotal kannten die Prüfsumme. Es lohnt sich immer wieder, mehrere "lines of defense" zu haben.

    Wie das bei mir läuft? Im Procmail laufen einige Filter, von denen eines per Python-Script die Prüfsummen der Attachments einzeln bei Virustotal prüft. So bleiben die eigentlichen Daten vertraulich und es geht dort erheblich schneller mit 50+ Scannern als mit einem lokal.

  22. Die Virenklatsche hat mal wieder einen erwischt, den der Spamfilter nicht auf dem Schirm hatte. 13 von 63 Scannern bei #Virustotal kannten die Prüfsumme. Es lohnt sich immer wieder, mehrere "lines of defense" zu haben.

    Wie das bei mir läuft? Im Procmail laufen einige Filter, von denen eines per Python-Script die Prüfsummen der Attachments einzeln bei Virustotal prüft. So bleiben die eigentlichen Daten vertraulich und es geht dort erheblich schneller mit 50+ Scannern als mit einem lokal.

  23. 🔥 TRENDING

    📢 VirusTotal APK 病毒检测统计 20220101-20220831

    🔗 blog.trustlook.com/virustotal-

    #Virustotal #GlobalFeed #News #EN

    <i>Automatically posted by Global Feed Bot</i>

    🚀

  24. Apparently we reached the state of #Thoughtcrime punishment, it's called #precrime and on virustotal. Microsoft and Sophos just "blocked" (aka content filter says it's porn... whuat?) a friend's website because the #AI was suspicious of his AI website probably because on #Virustotal PreCrime is flagging it as will-be-malicious-in-the-future.

    I want my Internet back.

  25. 🔥 Nouvelle vidéo tendance au Sénégal !
    🎬 Eviter d'appuyer sur n'importe quel lien, les arnaqueur peuvent facilement voler vos données E A la place faites ça. #virustotal #astuce #tips #tipsandtricks #heynasser
    👇 Regardez la vidéo complète :
    diodioglow.com/video/eviter-da
    #Senegal #BuzzSN #TikTokSN #DiodioGlow

  26. PHISHING - update 2/2

    Screenshots van de RELATIONS tabbladen van virustotal.com/gui/ip-address/ en virustotal.com/gui/ip-address/

    Hierin zijn de domeinnamen van "doorstuurwebsites" te zien. Als u zo'n domeinnaam in uw browser opent, wordt uw browser doorgestuurd naar één van de phishingsites die ik noemde in mijn vorige toot.

    Als een feitelijke phishingsite (zie de vorige toot) "uit de lucht" wordt gehaald, hoeven de cybercriminelen met kleine moeite deze (en waarschijnlijk nog vele andere die ik nog niet ontdekt heb) doorstuursites zo aan te passen dat deze naar een andere phishingsite wijzen.

    Ook passen zij deze sites aan voor nieuwe "spamruns", zoals van KvK naar Bitvavo (zelfde domeinnaam, andere URL).

    Nb. virustotal.com is *NIET* kwaadaardig.

    #VirusTotal

  27. Sale un nuevo #tutorial esta vez sobre #VirusTotal una herramienta de analisis de ip, dominios, archivos y hashes en busca de malware entre otros. Te cuento ¿que es? y ¿como usarla? paso a paso y al final un bonus propio.... miralo en: luiszambrana.ar/virustotal-que

  28. VirusTotal's Cloudflare relationship isn't incidental — it's structural. Every file you submit potentially enters a big-tech data graph. When your threat intelligence platform IS your surveillance infrastructure, the dependencies matter.

    The agent tracks these supply-chain relationships as part of autonomous agent security monitoring. Privacy-first scanning at the-service.live/scrub?ref=mastodon-cloudflare

    #InfoSec #Privacy #BigTech #VirusTotal

  29. Using DuckDuck Go as my main search engine for a while now.

    My experience so far has been underwhelming. I get prompted the Ai generated result, and then I get a bunch of random websites that have very little information or are unreliable of what I am looking for. Just now when searching for VirusTotal, I got a search result of a malicious phishing site. I quickly got out, cleared my cookies, updated my browser, just to be safe. I will be searching for a new engine.
    #DuckDuckGo #VirusTotal

  30. I should really spend an afternoon learning to use more of #virustotal features to their fullest

  31. Ah, yes, because the world was just crying out for a "skill marketplace" with built-in #malware scanning 😂. Clearly, the 2026 tech landscape needed a platform called "ClawHub" to lead the charge on #cybersecurity 🦾. After all, why bother with real security when you can just slap on a #VirusTotal sticker and call it a day? 🙄🔍
    openclaw.ai/blog/virustotal-pa #skillmarketplace #ClawHub #HackerNews #ngated

  32. if i had more energy i'd be trying to track this #phishing campaign in a #VirusTotal graph or something lol 🫠

  33. #OpenClaw has partnered with #VirusTotal to #scan #skills uploaded to its #ClawHubmarketplace for malicious content. This partnership aims to enhance security by using VirusTotal’s threat intelligence and Code Insight capability to detect and block malicious skills. However, OpenClaw acknowledges that this scanning is not foolproof. thehackernews.com/2026/02/open #tech #media #news

  34. What I wouldn't give to have a sugar daddy with access to #VirusTotal for this new open-source project I'm working on. It's super frustrating to read nifty research like defusedcyber.com/ivanti-epmm-s - only to see it requires a $40,000/yr license fee to download the malware it discusses.

  35. #OpenClaw has partnered with #VirusTotal to scan all skills published to #ClawHub using VirusTotal's threat intelligence. The Hacker News reports that OpenClaw, formerly known as Moltbot and Clawdbot, announced the integration with Google-owned VirusTotal to enhance security for its platform. thehackernews.com/2026/02/open #AIagent #AI #ML #NLP #LLM #GenAI

  36. VirusTotalのcli toolとあまりに小さいAPI制限

    久々にcli でVirusTotal を使おうとしたらツールが変更になっていたり,API 制限がおかしくなっていました. […]

    matoken.org/blog/2026/02/06/vi

  37. When you finally reverse the loader for that malware sample #VirusTotal flagged as "APT XYZ". and it turns out to be just a #Vidar #Stealer dropper.
    4 Stages including Steganography for nothing 😕

  38. How old were you, when you found out #virustotal was an #Alphabet / #google product? I might be extremely late to this but I just found out and I’m terribly disappointed. #degoogle #askfedi

  39. Почему VirusTotal настолько плох?

    Часто ли бывает, что вы скачали программу с зеленого магазина, залили на VirusTotal, увидели 0 угроз и пошли открывать? Так вот, вирустотал это не детектор вирусов , а фраза 0 угроз после сканирования буквально НИЧЕГО Как работает VirusTotal и почему его очень ЛЕГКО обойти?

    habr.com/ru/companies/femida_s

    #Virustotal #инфобез #антивирус #вирустотал #sandbox #виртуальная_машина #VirtualBox #linux #ubuntu #иб

  40. Почему VirusTotal настолько плох? Часто ли бывает, что вы скачали программу с зеленого магазина, залили на VirusTotal, ...

    #Virustotal #инфобез #антивирус #вирустотал #sandbox #виртуальная #машина #VirtualBox #linux #ubuntu #иб

    Origin | Interest | Match
Share on Mastodon

Enter the server where you have an account.