<?xml version="1.0" encoding="us-ascii"?>
<rss version="0.92"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/">
<channel>
	<title>Blog VirusTotal</title>
	<link>http://blog.hispasec.com/virustotal</link>
	<description></description>
	<language>es</language>

    <lastBuildDate>Tue, 25 Mar 2008 12:18:44 +0000</lastBuildDate>

	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<image>
		<url>http://blog.hispasec.com/virustotalimages/minilogo.png</url>
		<title></title>
		<link>http://blog.hispasec.com/virustotal</link>
	</image>

		<item>
		<title>VirusTotal Uploader in PC World's '101 Fantastic Freebies' List</title>
		<link>http://blog.hispasec.com/virustotal/29</link>
		<description>We were informed yesterday that &lt;a href=&quot;http://www.virustotal.com/metodos.html&quot;&gt;VirusTotal Uploader&lt;/A&gt;, our small tool to submit files to &lt;a href=&quot;http://www.virustotal.com&quot;&gt;VirusTotal&lt;/A&gt; via Windows context menu, has won an award in the US edition of PC World and has been published in their &lt;a href=&quot;http://www.pcworld.com/article/id,143642-page,1-c,webservices/article.html/?tk=pr_101FF_3-24-08&quot;&gt;'101 Fantastic Freebies'&lt;/A&gt; list, in fact &lt;a href=&quot;http://www.pcworld.com/article/id,143642-page,4-c,webservices/article.html&quot;&gt;heading their security section&lt;/A&gt;. Thanks a lot guys!&lt;p&gt;
&lt;center&gt;&lt;img src=&quot;http://blog.hispasec.com/laboratorio/images/noticias/freebies.jpg&quot; style=&quot;float: none;&quot;&gt;&lt;/center&gt;&lt;p&gt;</description>
	</item>
		<item>
		<title>Deleting the option &quot;Do not distribute the sample&quot;</title>
		<link>http://blog.hispasec.com/virustotal/28</link>
		<description>In the last few days, several articles have been published (&lt;a href=&quot;http://www.pcworld.com/article/id,140861-c,viruses/article.html&quot;&gt;1&lt;/A&gt;,&lt;a href=&quot;http://www.channelregister.co.uk/2007/12/21/dwindling_antivirus_protection/&quot;&gt;2&lt;/A&gt;,&lt;a href=&quot;http://www.pcpro.co.uk/news/150123/online-scanners-help-virus-writers-claims-kaspersky.html&quot;&gt;3&lt;/A&gt;,&lt;a href=&quot;http://www.bcs.org/server.php?show=conWebDoc.16580&quot;&gt;4&lt;/A&gt;), pointing to the &quot;Do not distribute the sample&quot; option in VirusTotal as a tool used by malware developers to avoid detection by AV engines. The reality is quite different and this is a mistaken interpretation. Nevertheless, as a preventive measure, we have agreed with AV developers to delete the &quot;Do not distribute the sample&quot; option from the VirusTotal website, as to prevent potentially malicious uses of that option.&lt;p&gt; 
When we launched VirusTotal back in 2004, the non-distribution option was intended to allow the analysis of files and documents containing sensitive data with the complete certainty they would not be sent to AV labs at all. Until now, the main use of this option has been the aforementioned: Analyzing Word files, PowerPoint presentations, PDF files, etc., that contained sensitive data.&lt;p&gt;
Besides this initial function, afterwards we realized other alternative uses could be applied, by both, computer security professionals and malware specialists, as well as malware developers. As explained in the post &quot;The Darker Side of Online Virus Scanners&quot; in &lt;a href=&quot;http://www.viruslist.com/en/weblog&quot;&gt;Kaspersky's blog&lt;/A&gt;, malware developers do not trust VirusTotal and have found their own methods to test their creations in multi-AV services.&lt;p&gt;
Although in the story from Kaspersky a pay underground service becomes the anecdote, at Hispasec we have been aware of underground tools, ready for download, that automatically analyze samples with over 20 AV products in your own computer. These tools use free/shareware/pirated versions of the AV engines that the AV developers make available for download in their own websites. Also, the online AV services based on ActiveX and similar services can be used individually for detection tests in your own computer without sending the malware to third parties.&lt;p&gt;
&lt;center&gt;&lt;img src=&quot;http://blog.hispasec.com/virustotal/recursos/multiav2.png&quot; style=&quot;float: none;&quot;&gt;&lt;br&gt;&lt;small&gt;Example of underground tool&lt;/small&gt;&lt;/center&gt;&lt;p&gt;
There is an additional technical reason that renders VirusTotal useless for malware developers to learn how to get around the detection of AV engines. Recently, AV solutions have incorporated new technologies, such as detection by behavioral analysis, that aren't available in the classical AV engines based on signatures and heuristic analysis of code that are used in online services. In order to test whether a specimen of malware is detected by these new technologies, the malware must be executed in a system with the AV program installed and activated. This is the reason why professional malware developers maintain many virtual machines with different AV solutions installed in order to execute and test their samples locally, without using online services such as VirusTotal.&lt;p&gt;
So, should AV developers remove their online AV programs? Should they stop providing demo versions of their AV programs to avoid a potentially malicious use? Obviously, we do not think so. If those measures were taken, the worst affected would be legitimate users, since malware developers would still use AVs fraudulently, with pirated versions or properly acquired versions. We mustn't forget that there is a true industry with plenty of resources, ready to make loads of money, behind most current malware.&lt;p&gt;
The use of the non-distribution option was mainly legitimate. Honeypots, CERTs, AV labs, and malware specialists frequently used this option in different processes. Precisely, AV labs knew our non-distribution option worked for sure since they could test this option anonymously and check whether they received the sample or not, while malware developers had no way of testing our system at VirusTotal and hence their lack of trust in our non-distribution option.&lt;p&gt;
Besides all that has been said, we must clarify that the default use of distribution vs. non-distribution was overwhelming. Over 85% of all samples identified as malware in VirusTotal were submitted as distributable, and automatically forwarded in real time to all AV labs whose engines did not detect said samples.&lt;p&gt;
Nevertheless, at VirusTotal we find appropriate to delete the anonymous and indiscriminate non-distribution option in our website to avoid possible suspicions on the use of VirusTotal. We apologize if this measure proves to be inconvenient for the people who used this option legitimately.&lt;p&gt;
VirusTotal is a reliable service that works in close collaboration with the AV industry. All functionalities and decisions in VirusTotal are agreed upon with all AV developers that participate in our service, and we are open to all suggestions about improving our service so it proves more helpful for our community.&lt;p&gt;
</description>
	</item>
		<item>
		<title>Permalinks for VirusTotal Results</title>
		<link>http://blog.hispasec.com/virustotal/27</link>
		<description>The increasing number of AV engines and the new web interface that we started using a few months ago for VirusTotal have meant, as an undesirable side effect, a more difficult time when doing a screen capture of the complete results of an analysis to publish them in web pages.&lt;p&gt;
Although we introduced the new function &quot;Compact&quot; in the results page, that allows the user to compress a report and view it in several formats to avoid scrolling and to make copying &amp; pasting easier, we have realized it would be far more convenient to be able to use links to refer to results.&lt;p&gt;
Until yesterday, URLs referring to VirusTotal results would expire within 20 minutes. From now on, URLs referring to VirusTotal results will be active for days and will never expire once they are linked and visited.&lt;p&gt;
This way, instead of doing a screen capture or copying data, we will be able to refer to specific analysis results by using a link to the URL that appears in the browser, for instance: &lt;a href=&quot;http://www.virustotal.com/resultado.html?726c9e52b80f4e52e39d9008e980aeab&quot;&gt;
http://www.virustotal.com/resultado.html?726c9e52b80f4e52e39d9008e980aeab&lt;/A&gt;&lt;p&gt;</description>
	</item>
		<item>
		<title>Changes in the web interface</title>
		<link>http://blog.hispasec.com/virustotal/26</link>
		<description>We're adding some new stuff to the VT web interface. One of them is adding new languages, something that has been possible because a lot of people helped us with translations to languages like Polish, Czech, German, Hungarian and Chinese. Other people are sending us new tanslations so we'll soon include other languages like Brazillian Portuguese and Italian among others. I want to thank to this people for this great work (their names appear in the 'About' section) :)

Besides that, and basically because the inclusion of that languages, we've changed the way to express the 'no virus found' in web reports. It has been changed to a simple '-', something more 'language neutral'. Frankly, I think it is also an improvement in legibility for identifying detections.</description>
	</item>
		<item>
		<title>VirusTotal += Rising</title>
		<link>http://blog.hispasec.com/virustotal/25</link>
		<description>We welcome &lt;a href=&quot;http://www.rising-global.com&quot;&gt;Rising Antivirus&lt;/a&gt; to the list of engines used at VirusTotal. This is a quite large AV company with HQ at Beijing and a big share of the Chinese home user market.</description>
	</item>
		<item>
		<title>PC World award for VirusTotal.com</title>
		<link>http://blog.hispasec.com/virustotal/24</link>
		<description>&lt;p align=justify&gt;PC World people honored VirusTotal.com as best Security Web Site in their &lt;a href=&quot;http://www.pcworld.com/article/id,131935-page,14/article.html&quot;&gt;'100 Best Products of 2007' awards&lt;/a&gt;. It is great for us to get this mention from a so renowned source. Thanks a lot guys!&lt;/p&gt;
&lt;center&gt;&lt;img src=&quot;http://blog.hispasec.com/virustotal/recursos/pcworld_best_2007&quot; style=&quot;float: none;&quot;&gt;&lt;/img&gt;&lt;/center&gt;
&lt;br&gt;</description>
	</item>
		<item>
		<title>VirusTotal Uploader</title>
		<link>http://blog.hispasec.com/virustotal/23</link>
		<description>&lt;p align=justify&gt;Small tool for sending samples to VirusTotal that you can &lt;a href=&quot;http://www.virustotal.com/vtsetup.exe&quot;&gt;download here&lt;/a&gt;. Once installed, you'll have the 'Send to -&gt; VirusTotal' option in the Windows contextual menu when you right-click on a file. Once the file transfer is done, you'll get the reply through the web interface using your browser.&lt;/p&gt;

&lt;center&gt;&lt;img src=&quot;http://www.virustotal.com/images/en_virustotal-uploader.png&quot; style=&quot;float: none;&quot;&gt;&lt;/center&gt;&lt;br&gt;

&lt;p align=justify&gt;Comments, problems detected and suggestions are, as always, welcome.&lt;/p&gt;</description>
	</item>
	
</channel>
</rss>