Proceedings of the Internet Measurement Conference 2019
DOI: 10.1145/3355369.3355585
|View full text |Cite
|
Sign up to set email alerts
|

Opening the Blackbox of VirusTotal

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
1
1

Citation Types

1
15
0

Year Published

2020
2020
2023
2023

Publication Types

Select...
5
1
1

Relationship

0
7

Authors

Journals

citations
Cited by 62 publications
(16 citation statements)
references
References 31 publications
1
15
0
Order By: Relevance
“…To reduce the effect of false positives from individual scanners, we examined websites that were detected as malicious by at least two online scanners. We note that this approach is consistent with the best practice used in many papers that make use of multiple engines/vendors of VirusTotal for the labeling task [16]. As a result, we found that the number was 357, which accounted for roughly 4% of the active Cov19doms websites.…”
Section: Malicious Activities Using Cov19domssupporting
confidence: 84%
“…To reduce the effect of false positives from individual scanners, we examined websites that were detected as malicious by at least two online scanners. We note that this approach is consistent with the best practice used in many papers that make use of multiple engines/vendors of VirusTotal for the labeling task [16]. As a result, we found that the number was 357, which accounted for roughly 4% of the active Cov19doms websites.…”
Section: Malicious Activities Using Cov19domssupporting
confidence: 84%
“…When we request VirusTotal to scan a URL, it evaluates the maliciousness of about 90 different types of anti-virus software and returns the results to us. Several studies [32,46,55,61,67] used VirusTotal as a metric for evaluation. Then it is appropriate for our study to evaluate how much of the information collected from Twitter are actually malicious URLs.…”
Section: Comparison Of Maliciousness Using Virustotalmentioning
confidence: 99%
“…If VirusTotal had no previous scan results, we requested a scan and obtained the scan results. VirusTotal has also seen cases of false positives from anti-virus vendors [46]; therefore, URLs identified as malicious/suspicious by one anti-virus vendor are not necessarily phishing URLs. As a result, in our study, we compared URLs flagged as malicious/suspicious by at least one and five anti-virus vendors in VirusTotal with CrowdCanary and two existing systems.…”
Section: Comparison Of Maliciousness Using Virustotalmentioning
confidence: 99%
See 1 more Smart Citation
“…We were able to prove such behavior by creating a harmless PowerShell code to just display a "hello world" message and obfuscating the file using AES; this file was also detected as malicious by several antivirus programs. The file was uploaded to VirusTotal [77,78] on 18 May 2021, and it was labeled as malicious by 9 antivirus programs.…”
mentioning
confidence: 99%