Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-malware software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old July 1st, 2010, 04:55 AM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Batch virustotal analyst

Is there any software,automation script for virustotal?

Can i generate like this report?Is it possible?

FileName|MD5|Infected or Clean|A2|Comodo|BlaBla Av|
ads.exe
sada.exe
asd.exe
  #2  
Old July 1st, 2010, 05:09 AM
tsilo's Avatar
tsilo tsilo is offline
Frequent Poster
 
Join Date: Apr 2006
Posts: 375
Default Re: Batch virustotal analyst

xxtp://www.virustotal.com/vtsetup.exe
__________________
OS: Windows 8 Prefesional x64 bit
Resident : No Autorun 1.1.2.25
Firewall:Comodo Firewall

Last edited by Cudni : July 1st, 2010 at 05:14 PM. Reason: De-linked Direct Download Link
  #3  
Old July 1st, 2010, 05:17 AM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Re: Batch virustotal analyst

Quote:
xxtp://www.virustotal.com/vtsetup.exe

No, it is not batch tool. I want to scan 10.000 files at once. I need stronger tools.

Last edited by Cudni : July 1st, 2010 at 05:15 PM. Reason: De-linked Direct Download Link
  #4  
Old July 1st, 2010, 11:59 AM
sg09's Avatar
sg09 sg09 is offline
Very Frequent Poster
 
Join Date: Jul 2009
Location: Kolkata, India
Posts: 2,386
Default Re: Batch virustotal analyst

I think Reanimator can do that...
__________________
Windows 7 Professional 64bit: Webroot Secure Anywhere, Zemana AL, KPD, Kingsoft AV
Windows 7 Home Premium 32bit
: AVG Internet Security, MCShield

My Blog
  #5  
Old July 1st, 2010, 01:02 PM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Re: Batch virustotal analyst

Quote:
I think Reanimator can do that...

it can scan with using vt but there is not log
  #6  
Old July 1st, 2010, 07:03 PM
Kyle1420's Avatar
Kyle1420 Kyle1420 is offline
Frequent Poster
 
Join Date: May 2008
Posts: 402
Default Re: Batch virustotal analyst

Can I please have a link to reanimator? I tried googling it... all i came up with was horror films.
__________________
Win 7 x64(gaming);
Sandboxie/Mbam paid
Linux Mint x64(everything else);
http://linuxmint.com/
  #7  
Old July 1st, 2010, 08:03 PM
jmonge's Avatar
jmonge jmonge is offline
Incredibly Massive Poster
 
Join Date: Mar 2008
Location: Calgary,Canada
Posts: 11,766
Default Re: Batch virustotal analyst

http://www.greatis.com/security/reanimator.html
__________________
Emsisoft Anti-Malware 7.0/WebRo0t AntiVirus 2o13
  #8  
Old July 2nd, 2010, 12:33 PM
Buster_BSA Buster_BSA is offline
Frequent Poster
 
Join Date: Nov 2009
Posts: 545
Default Re: Batch virustotal analyst

Obviously Reanimator will not do what maymoons asked.
__________________
http://bsa.isoftware.nl
  #9  
Old July 2nd, 2010, 02:45 PM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Re: Batch virustotal analyst

Quote:
Obviously Reanimator will not do what maymoons asked.

Yes, You know what i want. I hope you can add this function to BSA.
  #10  
Old July 2nd, 2010, 04:51 PM
Brummelchen Brummelchen is offline
Becky! Internet Mail Support
 
Join Date: Jan 2009
Posts: 869
Default Re: Batch virustotal analyst

The question for me is:

Is it usefull to query a lot of files this way - due to heavy traffic
it is more than possible that results may outstanding for a long time.
i suggest to use other - like MBAM or a portable tool

TheCleaner Portable (Demo, but enough)
http://www.moosoft.com/portable

SuperAntiSpyware Portable
http://www.superantispyware.com/portablescanner.html

emsisoft a2 portable/commandline
http://www.emsisoft.de/de/
  #11  
Old July 2nd, 2010, 05:24 PM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Re: Batch virustotal analyst

The Cleaner and Superantispyware dedection rate low, emsisoft cant scan 250.000 files at once.
  #12  
Old July 2nd, 2010, 06:26 PM
Kyle1420's Avatar
Kyle1420 Kyle1420 is offline
Frequent Poster
 
Join Date: May 2008
Posts: 402
Default Re: Batch virustotal analyst

maymoons, I would love to make an application that could upload those files recursively as It would prove useful in a lot of other cases too..The bit I get stuck on is interacting with virustotal.com to click the 'select file' button..I can do that with simulated mouse movement\clicks but I don't really think thats practical. I think that really you need to get in contact with Virustotal and request this tool from them as I don't think its possible AFAIK to make a 3rd party tool to do this..

Kyle
__________________
Win 7 x64(gaming);
Sandboxie/Mbam paid
Linux Mint x64(everything else);
http://linuxmint.com/
  #13  
Old July 2nd, 2010, 07:12 PM
Ibrad's Avatar
Ibrad Ibrad is offline
Very Frequent Poster
 
Join Date: Dec 2009
Posts: 1,887
Default Re: Batch virustotal analyst

Why not just put them all in one file and have each product scan the file and see what they detect? Only other way I would do it is ask one of the AV experts that work at the lab to check every file for ya and give you a nice detailed log of what each one was.
__________________
Panda Security TRUSTED MOD


Panda Cloud Antivirus + Rising PC Doctor + Common Sense

My Security Blog: http://igl-security.blogspot.com/
  #14  
Old July 2nd, 2010, 08:14 PM
Kyle1420's Avatar
Kyle1420 Kyle1420 is offline
Frequent Poster
 
Join Date: May 2008
Posts: 402
Default Re: Batch virustotal analyst

maymoons, I did some more reading on this. You can email VirusTotal files and they should get back to you. Would you be happy if I tried to make something that would email those attachments recursively ?
__________________
Win 7 x64(gaming);
Sandboxie/Mbam paid
Linux Mint x64(everything else);
http://linuxmint.com/
  #15  
Old July 2nd, 2010, 10:40 PM
kwismer kwismer is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 240
Default Re: Batch virustotal analyst

Quote:
Originally Posted by maymoons
No, it is not batch tool. I want to scan 10.000 files at once. I need stronger tools.

10 thousand?

here's something julio canto of virustotal posted to twitter a week or so ago

Quote:
Originally Posted by jcanto
dear virustotal users: I would like to remind you that VT may not be used for mass scanning. abusing the service -> blocking your IP

Quote:
Originally Posted by jcanto
it is a matter of resources -> we obviosly don't have the Google infrastructure for keeping the service running

if you've collected 10 thousand files to scan, maybe you should invest the time/effort/etc in setting up your own multi-scanning system.
  #16  
Old July 3rd, 2010, 05:28 AM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Re: Batch virustotal analyst

Quote:
maymoons, I did some more reading on this. You can email VirusTotal files and they should get back to you. Would you be happy if I tried to make something that would email those attachments recursively ?

Probably not only me, virus traders need this tools. There is a some script but they are not usefull. But if it is true;

Quote:
dear virustotal users: I would like to remind you that VT may not be used for mass scanning. abusing the service -> blocking your IP

There is no way for batch analyst.


Quote:
if you've collected 10 thousand files to scan, maybe you should invest the time/effort/etc in setting up your own multi-scanning system.

I dont know how can i do this. Anyway, I can use AV's log reports. This is long process, 24-48h per AV (some crashed and i can use it for generate log)
  #17  
Old August 13th, 2010, 05:10 AM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Re: Batch virustotal analyst

Now, VT has public api.
http://www.virustotal.com/advanced.html

Maybe batch analysis tools can be build easly
  #18  
Old August 13th, 2010, 05:37 AM
andylau andylau is offline
Frequent Poster
 
Join Date: Jan 2006
Posts: 558
Default Re: Batch virustotal analyst

Quote:
Originally Posted by maymoons
Now, VT has public api.
http://www.virustotal.com/advanced.html

Maybe batch analysis tools can be build easly

Quote:
The chosen format for the API is HTTP POST requests with JSON object responses and it is limited to at most 20 requests of any nature in a given 5 minutes time frame. The public API is a free service, available for any web site or application that is free to consumers.

The public API key has limitation. If you want to scan for mass files, you must apply for a private api key.
__________________
Best regards

Last edited by andylau : August 13th, 2010 at 05:45 AM.
  #19  
Old August 13th, 2010, 06:00 AM
maymoons maymoons is offline
Frequent Poster
 
Join Date: Oct 2007
Posts: 853
Default Re: Batch virustotal analyst

Quote:
The public API key has limitation. If you want to scan for mass files, you must apply for a private api key.

121 day for non-stop scan. Yes, it is not usefull.
It dont look like cymru service
http://www.team-cymru.org/Services/MHR/
 

Wilders Security Forums > Security Products > other anti-malware software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 05:31 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums