4 ms·
> VirusTotal runs its own passive DNS replication service, built by storing DNS resolutions performed when visiting URLs and executing malware samples submitted
by uxp 10y ago
> VirusTotal runs its own passive DNS replication service, built by storing DNS resolutions performed when visiting URLs and executing malware samples submitted by users.
It will run malware samples and store any DNS and/or direct IP connections and lookups from the compromised host. I'm guessing the researchers used a combination of searches for malware coming in from email attachments and malware that connects to external databases (whether that be mysql port 3306, or something else less direct is unclear)
https://www.virustotal.com/en/documentation/searching/ https://www.virustotal.com/en/documentation/searching/