4 ms·
New SUPERNOVA backdoor found in SolarWinds cyberattack analysis
- peter_d_sherman 6y agoYou know, this brings up an interesting point with respect to VirusTotal... That is, I'm sure that as of today, probably all VirusTotal engines detect this DLL as being unsafe... But... was that the case historically? VirusTotal people, if you're listening, users of VirusTotal need the ability to audit the individual virus scanners and virus scanning companies historically -- that is, even though a virus scanner from security company X detects a given threat in a given DLL today, Did that same virus scanner from company X detect that same threat at various points in time in the past? In other words, VirusTotal, show me the damn history of which virus scanners flagged a given file as a threat and show me the first date that this threat was detected on. Think of it this way... you have the Wayback Machine, the Internet Archive... You give it the URL for a web page, and it shows you snapshots of what that URL looked like at various points in time. Well, I want the same functionality for VirusTotal -- except that instead of an URL, it's a file, and you show me historically what various Virus Scanners, from various security companies, said about that file at various points in time. Then we could answer questions like: When did Virus Scanner X, from Company Y, first discover a threat (and what were those threats, exactly, please enumerate/describe them like you do today) in file Z? When did that happen in TIME? From this, we could compare the efficacy of different virus scanners and companies, and also see how quickly some companies react (or don't react) to address these threats. Also, the same system should be in place for false positives. If a false positive is identified by Virus Scanner X, from Company Y in file Z at a given date and that is later corrected moving into the future, THEN PLEASE PRESERVE ALL OF THAT HISTORY. History is a lot like log files; You see, Elon Musk is a great fan of them, and so am I. (Remember Telsa's log files vs. what the New York Times reporter said?) To investigators/debuggers/system fixers in the future, they help pinpoint the exact point in time where something unwanted may have occured, and while not the only tool, they aid greatly in getting to a root-cause analysis...
- mox1 6y agoVirustotal has a back-end API that is pseudo-public. You just have to call them and pay $$$$ for access. For enough money they will absolutely let you download every sample submitted to them, in near real-time. All the big 3 letter US agencies are getting this feed. So this is very doable by the FBI / NSA, probably also big players like Microsoft, Amazon, etc. if they cared to have the feed.
- peter_d_sherman 6y agoI don't care about the samples; I care about the detection/non-detection rates in a historical, logged, public-record context... who detected what, when, but perhaps more importantly, who didn't detect what, when? In fact, if VirusTotal doesn't do it, perhaps in the future I'll create a website -- send a file to VirusTotal AND create a historical public record about what VirusTotal said about it at that exact point in time. VirusTotal already does the first part; I want it, or some third party, to do the second...
- T3OU-736 6y agohttps://support.virustotal.com/hc/en-us/articles/115002739245-Searching https://support.virustotal.com/hc/en-us/articles/11500273924..., section entitled "Searching for file scan reports" seems to strongly suggest there is historical data available.
- bigbizisverywyz 6y agoSeeing this, it looks as if there could be a simple workaround to protect anybody who thinks they might be infected, by getting their webserver / proxy to block all incoming http requests with any of these headers.