Create an account

Very important

  • To access the important data of the forums, you must be active in each forum and especially in the leaks and database leaks section, send data and after sending the data and activity, data and important content will be opened and visible for you.
  • You will only see chat messages from people who are at or below your level.
  • More than 500,000 database leaks and millions of account leaks are waiting for you, so access and view with more activity.
  • Many important data are inactive and inaccessible for you, so open them with activity. (This will be done automatically)


Thread Rating:
  • 314 Vote(s) - 3.47 Average
  • 1
  • 2
  • 3
  • 4
  • 5
People easily get fooled by spoofed virustotal scans

#1

[To see links please register here]

is an online file-scanning service that allows users to upload file and to see how safe it is. Those are especially used for threads where an application is shared, allowing the viewer to see what the application gets detected as.

However, viewers can still be infected by a virus from the application, even if the virustotal scan has a detection rate of ~0 hits.

This can happen because of 2 reason:
- the creator somehow made an undetectable virus, which is very unlikely
- the person posting the application swapped the infected application with a clean file, renamed the clean file as the application and sends it to virustotal, while providing a download link to the infected file. This is 99.9% of the time the actual reason.

however, the person might also have made a relay application to download the actual malware, this normally doesnt get flagged as a virus if it has a "whitelisted" name in the antivirus's engine. therefore, please check the extracted files and links it might sends.

after, there is the obvious Archive scanning or URL scanning, those can be flagged way more easily compared to relay apps since they have a different filetype.

TL;DR: Always check the I/O of an app on virustotal & re-scan the file after download (but before launching it) to see if the original scan was spoofed or not.
edit: and always use a VM or atleast a Sandboxer to just make sure the file doesn't affect your computer.
Reply

#2
Further to the above, do not use your main system when downloading files from this board.

As I keep mentioning, always download and execute tools/applications In a controlled environment- VM, Sandboxie and the like. If members require assistance with setting up and configuring either of the two, simply shoot me a PM, and I shall provide my step-by-step tutorial.
Reply

#3
Quote:(05-15-2020, 10:07 AM)mothered Wrote:

[To see links please register here]

Further to the above, do not use your main system when downloading files from this board.

As I keep mentioning, always download and execute tools/applications In a controlled environment- VM, Sandboxie and the like. If members require assistance with setting up and configuring either of the two, simply shoot me a PM, and I shall provide my step-by-step tutorial.
thanks for reminding me about it, i've added colors in the thread and added your comment ^^
Reply

#4
As always, treat any unknown files with suspicion. In the event someone is providing a fake scan link, it is encouraged you provide a proper scan and report the thread to staff.
Reply

#5
Quote:(05-15-2020, 10:59 PM)miso Wrote:

[To see links please register here]

thanks for reminding me about it, i've added colors in the thread and added your comment ^^
You're very welcome.

Thanks for adding the VM/Sandboxie. The thread's color and layout looks a lot better.
Reply

#6
Quote:(05-16-2020, 03:39 AM)Oni Wrote:

[To see links please register here]

As always, treat any unknown files with suspicion. In the event someone is providing a fake scan link, it is encouraged you provide a proper scan and report the thread to staff.
that is what i do, i start by telling if the app is fake or not and if it is a malicious file, following with a manual scan. (if the download is a relay app, i will scan the file downloaded by the relay)
Reply



Forum Jump:


Users browsing this thread:
1 Guest(s)

©0Day  2016 - 2023 | All Rights Reserved.  Made with    for the community. Connected through