Tuesday, November 26, 2024
Homecyber securityVirusTotal Announced a New Feature Let Researchers To Create & Share IoCs

VirusTotal Announced a New Feature Let Researchers To Create & Share IoCs

Published on

The VirusTotal has recently released a new feature, VirusTotal Collections, that will eventually fill the gap that generally occurred during investigations. However, as time passes, it becomes more difficult to report some new findings.

This new feature will solve the problem as the VirusTotal collection provides a live report which includes:- 

  • A title
  • A group of IoCs
  • An optional description 

Pure IoC Sheet

However, the collection provides all the latest information, and it is enhanced with VirusTotal analysis along with some aggregate tags. 

- Advertisement - SIEM as a Service

The most interesting part of this collection is that they are public through the UI and API of VirusToal, it can also be shared using their permalink.

While the community provides content, that includes comments, graphs, and collections that generally contribute to the Community section of the file, URL, domain, as well as IP address reports.

Here’s what the software engineer of VirusTotal, Juan Infantes stated:- 

“Collections are open to our VirusTotal Community (registered users) and they will be enhanced with VirusTotal analysis metadata providing the latest information we have for the IoCs, along with some aggregated tags.”

Not only that even the IoCs in a collection also includes the other raw details that are provided by the VirusTotal itself, and here they are mentioned below:-

  • Detection rate
  • The first and last time the artifact was seen
  • File size

Along with other data, this feature also provides the following information:-

  • Name of the registrar
  • Country
  • The autonomous system
  • The managing network operator

This new feature of VirusTotal enables the security researchers to easily and effectively collude with other experts with each key detail that is needed to mitigate any threat in a more efficient and easy way.

You can follow us on Linkedin, Twitter, Facebook for daily Cybersecurity, and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

IBM Workload Scheduler Vulnerability Stores User Credentials in Plain Text

IBM has issued a security bulletin warning customers about a vulnerability in its Workload...

Multiple Flaws With Android & Google Pixel Devices Let Attackers Elevate Privileges

Several high-severity vulnerabilities have been identified in Android and Google Pixel devices, exposing millions...

Threat Actors Exploit Google Docs And Weebly Services For Malware Attacks

Phishing attackers used Google Docs to deliver malicious links, bypassing security measures and redirecting...

Python NodeStealer: Targeting Facebook Business Accounts to Harvest Login Credentials

The Python-based NodeStealer, a sophisticated info-stealer, has evolved to target new information and employ...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

IBM Workload Scheduler Vulnerability Stores User Credentials in Plain Text

IBM has issued a security bulletin warning customers about a vulnerability in its Workload...

Wireshark 4.4.2 Released: What’s New!

The Wireshark Foundation has officially announced the release of Wireshark 4.4.2, the latest version...

ANY.RUN Sandbox Automates Interactive Analysis of Complex Cyber Attack Chains

ANY.RUN, a well-known interactive malware analysis platform, has announced Smart Content Analysis, an enhancement...