Emiliano Martinez

161 posts

Emiliano Martinez banner
Emiliano Martinez

Emiliano Martinez

@zenitrame

Marbella (Spain) انضم Haziran 2009
150 يتبع427 المتابعون
Emiliano Martinez أُعيد تغريده
VirusTotal
VirusTotal@virustotal·
#MonthOfVTSearch is live! GUI searches are quota-free all month for VirusTotal customers. Day 1: Hunting Gamaredon-related document activity. Follow along. One search per day. Try it, pivot, and share your results.
VirusTotal tweet mediaVirusTotal tweet mediaVirusTotal tweet mediaVirusTotal tweet media
English
1
26
105
10.3K
motuariki
motuariki@motuariki_·
@bawitdaba3 This is my personal take but I just want VirusTotal. The Mandiant acquisition and merge by Google has resulted in things I never wanted or needed but am being forced to pay for. :(
English
1
0
0
79
motuariki
motuariki@motuariki_·
Thanks I hate it.
motuariki tweet media
English
1
1
3
968
Drunk Binary
Drunk Binary@DrunkBinary·
This is some straight up bullshit that @virustotal is pulling, it's expensive as hell to go up in tiers of service, talk about some shady business practices. @snlyngaas @Bing_Chris y'all gonna reach out to ask them why they are pulling a Microsoft business practices here?
安坂星海 Azaka || VTuber@AzakaSekai_

#VirusTotal just got back to us confirming that #Retrohunt quota is now counted on a per rule basis instead of per job WITHOUT ANY UPDATE OR NOTICES TO ITS CUSTOMERS. This is insane. #threatintel #infosec

English
2
2
12
7.3K
J. A. Guerrero-Saade
J. A. Guerrero-Saade@juanandres_gs·
The change to VirusTotal's retrohunt quota count (per YARA rule not per retrohunt run) is frankly insulting. Retrohunts don't cost VT more to run, the value is now lower, but the price is the same –low 4-figures per run?–, and you're still only scanning less than a year of data!?
English
4
6
25
7.5K
Florian Roth ⚡️
Florian Roth ⚡️@cyb3rops·
@M_haggis @_josehelps @mattnotmax @zenitrame: We're hashing out the idea of a VT Enterprise harvest to get a list of hashes for these drivers. I guess it would require a few hundred or a thousand search queries to generate an insanely useful DB of vuln drivers for the community Could we get an access to do that?
English
1
0
3
1.2K
The Haag™
The Haag™@M_haggis·
With lots of help from @_josehelps and @mattnotmax, I present a sneak peak of the LOLDrivers Project - Ability to search, access resources, hashes, CSV and json downloads as well. Coming soon. We're that much closer to a one stop driver shop.
The Haag™ tweet mediaThe Haag™ tweet mediaThe Haag™ tweet media
English
7
77
207
46.6K
Ali Alwashali
Ali Alwashali@ali_alwashali·
Hi @virustotal Could you please add all columns (detections AS, and country code) in the exported CSV from the collection page, currently CSV contains only the IPs which is not really helping a lot.
Ali Alwashali tweet media
English
2
1
5
3.7K
Emiliano Martinez
Emiliano Martinez@zenitrame·
@malearnity @daniel_gf3 deployed a fix. Section names lead to a UnicodeDecodeError and our PE analysis tool failed to process and produce a vhash for similarity pivoting. It should now be OK.
English
1
0
0
0
Emiliano Martinez
Emiliano Martinez@zenitrame·
@malearnity It is a PE, we should have indeed produced a vhash, let me look into it, keep you posted.
English
1
0
1
0
Omid Mirzaei
Omid Mirzaei@malearnity·
Any idea why VirusTotal cannot hash some feature vectors? Is it bc they can't parse the binary, or the hashing module actually fails to create a hash from the feature vector, or something else :-)? (see below) #VirusTotal
Omid Mirzaei tweet mediaOmid Mirzaei tweet media
English
1
0
0
0
Emiliano Martinez
Emiliano Martinez@zenitrame·
@pmsandstad @ChicagoCyber No, no plans. VT is about sharing threat context to improve world-wide defenses against them by empowering those that can take action (sec teams, vendors, etc.). On-prem goes against the mission of increasing world-wide visibility.
English
0
0
2
0
Emiliano Martinez
Emiliano Martinez@zenitrame·
@ChicagoCyber This is being misunderstood. Private scanning will not be a replacement for standard VT. It does not include AV scans but rather the rest of in-house static and dynamic analysis that we have. It is only for unknown files that you would not upload to VT, gives investigative leads.
English
1
9
44
0
Emiliano Martinez
Emiliano Martinez@zenitrame·
@ali_alwashali @cyb3rops @malshiekh @virustotal It has always been free but only visible to registered users. This is because displaying those insights to average non-technical users can make VT very cryptic. Users that register predominantly come from the industry and higher chances they'll understand.
English
1
0
4
0
Ali Alwashali
Ali Alwashali@ali_alwashali·
I just found out that @virustotal provides SIGMA rules matching behavior of uploaded malware, this is awesome.
Ali Alwashali tweet media
English
4
23
109
0
Sajid Nawaz Khan
Sajid Nawaz Khan@snkhan·
Hey @virustotal, your sandboxes aren’t doing well capturing msdt execution due to an interstitial. See: virustotal.com/gui/file/fc6a9… Consequently, my YARA rule with “cmd contains ‘msdt.exe’” within “vt.behaviour.command_executions” never fires. Can you help please? #Follina #msdt
City of London, London 🇬🇧 English
2
2
2
0