False sense of security
VirusTotal may have some use cases. But from my experience for phishing and scam sites the detection rate is near zero. Not sure about malware.
VirusTotal today issued a mea culpa, saying a blunder earlier this week by one of its staff exposed information belonging to 5,600 customers, including the email addresses of US Cyber Command, FBI, and NSA employees. The unintentional leak was due to the layer-eight problem; human error. On June 29, an employee accidentally …
"VirusTotal may have some use cases. But from my experience for phishing and scam sites the detection rate is near zero. Not sure about malware."
I hear what you're saying about the false sense of security which could perhaps represent a danger. I'm sure I've seen evidence for it but it would only be anecdotal so I'll say no more about that.
The threat profile from emails arriving here might not be typical, but I can share some of my experience, which is long and well documented.
I'm unable to comment on VirusTotal's (email) phishing and scam site detection performance because I haven't measured it, but I'd say it's pretty good for malware.
My milters, using a few simple Yara rules, routinely catch malware in email which multiple commercial and free virus scanners fail to identify. I have records for the last four hundred or so samples and about fifteen scanners courtesy of Jotti's Virus Scan. When I submit samples using our homebrew API to Jotti, very few threats are missed by all the scanners but the norm is for most of them to miss most threats. If I submit the threats (manually) to VirusTotal, the percentage of threats missed by all of the more than seventy scanners that they use is negligible, but again many of them seem to miss most threats.
You simply cannot rely on scanners alone. If you do, you are going to be compromised.
HTH
"VirusTotal may have some use cases. But from my experience for phishing and scam sites the detection rate is near zero. Not sure about malware."
No one should rely on a single source for protection. VirusTotal (and any other service you care to name) is no where near to being perfect. The best solution is to use a multi-layer protection system of multiple software scanners with firewalls, internal threat scanners and employing people who know how to intelligently interpret the results.
Virustotal is a system made of imperfect tools. Every antivirus program is an imperfect tool. The sum is a somehow less imperfect tool.
I use it a lot, and if the results show that it's malware, then usually it actually is malware. If the result comes out clean, then it's definitely NOT CLEAN. It usually means that no antivirus software gets that pattern right.
Still it's a useful check. Just don't trust it blindly if the result is "clean".
Anti virus engines have 2 modes of operation traditionally.
Signature matches
Heuristics
The latter can generate false positives.
I’ve had malware infested files given the clean bill of health by virustotal only to scan that same binary 10 years later and it has a trojan, an actual signature match so not a false positive.
The reality is, ask yourself this, what exactly IS malware
Clue, it’s malicious software
So basically all modern software is malware because it rarely acts in the end users interest.
Windows 10 is malware
Windows defender is great at finding keygens, but not so good at detecting actual malware
A reminder that even bright people can do daft things.
Given what we know, would not be surprised if the person at the centre of this simply “went on autopilot” and checked the file (as per good practise) before forwarding it to someone else.
Would not be surprised, if as a result of this, Virustotal sees an increase in the number of users “inspecting” files others have uploaded.