Author Topic: Reliable Antivirus/Antispyware site to send out files  (Read 710 times)

0 Members and 1 Guest are viewing this topic.

Offline edu19

  • Peasant
  • *
  • Posts: 61
  • Cookies: 5
    • View Profile
Reliable Antivirus/Antispyware site to send out files
« on: May 26, 2014, 11:40:38 am »
Hi people. I would like to know a good and trustworthy site to test files against Antivirus and Antispyware softwares that won´t send them to the Vendors. It is just a non-malicious, large file that I compressed with UPX (it is free simple to use and popular). Since AVs. and ASs. are dumb they may start detecting the file as malicious for the simple fact it was compressed.

Thanks in advance.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #1 on: May 26, 2014, 12:19:39 pm »
Hi people. I would like to know a good and trustworthy site to test files against Antivirus and Antispyware softwares that won´t send them to the Vendors. It is just a non-malicious, large file that I compressed with UPX (it is free simple to use and popular). Since AVs. and ASs. are dumb they may start detecting the file as malicious for the simple fact it was compressed.

Thanks in advance.
What do you think those websites are for, I seriously doupt anyone is willing to pay such massive hosting costs just for giggles.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline d4rkcat

  • Knight
  • **
  • Posts: 287
  • Cookies: 115
  • He who controls the past controls the future. He who controls the present controls the past.
    • View Profile
    • Scripts
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #2 on: May 26, 2014, 12:38:50 pm »
I think there is a way to just send the hash of your binary to virus total.
That way they do not get the binary to analyse.
https://www.virustotal.com/en/documentation/searching/#getting-file-scans
Jabber (OTR required): thed4rkcat@einfachjabber.de    Email (PGP required): thed4rkcat@yandex.com    PGP Key: here and here     Blog

<sofldan> not asking for anyone to hold my hand uber space shuttle door gunner guy.


Offline Architect

  • Sir
  • ***
  • Posts: 428
  • Cookies: 56
  • STFU
    • View Profile
    • Rootd IRC
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #3 on: May 26, 2014, 05:32:33 pm »
You never upload files in their entirety, as this leaves your files open to analysis by whoever sees the file on the other side. And it leaves you at risk to expose your files that contain malware to the world. And it creates a signature for that particular file, which is then pushed in the next virus definitions. All of this is bad. If you want to be on the safe side, I recommend against it.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #4 on: May 26, 2014, 05:46:40 pm »
You never upload files in their entirety, as this leaves your files open to analysis by whoever sees the file on the other side. And it leaves you at risk to expose your files that contain malware to the world. And it creates a signature for that particular file, which is then pushed in the next virus definitions. All of this is bad. If you want to be on the safe side, I recommend against it.
My point with more eloquence.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline iTpHo3NiX

  • EZ's Pirate Captain
  • Administrator
  • Titan
  • *
  • Posts: 2920
  • Cookies: 328
    • View Profile
    • EvilZone
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #5 on: May 26, 2014, 07:16:11 pm »
Trustworthy and antivirus don't belong in the same sentence. The point of these mass online scanning sites is to detect viruses and share them with antivirus companies. Also most AVs will throw out false positives on anything packed with UPX.

Back in the XP days when I would make WPI's I would UPX silent installers to fit on a 700mb disk and was a complete disaster once any AV was installed.

What I suggest is a Slim VM environment with several of the leading AVs on them

Most people use the following:
-bit defender
-Norton
-McAfee
-avg
-avast
-avira
-kasperky
-malwarebytes

However most systems don't do well with several AVs on one machine so multiple VMs, update and then take offline, use a machine freeze app like deepfreeze so when you shutdown the VM all changes are removed. Test and run your virii to ensure the file is undetected as a file and at runtime. When you reboot your VM there is no trace and no internet for the AVs to send it out for further exploration

If you want to share your file with AVs you have a few that I can think of off the top of my head, dunno if they still exist haven't used them in years...

Virustotal, novirusthanks, virusscan jotti, kasperky online, Norton online, bitdefender online, and I think avira has an online scanner as well
« Last Edit: May 26, 2014, 07:19:01 pm by DeepCopy »
[09:27] (+lenoch) iTpHo3NiX can even manipulate me to suck dick
[09:27] (+lenoch) oh no that's voluntary
[09:27] (+lenoch) sorry

Offline edu19

  • Peasant
  • *
  • Posts: 61
  • Cookies: 5
    • View Profile
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #6 on: May 27, 2014, 04:30:53 am »
thank you very much for the feedbacks, folks. Well the program itself is not malicious in anyway, the problem is the size is large just that. DeepCopy, you´re damn right the best way to do it is on a VM with like 1 or 2 AVs (maximum) installed for testing, preferably with the internet cable disconnected just in case of false positives and the risk of them sending the file to their db.

I tested on a machine in my local network that has Kaspersky up to date. Did not detect anything. Let´s see the others now. :)

 +1 to everyone :)

PS: sorry for the above quote post, it was supposed to modify the first reply but it quoted.

Staff note: do not double post FFS!!!
« Last Edit: May 27, 2014, 07:16:42 am by Kulverstukas »

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #7 on: May 27, 2014, 07:44:48 am »
thank you very much for the feedbacks, folks. Well the program itself is not malicious in anyway, the problem is the size is large just that. DeepCopy, you´re damn right the best way to do it is on a VM with like 1 or 2 AVs (maximum) installed for testing, preferably with the internet cable disconnected just in case of false positives and the risk of them sending the file to their db.

I tested on a machine in my local network that has Kaspersky up to date. Did not detect anything. Let´s see the others now. :)

 +1 to everyone :)

PS: sorry for the above quote post, it was supposed to modify the first reply but it quoted.

Staff note: do not double post FFS!!!

Keep in mind that the AV on your machine also sends out binaries.

Offline proxx

  • Avatarception
  • Global Moderator
  • Titan
  • *
  • Posts: 2803
  • Cookies: 256
  • ФФФ
    • View Profile
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #8 on: May 27, 2014, 08:18:08 am »
Keep in mind that the AV on your machine also sends out binaries.
preferably with the internet cable disconnected just in case of false positives and the risk of them sending the file to their db.
Wtf where you thinking with that signature? - Phage.
This was another little experiment *evillaughter - Proxx.
Evilception... - Phage

Offline Deque

  • P.I.N.N.
  • Global Moderator
  • Overlord
  • *
  • Posts: 1203
  • Cookies: 518
  • Programmer, Malware Analyst
    • View Profile
Re: Reliable Antivirus/Antispyware site to send out files
« Reply #9 on: May 27, 2014, 01:15:27 pm »
@proxx