LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-23-2021, 03:36 PM   #1
winger9
Member
 
Registered: Jan 2014
Posts: 85

Rep: Reputation: 1
Why isn't VirusTotal detecting a zip file that contains malware?


Summary

1. On www.virustotal.com, I have just used its "Scan a URL" feature to see if it
detects malware within zip files.

I found a test zip file containing malware (I believe), at

https://github.com/ActorExpose/source-code-apk-malware

The actual file containing the malware is

https://github.com/ActorExpose/sourc...heads/main.zip

2. So I pasted the above zip file URL into VirusTotal's url box, and hit ENTER.
But to my surprise, the result showed "0/88: No security vendors flagged this
URL as malicious".

3. So my questions are:

a) Does this mean that VirusTotal is not detecting the malware?
b) If not, why not?
c) Or have I chosen a zip file on github that doesn't actually contain malware?
d) If the latter is the case, where can I find a zip file that does contain
malware, so that I can test it on VirusTotal?
e) Is there a reputable site that has such a sample zip file?


Full Details

4. Initially, I ran the malware checker www.virustotal.com on the Firefox
extension visited-color-picker. This is because I was considering downloading
the extension, but Firefox point out that they don't maintain security checks on
it. The extension changes the colour of visited links to the colour of your
choice.

You see, Firefox's own visited links color selector doesn't work satisfactorily
(yes I HAVE selected "Always" in Firefox's Preferences...Colors).

5. The extension visited-color-picker can be downloaded from

https://github.com/william-billaud/visited-color-picker

And the file to download is

https://github.com/william-billaud/v...ads/master.zip

6. So I used VirusTotal's "Scan a URL" feature, and pasted the above URL address
of the zip file into the box.

The result showed "0/88: No security vendors flagged this URL as malicious".

7. But I decided to check if www.virustotal.com really does detect malware. So I
found what I believe is a zip file containing malware, at

https://github.com/ActorExpose/source-code-apk-malware

The rest is explained in the "Summary" at the start.
 
Old 05-24-2021, 03:30 AM   #2
HTop
Member
 
Registered: Mar 2019
Posts: 44

Rep: Reputation: Disabled
Source code will not harm your computer.
Compiled source code, which makes it an executable, will be detected as malware.
 
Old 06-01-2021, 04:31 PM   #3
winger9
Member
 
Registered: Jan 2014
Posts: 85

Original Poster
Rep: Reputation: 1
To HTop:

Many thanks for your comment HTop. It put me on the right track.
 
Old 06-02-2021, 12:37 AM   #4
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
Quote:
Originally Posted by winger9 View Post
I found a test zip file containing malware (I believe), at

https://github.com/ActorExpose/source-code-apk-malware

The actual file containing the malware is

https://github.com/ActorExpose/sourc...heads/main.zip

2. So I pasted the above zip file URL into VirusTotal's url box, and hit ENTER.
But to my surprise, the result showed "0/88: No security vendors flagged this
URL as malicious
".
I have no idea how virustotal works, but the statement is pretty self-explanatory.

How did you come to suspect that specifically this software, and in it, specifically that zip file, might contain malware?

I don't think you'll ever get the answer "No, this software definitely does not contain malware", it will always be something along the lines of "we haven't detected anything".

PS: can't you also upload actual files to virustotal?
 
  


Reply

Tags
malware



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] PERL : virustotal api v2 - uploader doesn't work. ////// Programming 1 02-09-2021 12:23 PM
[SOLVED] How can I have zip -d file.zip "__MACOSX*" work on all zip files in directory? thomwblair Linux - Newbie 10 10-08-2018 02:30 PM
virustotal qrange Linux - Security 9 05-13-2018 06:33 AM
LXer: Google's VirusTotal puts Linux malware under the spotlight LXer Syndicated Linux News 0 11-12-2014 01:20 PM
list all contains and subdirectories' contains babis Linux - Newbie 2 10-22-2004 09:40 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 02:58 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration