User Tools

Site Tools


provenance:security:virustotal

Provenance: security:virustotal

Working log behind virustotal. Corpus-wide caveats are on corpus. Citations use the shared bibliography; this page adds no keys of its own.

Run: 2026-08-27. Corpus: 5,859 extracted papers, 7 venues, 2010–2026, data/extract/run1. Item: drain wiki-measuretheweb / “security:virustotal (new)”, claimed as cursor-drain-virustotal, store id 222, run 60. Author of the page and this log: Cursor, not Claude Code. Reviews: three focused passes then one generic, all on GPT 5.6 Luna medium (gpt-5.6-luna-medium), the sitting's requested substitute for the spec's sonnet/fable split.

Creating, not extending. ?do=export_raw on security:virustotal returned the HTML error page (not an existence test by byte count). dw.mjs pages does not list provenance:. Neighbour security already linked the red child. Overlap judgement: write the promised child rather than widen website_classification — that page owns topic categories; this one owns the maliciousness oracle.

No ~~DISCUSSION~~ on this provenance page. Comments belong on the content page.

Scope decisions

Decision Why What a reasonable person might have done instead
Keep the 277 as an upper bound, do not hand-map all 277 roles Namespace sitting already found a references-only hit labelled used. 277 papers is a week of reading. Hand-map the 107 web papers. Defensible; not this sitting.
Cite Zhu's 115 for “what people did” rather than our 98-hit regex The 98 is an upper bound with 47-paper residue (clustering t, F-beta, t = 43 days). Zhu hand-read 93 methods. Publish 98/277 as “35% state a threshold”. That would be a lie about the residue.
Four lookups as objects, not as “VirusTotal” Mixing file-hash results with URL-scan results is the bug Peng measured. One “how to call the API” tutorial. Rejected: MDN/docs already exist.
No malware-datasets child Already rejected on security.
Cross-link, do not duplicate, the 500/day cap Already dated on website_classification. Repeated here because the oracle user hits the same cap. Point only, omit the number. Worse for a reader who never opens the other page.

Report script

scripts/report_virustotal.mjs plus scripts/vt_fold.mjs. Deterministic. Re-run:

node scripts/report_virustotal.mjs > scripts/report_virustotal-output.txt

Exits 1 if missing paper.cols.txt is not 4, if STUDIES_VT and the title/slug sweep disagree, or if API_TIER and the tight API-tier sweep disagree. A printed FAILURE with exit 0 is forbidden.

python3 pages/vt_label.py –demo is the published script. Its output is quoted in a <code> block; external_checks_virustotal.sh asserts equality.

Queries

# Query Population / denominator Result On the page?
Q1 Extraction records all 5,859 outer frame
Q2 UNION tools/classification/sourceList /virus total/i, used+produced+source 5,859 277 (107 web, 107 crawled) yes, labelled upper bound
Q3 tools used/produced 5,859 262 yes
Q4 of Q3, category classification-service 262 254 (96.9%) yes
Q5 classification used/produced 5,859 209 yes
Q6 lookup kind from classification.target (multi) 209 file 92, domain 43, apk 37, topic 16, url 12, ip 11, other 9 yes
Q7 topic-only 209 14 yes
Q8 non-topic VT target 209 195 yes
Q9 distinct raw strings, no fold union any-role 279 64 yes
Q10 full-text VT 5,855 with .cols 332; schema-used ∩ ft = 277 / 0 / 55 yes, 0 schema-only
Q11 title/slug studies VT 277 4 (Peng, Zhu USENIX, Zhu CCS demo, Wang IMC) yes; STUDIES_VT both directions
Q12 THRESHOLD_RE on UNION 277 98 (35.4%), upper bound yes, with family table and residue
Q13 Q12 minus homograph family 98 92, still an upper bound yes
Q14 API_TIER_RE, hand map 277 15; used academic/private/premium/public 11 (4.0%) yes
Q15 used-academic among Q14 15 4; one names 20k/day yes
Q16 AVClass/AVClass2 full text 5,859 47; 41 in UNION yes
Q17 detection.prevalence naming VT 277 167 tuples / 119 papers yes
Q18 OVERVIEW.md folded used-tool VirusTotal 5,859 239 / 4th yes, as a different fold, do not mix
Q19 year buckets of UNION 277 23 / 62 / 71 / 76 / 45* yes
Q20 venue of UNION 277 USENIX 59 … PETS 6 yes

Folding and residue

No name-fold on VirusTotal. 64 distinct strings are products, feeds, thresholds and combinations. Count published; list in the report.

Lookup kind is a fold of classification.target, not of free-text. other:malicious URLs → url, other:PDF documents → file. Residue of that fold is the 9 “other”.

THRESHOLD_RE is an upper bound. Family fold of the first matching context: any-engine-t1 10, t2-to-t5 19, t6-or-more 16, homograph 6, unmapped 47. The 47 are printed in the report. Several are real detection ratios (“33 out of 46”, “more than 40 AV engines”) that the family regexes missed; they are why 92 is still an upper bound rather than a census. We did not pretend to finish the hand map.

API_TIER is a 15-row hand map. Roles and deciding sentences in vt_fold.mjs. Sweep and map agree both ways.

STUDIES_VT is four title/slug hits. Zhu USENIX quote used 50 papers set t = 1: a file is because the 82-out-of-93 sentence is column-spliced; both strings are in paper.cols.txt. The 82/93 figure is still on the content page, taken from the same paragraph.

Quotes spot-checked

Paper Needle In .cols?
Peng IMC 2019 even the best vendors missed 30% of our phishing sites yes
Peng IMC 2019 only pulls the previous scanning results when a new scan request is submitted yes
Zhu USENIX 2020 50 papers set t = 1 yes
Zhu USENIX 2020 t = 1 is not a good threshold yes
Zhu CCS 2020 daily VirusTotal labels on more than 14,000 files over one year yes
Wang IMC 2023 571 million samples and 847 million reports yes

Zhu's 1,760,484 hazard flips and 811,325 non-hazard flips, 14,423 files, 65 engines, 115 papers, 22/115 silent, 82/93 threshold, 50 at t=1: all read from paper.cols.txt (some across a column break). Peng 68 vendors, 15/68, best vendor 26, 36 simple sites, IRS undetectable via scan API alone: same. Wang's contradiction with Zhu is stated as Wang's claim, not re-derived.

External sources

Fetched 2026-08-27, re-checked by scripts/external_checks_virustotal.sh:

  • docs.virustotal.com/reference/public-vs-premium-api — 500/day, 4/min, no commercial.
  • docs.virustotal.com/reference/overview — v3 default, v2 not deprecated.
  • docs.virustotal.com/reference/url-object, /reference/files, /reference/domains-object, /reference/ip-object — URL/domain/IP last_analysis_stats five keys and four per-engine categories; file object also documents confirmed-timeout, failure, type-unsupported. Domain and IP have no first_submission_date. timeout is a stats bucket, not a per-engine category.
  • gtidocs.virustotal.com/docs/vt-migration-guide — existing automations keep working.
  • gtidocs.virustotal.com/docs/google-threat-intelligence-customer-migration — VirusTotal support channel for GTI customers ended 2 December 2025 (already past). An earlier draft of the content page wrote 2026-12-02; that was a year-slip and was corrected before review freeze.
  • www.virustotal.com/gui/contact-us/legal — subject line “I have an academic research request” (fetched 2026-08-27). Not a self-serve 20k/day form.

Rejected: SEO pricing pages quoting $1,500–$4,000/mo for Premium. No primary source. Not on the page.

Academic access: no standalone quota-application form. The contact-form subject is the live path; four corpus papers still name an academic licence; one names 20k/day.

What could not be established

  • A complete citation-only map of the 277. A REFERENCES-heading heuristic found 6 cite-only of 132 with a heading; 139 papers have no REFERENCES heading in .cols, so the heuristic is not a population filter.
  • A complete threshold census of the 277. Residue 47/98.
  • Whether OVERVIEW.md's 239 and this script's 262 are the same papers under a different fold. Not mixed on the page.
  • Live engine count today (needs an API key). Page tells the reader to read last_analysis_stats on their object.
  • A published academic quota number other than what papers already named (20k/day). The contact form does not state a quota.

Published script

pages/vt_label.py. Stdlib. –demo fixture is internally consistent (2 malicious of 4 engines). Requires the v3 data.attributes wrapper; missing last_analysis_stats is a KeyError. Undocumented stats keys are a ValueError. File objects must include the three extra stats keys and they count toward total. Domain and IP objects have no first_submission_date. Advertised flags: a JSON path, –demo, –threshold N with N >= 1. Giving both or neither, or N < 1, exits 2.

Bibliography keys added

Collision-checked against a fresh export of live literature:bibliography (not the stale pages/literature_bibliography.txt). peng2019_opening and vallina2020_misshapes already live. Added: zhu2020_label, zhu2020_vtset, wang2023_remeasuring.

zhu2020_label is USENIX: no DOI in the index. Authors hand-written from the paper header (Shuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin, Ziyi Zhang, Linhai Song, Gang Wang). scripts/fetch_authors.py returned BIT/BUPT/USTC as authors — the known affiliation-glue bug (audit-usenix-author-lists). Do not use that cache row.

Report output (unedited)

report_virustotal-output.txt
========================================================================
A. CORPUS
========================================================================
corpus papers                                       5859
empirical                                           5118
crawled                                             1120
web platform                                        1622
classified                                          4439
missing paper.cols.txt                              4
 
========================================================================
B. POPULATION (schema UNION, upper bound on true use)
========================================================================
tools[].name matches VT (any role)                  263
  used or produced                                  262
classification.resourceName matches (any role)      211
  used or produced                                  209
population.sourceList matches                       62
UNION used/produced/source                          277
UNION any role                                      279
  of UNION: web platform                            107  38.6%
  of UNION: crawled                                 107  38.6%
tool-used with category classification-service      254  96.9% of tool-used
 
PAGE POPULATION: the UNION of 277 is the headline upper bound.
The web slice (107) is the student who is measuring the web. The rest are
mostly file/APK malware papers using the same instrument. Topic-classifier
use (website-category) is counted below and sent to design:website_classification.
Do not mix OVERVIEW.md folded-tool 239 / 4th with this 262 used-or-produced.
distinct raw strings (no fold)                      64
raw strings (count is tuples, not papers):
  482	VirusTotal
  14	VirusTotal API
  5	VirusTotal Intelligence
  4	VirusTotal feed
  4	VirusTotal Intelligence API
  3	VirusTotal internal data
  3	VirusTotal Relations
  3	VirusTotal Retrohunt
  2	Virus Total
  2	VirusTotal intelligence API
  2	VirusTotal IP and graph APIs
  2	VirusTotal Premium API
  2	VirusTotal URL feed
  2	VirusTotal's URL reputation service
  1	30% VirusTotal detection threshold (custom)
  1	AMD reports and VirusTotal reports
  1	Bazaar and VirusTotal
  1	Drebin dataset and VirusTotal
  1	filtered VirusTotal APK corpus
  1	ForcePoint engine via VirusTotal
  1	Google Play and third-party Android markets plus VirusTotal
  1	Google Safe Browsing and VirusTotal
  1	Hacking forums and VirusTotal
  1	Malsign, Malcert, Symantec data set, Samples from WINE and VirusTotal
  1	MalwareBazaar, Hybrid Analysis, VirusTotal, and direct botnet downloads
  1	MalwareConfig, Shodan, VirusTotal, @Scum, and ReversingLabs
  1	MalwareConfig, Shodan, VirusTotal, and ReversingLabs
  1	Mozilla's PDF.js test suite and VirusTotal
  1	PDF.js test suite, VirusTotal, and V8 regression test suite
  1	SEISMIC; MineSweeper; Musch et al.; VirusTotal; VirusShare; NoCoin; MadeWithWasm
  1	six VirusTotal machine-learning engines
  1	VirusShare, VirusTotal, and the AMD dataset
  1	VirusTotal and abuse.ch
  1	VirusTotal and Github
  1	VirusTotal and malware.lu
  1	VirusTotal and MalwareBazaar
  1	VirusTotal and VirusShare
  1	VirusTotal antivirus detections
  1	VirusTotal antivirus reports
  1	VirusTotal API and Google SafeBrowsing
  1	VirusTotal AV engines
  1	VirusTotal AV-engine threshold (t=4)
  1	VirusTotal Balanced Dataset
  1	VirusTotal blacklists
  1	VirusTotal CVE tags and AV-vendor scanner
  1	VirusTotal distribute API
  1	VirusTotal Hunting
  1	VirusTotal Intelligence Search
  1	VirusTotal malware configurations
  1	VirusTotal private API v3.0
  1	VirusTotal public API
  1	VirusTotal Public API v2.0
  1	VirusTotal report APIs
  1	VirusTotal score
  1	VirusTotal URL Feed
  1	VirusTotal vhash
  1	VirusTotal-labeled malware subset
  1	VirusTotal, certificate-matched potentially benign samples
  1	VirusTotal, HybridAnalysis, and MetaDefender
  1	VirusTotal, MetaDefender, and HybridAnalysis
  1	VirusTotal, MetaMask, SEAL-ISAC, Google Safe Browsing, WalletGuard, Phishfort, and ChainPatrol
  1	VirusTotal, Qihoo 360, and Baidu
  1	VirusTotal, URLQuery, Malware Domain List, and VxVault
  1	VX Heaven, VirusShare, and VirusTotal
 
========================================================================
C. FULL-TEXT SWEEP versus schema
========================================================================
full-text /virus total|virustotal/i                 332  missing=4
schema-used ∩ full-text: both=277 schema-only=0 ft-only=55
0 schema-only means the schema does not invent papers the full text never names.
It does NOT mean every used label is true use. ft-only includes bibliography hits.
ft-only count                                       55
 
========================================================================
D. CLASSIFICATION TARGET (used VT resource; papers, multi-valued)
========================================================================
Target                                                                  Papers  Share of 209
----------------------------------------------------------------------  ------  ------------
malware                                                                 86      41.1%
domain                                                                  42      20.1%
mobile-app                                                              37      17.7%
website-category                                                        16      7.7%
ip-address                                                              11      5.3%
web-request                                                             10      4.8%
vulnerability                                                           5       2.4%
other:downloaded software                                               1       0.5%
other:advertiser binaries and software families                         1       0.5%
other:exposed URLs                                                      1       0.5%
other:malicious URLs                                                    1       0.5%
other:VirusTotal engine detection labels                                1       0.5%
other:PDF documents as malicious                                        1       0.5%
other:website blacklist status                                          1       0.5%
other:STIX indicator values as malicious or non-malicious               1       0.5%
other:threat type of files                                              1       0.5%
other:shared files, proxy IPs, VPN configurations, and HTTP injections  1       0.5%
other:malware behavior risk reports                                     1       0.5%
user-generated-text                                                     1       0.5%
other:cryptomining processes                                            1       0.5%
class-used papers                                   209
 
========================================================================
E. LOOKUP KIND (folded from classification.target of used VT resources)
========================================================================
Lookup kind  Papers  Share of 209
-----------  ------  ------------
file         92      44.0%
apk          37      17.7%
url          12      5.7%
domain       43      20.6%
ip           11      5.3%
topic        16      7.7%
other        9       4.3%
topic = website-category. That use is design:website_classification, not this page.
topic papers                                        16
oracle (class-used minus topic-only possible mix)   class-used 209; papers with a non-topic VT target 195
topic-only (no other VT target on the paper)        14
 
========================================================================
F. YEAR AND VENUE of UNION
========================================================================
Window      Papers  Share of 277  Web
----------  ------  ------------  ---
2010–2014   23      8.3%          10
2015–2018   62      22.4%         27
2019–2021   71      25.6%         24
2022–2024   76      27.4%         29
2025–2026*  45      16.2%         17
2025–2026* is provisional: CCS/IMC 2026 not held; IEEE S&P/WWW 2026 incompletely selected.
Venue    Papers  Share of 277
-------  ------  ------------
USENIX   59      21.3%
CCS      54      19.5%
IEEE-SP  48      17.3%
NDSS     46      16.6%
WWW      33      11.9%
IMC      31      11.2%
PETS     6       2.2%
 
========================================================================
G. PAPERS THAT STUDY VIRUSTOTAL (title/slug)
========================================================================
title/slug about VT                                 4
  2019/IMC/opening-the-blackbox-of-virustotal-analyzing-online-phishing-scan-engines	studies-url	Opening the Blackbox of VirusTotal: Analyzing Online Phishing Scan Engines.
  2020/CCS/benchmarking-label-dynamics-of-virustotal-engines	studies-file-demo	Benchmarking Label Dynamics of VirusTotal Engines.
  2020/USENIX/measuring-and-modeling-the-label-dynamics-of-online-anti-malware-engines	studies-file	Measuring and Modeling the Label Dynamics of Online Anti-Malware Engines
  2023/IMC/re-measuring-the-label-dynamics-of-online-anti-malware-engines-from-millions-of	studies-file	Re-measuring the Label Dynamics of Online Anti-Malware Engines from Millions of Samples.
STUDIES_VT vs title/slug                            OK both directions
 
========================================================================
H. THRESHOLD PROBE (upper bound; classifyThreshold on first matching context)
========================================================================
UNION papers matching THRESHOLD_RE                  98  35.4% of 277
This is an UPPER BOUND. Clustering thresholds, F-beta, and "t = 0.6" still match.
Family         Papers  Share of 98
-------------  ------  -----------
any-engine-t1  10      10.2%
t2-to-t5       19      19.4%
t6-or-more     16      16.3%
homograph      6       6.1%
unmapped       47      48.0%
probe minus homograph family                        92  still an upper bound on "stated an AV-engine threshold"
unmapped residue                                    47
  UNMAPPED 2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem | ctions, the higher is the probability that a sample is indeed infected with malware. In Virustotal reports, this ratio is commonly known as detection ratio. In contrast, Anubis calculates a severity score (Section 4.3.2) that reflects how malicious a sample behaved inside the ana
  UNMAPPED 2013/WWW/the-role-of-web-hosting-providers-in-detecting-compromised-websites | of 25/43 (25 antivirus engines detecting it, out of 43 it was tested against), and sb.exe, a copy of the 2011 Ramnit worm, detected by 36 out of 42 antivirus products according to VirusTotal. In order to make sure the malicious files were not reachable by any web visitor, but onl
  UNMAPPED 2015/USENIX/webwitness-investigating-categorizing-and-mitigating-malware-download-paths | cond level domains (e2LDs) of popular benign sites (e.g., microsoft.com, google. com, etc.). For the remaining downloads, we scan them with more than 40 antivirus (AV) engines, using virustotal.com. In addition, we rescan them periodically because many "fresh" malware files are n
  UNMAPPED 2014/NDSS/execute-this-analyzing-unsafe-and-malicious-dynamic-code-loading-in-android-appl | us applications on both the original PJApps sample and the downloader application we developed. When presented with the PJApps sample, 33 out of 46 anti-virus applications used by VirusTotal and all 7 used by AndroTotal correctly flagged the APK as malicious. However, no anti-vir
  UNMAPPED 2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal | ompared to the anti-virus products employed by VirusTotal. Algorithms TP rate FP rate F-score ROC Area 10-fold Cross Validation. We choose Nt = 40 and Nf = All Features 0.980 0.020 0.980 0.998 log2 (# of features) + 1, for our experiments. We observe that in- FI+FL+FD+FU 0.868 0.
  UNMAPPED 2015/IEEE-SP/the-attack-of-the-clones-a-study-of-the-impact-of-shared-code-on-vulnerability-p | ng rate was high, initially, followed by a drop and then by a second wave of patching activity (suggested by the inflection in the curve at t = 43 days). The second wave started on 25 May 2011, when the vulnerability survival was at 86%. According to analyst reports, a surge of a
  UNMAPPED 2016/IMC/an-analysis-of-the-privacy-and-security-risks-of-android-vpn-permission-enabled | rison of Android permissions (x-axis) requested by VPN apps and the top-1,000 non-VPN apps. VPN Apps Free # App ID Class Rating # Installs AV-rank # Trackers Premium Free All non-VPN Apps 1 OkVpn [35] Prem. 4.2 1K 24 0 65% 28% 33% 19% 2 EasyVpn [15] Prem. 4.0 50K 22 1 13% 10
  UNMAPPED 2016/USENIX/towards-measuring-and-mitigating-social-engineering-software-download-attacks | ed executable files. To increase AV detections we "aged" the downloads in our dataset for a period of two months, before scanning them with more than 40 AV engines using virustotal.com. Notice that AV labels are mainly used for confirmation purposes. The actual labeling of SE att
  UNMAPPED 2016/WWW/no-honor-among-thieves-a-large-scale-analysis-of-malicious-web-shells | g the directory structure of the compromised website, such as, http://vict.im/admin/domainfonder.php? act=ls&d=/home/victim/public_html/&sort=0a. We recorded compromised websites all over the world, logging many instances of shells on websites of local businesses like an order s
  UNMAPPED 2017/CCS/hiding-in-plain-sight-a-longitudinal-study-of-combosquatting-abuse | ce. 2016. OPERATION DUST STORM. https://www.cylance.com/ hubfs/2015_cylance_website/assets/operation-dust-storm/Op_Dust_ Storm_Report.pdf?t=1477417126448. (February 2016). [31] Artem Dinaburg. 2011. Bitsquatting: DNS Hijacking without Exploitation. In Proceedings of BlackHat S
  UNMAPPED 2017/USENIX/6thsense-a-context-aware-sensor-based-attack-detector-for-smart-devices | ut these two only reported risks without clearly identifying any explicit malicious behaviour. Hence, it is difficult to Adversary Model Detection Ratio Threat-1 2/60 Threat-2 2/60 Threat-3 3/62 Table 8: VirusTotal scan result for the adversary models. detect the senso
  UNMAPPED 2017/USENIX/binsim-trace-based-semantic-binary-diffing-via-system-call-sliced-segment-equiva | t2(unsigned int n) 4: n = (n & (0x33333333)) + 1: void BitCount1(unsigned int n) 2: { ((n >> 2) & (0x33333333)); 2: { 3: unsigned int count = 0; 5: n = (n & (0x0f0f0f0f)) + 3: unsigned int count = 0; 4: while (n != 0 ) { ((n >> 4) & (0x0f0f0f0f)); 4: for (count = 0; n; n >>= 
  UNMAPPED 2018/CCS/towards-paving-the-way-for-large-scale-windows-malware-analysis-generic-binary-u | de performance boost and 100% success rate. In the packed benign program experiments with three popular web browsers, we find that more that 20 anti-virus scanners generate false alarms, and all of the other three unpacking tools fail to extract the original code. BinUnpack's ou
  UNMAPPED 2018/IMC/beyond-google-play-a-large-scale-comparative-study-of-chinese-android-app-market | ndroid App Markets IMC '18, October 31-November 2, 2018, Boston, MA, USA Table 4: Percentage of apps labeled as malware in each market by AV-rank. 0.30 AV-rank (% apps) Market >= 1 >= 10 >= 20 0.25 Google Play 17.03 2.09 0.32 Percentage of Apps 0.20 Tencent Myapp 34.15
  UNMAPPED 2018/IMC/characterizing-the-internet-host-population-using-deep-learning-a-universal-and | gia Tech Information Security Center. Malware Passive DNS Data. https: Wide Web. ACM, 639-648. //impactcybertrust.org/dataset_view?idDataset=520. [11] Hamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub, Kang G Shin, and Karl Aberer. 2018. Polisis: Automated Analysis and 
  UNMAPPED 2019/CCS/hidenoseek-camouflaging-malicious-javascript-in-benign-asts | mples were detected (Donxref1 5 for classification purpose. HideNoSeek is a novel camouflage attimes and PowerShell 3 times), and by at most 2 AV-vendors. Even tack that rests upon the assumption that malicious obfuscation though the detection accuracy is very low, we envision 
  UNMAPPED 2019/CCS/malmax-multi-aspect-execution-for-automated-dynamic-web-server-malware-analysis | [70]. Fourth, ClamAV is an open-source antivirus [20]. Fifth, we also use VirusTotal [1], an online aggregate service that scans files with more than 50 antivirus systems. There are also online PHP malware detection and deobfuscation services, such as unPHP [69] and shellray [49]
  UNMAPPED 2019/NDSS/mind-your-own-business-a-longitudinal-study-of-threats-and-vulnerabilities-in-enterprises | bilities. Even more worryingly, at 10 industries (between 78 and 199 days) is way above the least 10% of vulnerable servers are affected by more than 15 average 50% patch time across all applications (56 days). The vulnerabilities. One important observation is that 1.5M servers s
  UNMAPPED 2019/USENIX/reading-the-tea-leaves-a-comparative-analysis-of-threat-intelligence | load a file to be scanned. Upon submission, erage of VirusTotal as an oracle to detect targeted threats that these files will be scanned by more than 70 antivirus scanners, are not of broader interest. which creates a report on how many antivirus scanners mark To further understa
  UNMAPPED 2019/USENIX/tesseract-eliminating-experimental-bias-in-malware-classification-across-space-a | (N − 1) is a normalization factor so that AUT ∈ [0, 1]. The perfect classifier with robustness to time decay in the time window S has AUT = 1. By default, AUT is computed as the area under point estimates, as they capture the trend of the classifier over time more closely; if
  UNMAPPED 2019/WWW/revisiting-mobile-advertising-threats-with-madlife | cyclmnrepv.com. Listing 1 shows the coinhive14 script used in 6(a). We submitted the embedded JavaScript file15 to VirusTotal, where 33 out of 58 scanners reported this script. We later found out that our discovery was confirmed by both Symantec [30] and Malwarebytes [40]. T
  UNMAPPED 2019/WWW/the-chain-of-implicit-trust-an-analysis-of-the-web-third-party-resources-loading | e solution which aggregates the scanning capabilities pro- they allow third-parties to load further third-parties on their behalf. vided by more than 68 AV tools, scanning engines and datasets. It The propensity to form dependency chains is marginally higher has been commonly use
  UNMAPPED 2019/WWW/understanding-the-evolution-of-mobile-app-ecosystems-a-longitudinal-measurement | e whether Google Play is moving towards higher security levels during its evolution. Table 4: Distribution of potential malware over time. AV-rank (# apps, % apps) Year ≥1 ≥ 10 ≥ 20 Google Play 2014 261,480 (17.17%) 44,664 (2.93%) 9,324 (0.61%) Google Play 2015 250,484 (15
  UNMAPPED 2020/CCS/lies-in-the-air-characterizing-fake-base-station-spam-ecosystem-in-china | ase Stations. http://m.sohu.c om/n/444726367/. [15] 2016. Mobile Security Reports by Qihoo 360. http://zt.360.cn/2015/reportlist.htm l?list=1. [16] 2016. Research Reports: 2016 Fake Base Station of China. http://zt.360.cn /1101061855.php?dtid=1101061451&did=1101741409. [17] 20
  UNMAPPED 2020/NDSS/flowprint-semi-supervised-mobile-app-fingerprinting-on-encrypted-network-traffic | destinations that belong to the same app. Our ci [t] · cj [t] experiments in Section V demonstrate that this method of (ci ? cj )norm = PT t=0 (4) fingerprint generation can be used for both app recognition t=0 max(ci [t], cj [t]) and detection of previously unseen apps. Using t
  UNMAPPED 2020/NDSS/prevalence-and-impact-of-low-entropy-packing-schemes-in-the-malware-ecosystem | he instruction tween 2013 and 2019. We only selected PE samples classified " mov WORD PTR [0x1000], 0x4142 " at the address as malicious by more than 20 antivirus engines, and such that 0x1234, PD manages the size directive adding the tuples the entropy of each section, of the en
  UNMAPPED 2020/PETS/the-tv-is-smart-and-full-of-trackers-measuring-smart-tv-advertising-and-tracking | s://firebog.net, 2019. [Online; accessed 2019-04-29]. [9] MoaAB: Mother of All AD-BLOCKING. https://forum.xdadevelopers.com/showthread.php?t=1916098, 2019. [Online; accessed 2019-04-22]. [10] Kromtech Alliance Corp. Stopad for tv. https://stopad.io/ tv, 2019. [11] Hooman Mohaj
  UNMAPPED 2021/USENIX/phishpedia-a-hybrid-deep-learning-based-approach-to-visually-identify-phishing-w | them discuss and come to a consensus. Then, we use VirusTotal [9] to check whether it reports the same results. VirusTotal is equipped with more than 70 engines for malicious webpage detection (e.g., Google Safebrowsing). If a real phishing webpage is reported by a specific solut
  UNMAPPED 2021/USENIX/understanding-malicious-cross-library-data-harvesting-on-android |  before. To further libraries assess whether existing techniques can detect XLDH libraries, we leveraged VirusTotal [38], which aggregates more than 70 antivirus products, to scan all the XLDH libraries we found. Interestingly, no single product in the VirusTotal can detect a
  UNMAPPED 2023/CCS/efficient-query-based-attack-against-ml-based-android-malware-detection-under-ze |  adversarial Android malware generated by AdvDroidZero, indicating a 100% ASR against these products. For Avira, AdvDroidZero reduces the detection ratio from 30.98% to 5.63%. For Microsoft, AdvDroidZero decreases the detection ratio from 57.74% to 7.04%. These results demons
  UNMAPPED 2023/IMC/re-measuring-the-label-dynamics-of-online-anti-malware-engines-from-millions-of | tion results in VirusTotal (see Section 5). We mainly focus on how the number of engines that detect the sample as malicious (which we call AV-Rank) varies over time for a given sample. We find an almost 50/50 split between samples with changes in AV-Rank and those that remain st
  UNMAPPED 2023/IMC/wolf-in-sheeps-clothing-evaluating-security-risks-of-the-undelegated-record-on-d | 23. Domain Names, Websites, and Hosting. https://sg.godaddy.com/. [26] Google. 2023. Google Scholar. https://scholar.google.com/scholar?start=0&as_ sdt=2005&sciodt=0,5&cites=1499698348405075976&scipsc=. [27] Google. 2023. Public DNS-Google for Developers. https://developers.goog
  UNMAPPED 2023/CCS/under-the-dark-a-systematical-study-of-stealthy-mining-pools-ab-use-in-the-wild | e source for identifying malicious activities, which is a publicly available open threat intelligence platform that synthesizes data from more than 70 anti-virus engines. The intelligence report for stealthy mining pool can be categorized into two folds, the IP analysis report
  UNMAPPED 2024/NDSS/like-comment-get-scammed-characterizing-comment-scams-on-media-platforms | In order to evaluate the current online blocklist for those websites, we utilize VirusTotal API, which is an online service that integrates more than 90 antivirus scanners and URL/domain blocklisting services [39]. Following standard VirusTotal labeling practices[47], We define a
  UNMAPPED 2023/WWW/measuring-and-evading-turkmenistans-internet-censorship-a-case-study-in-large-sc | ily refect the opinions of the sponsors. REFERENCES [1] 2010. Tor Metrics. https://metrics.torproject.org/userstatsrelay-country.html?start=2021-01-01&end=2022-09-28&country= tm&events=off Accessed September 2022. [2] 2019. Turkmenistan Blocks DNS-over-HTTPS Resolvers. https:
  UNMAPPED 2017/IEEE-SP/a-lustrum-of-malware-network-communication-evolution-and-insights | 2] DGArchive. https://dgarchive.caad.fkie.fraunhofer.de/, 2016. [13] DNS-BH - Malware Domain Blocklist. http://www.malwaredomains. com/?cat=140, 2016. [14] DynDNS. http://dyn.com/remote-access, 2016. [15] Find Domain Names for Your DynDNS Pro Plan. http://dyn.com/ remote-acces
  UNMAPPED 2016/IEEE-SP/sending-out-an-sms-characterizing-the-security-of-the-sms-ecosystem-with-public |  July 2015 and has shared over 2,802 Bitly links. The SPAM campaigns, phishing campaigns, and even one black destination domain has a 0/65 detection ratio on VirusTotal. market as discussed in Section V-A. In this section, we will We were surprised at the low spam volume observ
  UNMAPPED 2025/USENIX/irblock-a-large-scale-measurement-study-of-the-great-firewall-of-iran | .org. [3] Data explorer | cloudflare radar - http versions time series for as58224. https://radar.cloudflare. com/explorer?dataSet=http&dt=12w&loc=58224& groupBy=http_version. [4] DB-IP: IP Geolocation API & Free Address Database. https://db-ip.com. [5] Dynamic UDP port 
  UNMAPPED 2026/NDSS/actively-understanding-the-dynamics-and-risks-of-the-threat-intelligence-ecosystem | available and no human in the loop for registration). We included five additional well-known vendors given our prior knowledge. The full list of 40 vendors considered in this paper is in Table XI. Although there is no agreed upon categorization in the literature, we group vendor
  UNMAPPED 2026/USENIX/cracks-in-the-walled-garden-dissecting-the-gray-market-of-unauthorized-ios-app-d | hannels. Their presence highlights 1 Search format: "https://itunes.apple.com/search?term={Baseapp}&country= {Country}&entity=software&limit=1" the broader scope of the unofficial iOS distribution ecosystem and raises legal and ethical concerns. 7.2 Dylib-Based Modification Me
  UNMAPPED 2018/IEEE-SP/the-spyware-used-in-intimate-partner-violence | sis We also evaluate whether Virustotal [57], an aggregator of many anti-virus engines, can be used to identify IPS apps. Virustotal hosts more than 60 anti-virus engines (AV engines), and a large number of tools for static and dynamic analysis of content. Access to the Virust
  UNMAPPED 2012/IEEE-SP/abusing-file-processing-in-malware-detectors-for-fun-and-profit | ifferent header 1 header 2 contents will be extracted depending on which program is length chksum file 1 length chksum file 2 used. 20 out of 36 scanners fail to detect the infection. Other werewolf files that can be parsed according to regular TAR archive multiple formats a
  UNMAPPED 2016/IEEE-SP/cloak-of-visibility-detecting-when-machines-browse-a-different-web | ew of the cloaking websites we identified are distributing malware. For example, saomin.com, delivers to mobile user an Android app that is flagged as malicious by 19 AntiVirus engines on VirusTotal. In another case, the user was encouraged to install a malicious browser extensio
  UNMAPPED 2025/IMC/decoy-databases-analyzing-attacks-on-public-facing-databases |  readability. 9 HOST=$ { s e r v e r / / : ∗ } 10 PORT=$ { s e r v e r / / ∗ : } 11 [ [ x " $ { HOST } " == x " $ { PORT } " ] ] && PORT=80 12 1 NewConnect 13 e x e c 3 < >/ dev / t c p / $ { HOST } / $PORT 2 JDWP− Handshake 14 echo −en " GET $ {DOC} HTTP / 1 . 0 \ r \ n
  UNMAPPED 2026/NDSS/phishlang-a-real-time-fully-client-side-phishing-detection-framework-using-mobilebert | ng form rendered only after CAPTCHA interac- interpret. The GPT prompt used for this task is provided in tion <iframe> with width=1, height=1, or the next page. opacity: 0 Clickjacking [95, 16] z-index stacking to overlay invisible login forms We also used a GPT prompt later
  UNMAPPED 2021/IEEE-SP/survivalism-systematic-analysis-of-windows-malware-living-off-the-land | J [26] Impact Cyber Trust, "GT Malware Netflow Daily Feed," 2020. [Online]. Available: https://impactcybertrust.org/dataset{ }view?idDataset=1143 [27] D. Kim, B. J. Kwon, and T. Dumitras, "Certified Malware: Measuring breaches of trust in the windows code-signing PKI," Proceed
  UNMAPPED 2022/IEEE-SP/symbexcel-automated-analysis-and-understanding-of-malicious-excel-4-0-macros | e antivirus engine. The median detection rate WsatConfig.exe starts. This technique is particularly interest- of the public samples is 28 out of 75 engines. However, the median ing since it is significantly different from most observed malicious detection rate for the domains and
Zhu et al. USENIX 2020 surveyed 115 papers (2008–2018, Google Scholar, not this corpus):
  22 of 115 did not describe their processing; of the remaining 93, 82 used a threshold;
  50 set t=1; 9 set 1<t<5; 15 set t>=5; 4 set t<50%; 4 set t>=50%; 10 used a reputable subset.
 
========================================================================
I. API TIER (hand map; sweep must match API_TIER keys both ways)
========================================================================
tight API-tier sweep of UNION                       15
Role              Papers  Share of 15
----------------  ------  -----------
used-academic     4       26.7%
used-private      4       26.7%
used-premium      1       6.7%
used-public       2       13.3%
samples-academic  1       6.7%
describes-public  1       6.7%
cites-public-v2   1       6.7%
citation          1       6.7%
used an academic/private/premium/public API (hand)  11  4.0% of UNION
used-academic                                       4
20K/day academic license (children websites 2024)   1 paper names 20K/day/per academic license
API_TIER vs sweep                                   OK both directions
  2011/CCS/bitshred-feature-hashing-malware-for-scalable-triage-and-semantic-analysis	used-private
  2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal	describes-public
  2016/IMC/an-analysis-of-the-privacy-and-security-risks-of-android-vpn-permission-enabled	used-public
  2017/CCS/certified-malware-measuring-breaches-of-trust-in-the-windows-code-signing-pki	used-private
  2019/IMC/opening-the-blackbox-of-virustotal-analyzing-online-phishing-scan-engines	cites-public-v2
  2019/WWW/a-multi-modal-neural-embeddings-approach-for-detecting-mobile-counterfeit-apps	used-private
  2019/WWW/the-chain-of-implicit-trust-an-analysis-of-the-web-third-party-resources-loading	citation
  2020/IEEE-SP/pmp-cost-effective-forced-execution-with-probabilistic-memory-pre-planning	samples-academic
  2021/NDSS/minos-a-lightweight-real-time-cryptojacking-detection-system	used-premium
  2021/WWW/twiti-social-listening-for-threat-intelligence	used-private
  2022/CCS/phishing-url-detection-a-network-based-approach-robust-to-evasion	used-academic
  2022/USENIX/helping-hands-measuring-the-impact-of-a-large-threat-intelligence-sharing-commun	used-academic
  2024/IEEE-SP/targeted-and-troublesome-tracking-and-advertising-on-childrens-websites	used-academic
  2024/PETS/a-black-box-privacy-analysis-of-messaging-service-providers-chat-message-process	used-academic
  2025/IMC/fishing-for-smishing-understanding-sms-phishing-infrastructure-and-strategies-by	used-public
 
========================================================================
J. AVCLASS full-text (corpus, not only UNION)
========================================================================
full-text AVClass/AVClass2                          47 of 5859
  of which in the VT UNION                          41
 
========================================================================
K. DETECTION.PREVALENCE tuples that name VirusTotal
========================================================================
prevalence tuples naming VT                         167 across 119 papers of 277
  2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem	More than 22% of samples successfully infected the whole system	Even though not each purportedly infected file leads to malicious activities, we could observe that more than 22% of our samples managed to 
  2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem	about 55% of samples included malware	considering fresh reports with the same Virustotal detection percentage, about 55% of our samples would include malware.
  2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem	36.32% (1,268 samples) were previously unknown	more than 36.32% (1, 268 samples) of our cracks and keygens were previously unknown to Virustotal and had no existing report.
  2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem	243 of 2,285 possibly infected samples (10.63%)	out of 2, 285 possibly infected samples, only 243 (10.63%) used a packer that was detected by Virustotal.
  2013/WWW/bitsquatting-exploiting-bit-flips-for-fun-or-profit	2.3% flagged one executable as packed malware; 28.6% flagged a fake antivirus	Five other domains, e.g., microskft.com and microsogt.com, were redirecting the unsuspecting user to the domain errorfix.com. That site was 
  2014/CCS/a-nearly-four-year-longitudinal-study-of-search-engine-poisoning	19.5% of unclassified results appeared malicious according to VirusTotal.	When we observe a difference in the HTML returned between the two treatments, we infer there might have been cloaking.
  2014/IEEE-SP/hunting-the-red-fox-online-understanding-and-detection-of-mass-redirect-script-i	409 infected JS files, with no false positives	Altogether, our approach captured 409 infected JS files (with 277 URLs). All of them were confirmed through VirusTotal and manual analysis, 
  2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google	20 of 40 randomly chosen samples were likely zero-day malware	We analyzed 40 samples randomly chosen from this set and concluded that 20 of them were indeed problematic through manual analysis, likely t
  2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google	70.1%	The coverage of MassVet, with regard to the collective result of all 54 scanners, is 70.1%, better than what could be achieved by any indivi
  2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google	9.46% FDR and 1% FPR	This gives us a false detection rate (FDR: false positives vs. all detected) of 9.46% and a false positive rate (FPR: false positives vs. al
  2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google	379 apps disappeared within 90 days	40 days after uploading 3,711 apps ... to VirusTotal, we found that 250 of them disappeared from Google Play. 90 days later, another 129 app
  2015/CCS/certified-pup-abuse-in-authenticode-code-signing	Median 1.3 days; 8% were observed by VirusTotal over a month later.	Overall, it takes VT a median of 1.3 days to observe a sample, but the distribution is long-tailed.
  2015/USENIX/webwitness-investigating-categorizing-and-mitigating-malware-download-paths	5,536 downloads labeled malicious	Using the malicious executable identification process defined in Section 2.2, we labeled 5, 536 downloads as malicious.
  2014/IMC/the-dark-alleys-of-madison-avenue-understanding-malicious-advertisements	6,601 incidents; about 1% of 673,596 advertisements	In general, we identified 6,601 incidents in which the advertisements triggered our detection framework. Surprisingly, we observed that abou
  2014/IMC/the-dark-alleys-of-madison-avenue-understanding-malicious-advertisements	68 incidents	Malicious executables 68
  2014/IMC/the-dark-alleys-of-madison-avenue-understanding-malicious-advertisements	31 incidents	Malicious Flash 31
  2015/WWW/understanding-malvertising-through-ad-injecting-browser-extensions	roughly 4% on top-1000 Alexa websites	none of the ads originally embedded on the top-1000 Alexa websites were malicious, whereas we found that roughly 4% of extension-injected ad
  2014/USENIX/a-look-at-targeted-attacks-through-the-lense-of-an-ngo	No zero-day vulnerabilities were found; some were exploited within a week of disclosure.	We find no evidence of the use of zero-day vulnerabilities against our dataset, but several uses of disclosed vulnerabilities within the sam
  2014/USENIX/a-look-at-targeted-attacks-through-the-lense-of-an-ngo	No single antivirus detected all malicious documents.	No single AV detected all malicious documents despite their use of well-known vulnerabilities.
  2014/NDSS/execute-this-analyzing-unsafe-and-malicious-dynamic-code-loading-in-android-appl	PJApps detected by 33/46 VirusTotal and 7/7 AndroTotal engines; downloader detected by none	However, no anti-virus was able to detect the malicious nature of our downloder application.
  2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal	80.6 days on average before discovery	Nevertheless, the distribution has a long tail, with an average of 80.6 days (approximately 2.7 months) before discovery.
  2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal	9.24 days before VirusTotal detection on average	On average, we detect malware 9.24 days before the first VirusTotal detection.
  2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal	41.41% of binaries in malicious IGs were known malicious to other AV vendors	On average 41.41% of the binaries that construct the IGs are known to be malicious also by other AV vendors
  2016/CCS/acing-the-ioc-game-toward-automatic-discovery-and-analysis-of-open-source-cyber	IPs and domains often took more than 12 days; malware hashes usually within 2 days	Particularly, for IPs and domains, the whole process often took more than 12 days. On the other hand, the malware hashes were often quickly 
  2016/IMC/an-analysis-of-the-privacy-and-security-risks-of-android-vpn-permission-enabled	38% had at least one positive report; 4% had AV-rank higher than 5	38% of the analyzed VPN apps have at least one positive malware report according to VirusTotal but only 4% of them have an "AV-rank" higher 
 
========================================================================
L. STUDIES-VT QUOTES (load-bearing; checked against paper.cols.txt)
========================================================================
2019/IMC/opening-the-blackbox-of-virustotal-analyzing-online-phishing-scan-engines  quote-prefix-in-cols=yes
  we show that vendors have trouble flagging all phishing sites, and even the best vendors missed 30% of our phishing sites
2020/USENIX/measuring-and-modeling-the-label-dynamics-of-online-anti-malware-engines  quote-prefix-in-cols=yes
  50 papers set t = 1: a file is
2020/CCS/benchmarking-label-dynamics-of-virustotal-engines  quote-prefix-in-cols=yes
  we present VTSet, which contains daily VirusTotal labels on more than 14,000 files over one year
2023/IMC/re-measuring-the-label-dynamics-of-online-anti-malware-engines-from-millions-of  quote-prefix-in-cols=yes
  Our dataset involves all the scan data in VirusTotal over a 14-month period, including over 571 million samples and 847 million reports in total
 
========================================================================
Z. NON-CORPUS FIGURES (primary sources; re-fetched by external_checks_virustotal.sh)
========================================================================
Public API rate: 500 requests per day and 4 requests per minute
  source: docs.virustotal.com/reference/public-vs-premium-api  fetched 2026-08-27
Public API must not be used in commercial products or services
  same page
API v3 is the default; v2 "for the time being, will not be deprecated"
  source: docs.virustotal.com/reference/overview
last_analysis_stats URL/domain/IP keys: harmless, malicious, suspicious, timeout, undetected
  file object also has confirmed-timeout, failure, type-unsupported (docs.virustotal.com/reference/files)
  domain and IP objects have last_analysis_results with the same four per-engine categories as URL
  domain and IP objects have no first_submission_date (docs.virustotal.com/reference/domains-object and /reference/ip-object)
No standalone academic quota form; contact-us/legal has subject "I have an academic research request" (fetched 2026-08-27)
Wang IMC 2023 PE-file threshold recommendation t=1 to 24; overall low-grey bands 1-11 and 28-50
277 minus 4 title/slug studies = 273 remaining records (still an extractor upper bound)
last_analysis_date and first_submission_date are UTC unix timestamps on the object
Google Threat Intelligence migration: existing VT API automations keep working
  source: gtidocs.virustotal.com/docs/vt-migration-guide
VirusTotal support channel for GTI customers discontinued 2 December 2025 (already past as of this sitting)
  source: gtidocs.virustotal.com/docs/google-threat-intelligence-customer-migration
Vallina et al. academic key 20k/day (2019); children-websites paper names 20K/day/per academic license (IEEE S&P 2024)
Peng IMC 2019: 68 URL vendors; 15 of 68 detected at least one of 36 simple phishing sites; best vendor 26; IRS undetectable via VT scan API alone; 66 experimental websites
100k URLs at 500/day = 200 days (arithmetic; same figure on design:website_classification)
file object identifier is SHA-256
Zhu survey window 2008-2018 (Google Scholar, not this corpus)
Zhu USENIX 2020: 14,423 PE files, 65 engines, >1 year; 1,760,484 hazard flips and 811,325 non-hazard flips; t=1 is not a good threshold
Zhu CCS 2020 demo: VTSet, daily labels on more than 14,000 files over one year
Wang IMC 2023: 571 million samples, 847 million reports, 14 months; some findings contradict Zhu 2020
OVERVIEW.md folded used-tool ranking: VirusTotal 239 / 4.1% / 4th — different fold from this script's 262
 
ROLE/sweep guards                                   OK

Review log

Freeze snapshot: out/freeze_virustotal/ taken before the three focused reviewers were launched. The content page was not edited while they ran. Model on all four passes: GPT 5.6 Luna medium (gpt-5.6-luna-medium).

Reviewer 1 — figures vs script (GPT 5.6 Luna medium)

# Finding Decision
1 “Treating 70 rows as independent Bernoulli trials” — Zhu measured 65 engines; 70 is not a script figure. Accepted. Now “Zhu's 65 engine rows”.
2 “Everyone else is using it.” overstates the 277, which is an extractor upper bound. Accepted. Now: the other 273 records are not title/slug studies; still an upper bound, not a verified-user census.

Confirmed by this reviewer and held: report exit 0 and byte-identical to freeze; demo equals the <code> block; lookup/threshold/year/venue/API-tier tables; 14 topic-only / 195 non-topic; OVERVIEW 239 labelled as a different fold; Zhu 115 table scoped as Google Scholar; 277 labelled upper bound.

Re-run after edits: one leftover. “VirusTotal is the service everyone else used” in the lead still overclaimed verified use. Accepted. Lead now says “the usual aggregator,” with the 239/4th ranking in the next sentence.

Reviewer 2 — citations and quotes (GPT 5.6 Luna medium)

# Finding Decision
1 zhu2020_label BibTeX authors still TODO in out/vt_bib_raw.txt. Accepted. Authors from the USENIX paper header: Shuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin, Ziyi Zhang, Linhai Song, Gang Wang. No DOI.
2 WRAP said Wang “does not bless t = 1 either.” Wang's PE-file recommendation is t in 1–24; grey-share trend contradicts Zhu. Accepted. WRAP and the Wang paragraph now state the contradiction and the 1–24 PE range, and that this is not a default to copy.
3 “Zhu's measurement says not to use it” is broader than Zhu's PE-file result. Accepted. Now “Zhu's PE-file measurement says it is not a good threshold.”
4 VTSet BibTeX title omitted “Demo:”. Accepted. Title restored to “Demo: Benchmarking Label Dynamics of VirusTotal Engines.”

Citekeys on the page are exactly the five intended. Quotes listed in the freeze provenance table remain in .cols.

Reviewer 3 — external currency (GPT 5.6 Luna medium)

# Finding Decision
1 external_checks_virustotal.sh exited 2 (unescaped won't in grep); section F heading still said 2026-12-02. Accepted. Quoting fixed; heading is 2025-12-02; failures exit 1.
2 Academic access: live contact form has subject “I have an academic research request.” Accepted. Page and website_classification now name that form and still refuse a self-serve 20k/day assumption.
3 URL last_analysis_results categories do not include timeout; file stats may add confirmed-timeout / failure / type-unsupported. Accepted. Page text split stats vs per-engine categories. vt_label.py now ValueErrors on undocumented stats keys and includes the three file keys in total when present. Demo output unchanged.

Confirmed and held: 500/day and 4/min; v3 default / v2 not deprecated; v3 paths; GTI automations keep working; support cutoff 2 December 2025 already past; HTTPS URLs on the freeze page fetched; no Premium dollar figures.

Reviewer 4 — generic, no checklist (GPT 5.6 Luna medium)

# Finding Decision
1 Published script documented only file/URL/domain and always required first_submission_date; IP objects have no such field. Accepted. Script now accepts file / url / domain / ip_address. File and URL print first_submission_date; domain and IP omit the line. Unsupported types ValueError.
2 try/except KeyError: pass around optional file stats. Accepted. File objects require confirmed-timeout / failure / type-unsupported (direct access). URL/domain/IP objects do not print those keys.
3 –threshold 0 and negatives labelled every object malicious. Accepted. N < 1 exits 2.
4 When majority equals 1, 2, 4 or 10, that row was relabelled “majority” and the t=N row vanished. Accepted. t = 1, 2, 4, 10 always print; majority is a separate row. Demo output unchanged (majority = 3).
5 Schema sentence cited only URL and file docs for all four object types. Accepted. Domain and IP object docs linked; per-engine categories on those objects match URL (four, no timeout).

The page otherwise answered its question. Provenance focused-review log was honest; this section is the generic pass (no GENERIC_REVIEW placeholder). Re-run after those five edits: no leftover defects.

provenance/security/virustotal.txt · Last modified: by karel.kubicek.claude

Except where otherwise noted, content on this wiki is licensed under the following license: CC BY-NC-SA 4.0
CC BY-NC-SA 4.0 Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki