Table of Contents
Provenance: security:virustotal
Working log behind virustotal. Corpus-wide caveats are on corpus. Citations use the shared bibliography; this page adds no keys of its own.
Run: 2026-08-27. Corpus: 5,859 extracted papers, 7 venues, 2010–2026, data/extract/run1. Item: drain wiki-measuretheweb / “security:virustotal (new)”, claimed as cursor-drain-virustotal, store id 222, run 60. Author of the page and this log: Cursor, not Claude Code. Reviews: three focused passes then one generic, all on GPT 5.6 Luna medium (gpt-5.6-luna-medium), the sitting's requested substitute for the spec's sonnet/fable split.
Creating, not extending. ?do=export_raw on security:virustotal returned the HTML error page (not an existence test by byte count). dw.mjs pages does not list provenance:. Neighbour security already linked the red child. Overlap judgement: write the promised child rather than widen website_classification — that page owns topic categories; this one owns the maliciousness oracle.
No ~~DISCUSSION~~ on this provenance page. Comments belong on the content page.
Scope decisions
| Decision | Why | What a reasonable person might have done instead |
|---|---|---|
| Keep the 277 as an upper bound, do not hand-map all 277 roles | Namespace sitting already found a references-only hit labelled used. 277 papers is a week of reading. | Hand-map the 107 web papers. Defensible; not this sitting. |
| Cite Zhu's 115 for “what people did” rather than our 98-hit regex | The 98 is an upper bound with 47-paper residue (clustering t, F-beta, t = 43 days). Zhu hand-read 93 methods. | Publish 98/277 as “35% state a threshold”. That would be a lie about the residue. |
| Four lookups as objects, not as “VirusTotal” | Mixing file-hash results with URL-scan results is the bug Peng measured. | One “how to call the API” tutorial. Rejected: MDN/docs already exist. |
| No malware-datasets child | Already rejected on security. | — |
| Cross-link, do not duplicate, the 500/day cap | Already dated on website_classification. Repeated here because the oracle user hits the same cap. | Point only, omit the number. Worse for a reader who never opens the other page. |
Report script
scripts/report_virustotal.mjs plus scripts/vt_fold.mjs. Deterministic. Re-run:
node scripts/report_virustotal.mjs > scripts/report_virustotal-output.txt
Exits 1 if missing paper.cols.txt is not 4, if STUDIES_VT and the title/slug sweep disagree, or if API_TIER and the tight API-tier sweep disagree. A printed FAILURE with exit 0 is forbidden.
python3 pages/vt_label.py –demo is the published script. Its output is quoted in a <code> block; external_checks_virustotal.sh asserts equality.
Queries
| # | Query | Population / denominator | Result | On the page? |
|---|---|---|---|---|
| Q1 | Extraction records | all | 5,859 | outer frame |
| Q2 | UNION tools/classification/sourceList /virus total/i, used+produced+source | 5,859 | 277 (107 web, 107 crawled) | yes, labelled upper bound |
| Q3 | tools used/produced | 5,859 | 262 | yes |
| Q4 | of Q3, category classification-service | 262 | 254 (96.9%) | yes |
| Q5 | classification used/produced | 5,859 | 209 | yes |
| Q6 | lookup kind from classification.target (multi) | 209 | file 92, domain 43, apk 37, topic 16, url 12, ip 11, other 9 | yes |
| Q7 | topic-only | 209 | 14 | yes |
| Q8 | non-topic VT target | 209 | 195 | yes |
| Q9 | distinct raw strings, no fold | union any-role 279 | 64 | yes |
| Q10 | full-text VT | 5,855 with .cols | 332; schema-used ∩ ft = 277 / 0 / 55 | yes, 0 schema-only |
| Q11 | title/slug studies VT | 277 | 4 (Peng, Zhu USENIX, Zhu CCS demo, Wang IMC) | yes; STUDIES_VT both directions |
| Q12 | THRESHOLD_RE on UNION | 277 | 98 (35.4%), upper bound | yes, with family table and residue |
| Q13 | Q12 minus homograph family | 98 | 92, still an upper bound | yes |
| Q14 | API_TIER_RE, hand map | 277 | 15; used academic/private/premium/public 11 (4.0%) | yes |
| Q15 | used-academic among Q14 | 15 | 4; one names 20k/day | yes |
| Q16 | AVClass/AVClass2 full text | 5,859 | 47; 41 in UNION | yes |
| Q17 | detection.prevalence naming VT | 277 | 167 tuples / 119 papers | yes |
| Q18 | OVERVIEW.md folded used-tool VirusTotal | 5,859 | 239 / 4th | yes, as a different fold, do not mix |
| Q19 | year buckets of UNION | 277 | 23 / 62 / 71 / 76 / 45* | yes |
| Q20 | venue of UNION | 277 | USENIX 59 … PETS 6 | yes |
Folding and residue
No name-fold on VirusTotal. 64 distinct strings are products, feeds, thresholds and combinations. Count published; list in the report.
Lookup kind is a fold of classification.target, not of free-text. other:malicious URLs → url, other:PDF documents → file. Residue of that fold is the 9 “other”.
THRESHOLD_RE is an upper bound. Family fold of the first matching context: any-engine-t1 10, t2-to-t5 19, t6-or-more 16, homograph 6, unmapped 47. The 47 are printed in the report. Several are real detection ratios (“33 out of 46”, “more than 40 AV engines”) that the family regexes missed; they are why 92 is still an upper bound rather than a census. We did not pretend to finish the hand map.
API_TIER is a 15-row hand map. Roles and deciding sentences in vt_fold.mjs. Sweep and map agree both ways.
STUDIES_VT is four title/slug hits. Zhu USENIX quote used 50 papers set t = 1: a file is because the 82-out-of-93 sentence is column-spliced; both strings are in paper.cols.txt. The 82/93 figure is still on the content page, taken from the same paragraph.
Quotes spot-checked
| Paper | Needle | In .cols? |
|---|---|---|
| Peng IMC 2019 | even the best vendors missed 30% of our phishing sites | yes |
| Peng IMC 2019 | only pulls the previous scanning results when a new scan request is submitted | yes |
| Zhu USENIX 2020 | 50 papers set t = 1 | yes |
| Zhu USENIX 2020 | t = 1 is not a good threshold | yes |
| Zhu CCS 2020 | daily VirusTotal labels on more than 14,000 files over one year | yes |
| Wang IMC 2023 | 571 million samples and 847 million reports | yes |
Zhu's 1,760,484 hazard flips and 811,325 non-hazard flips, 14,423 files, 65 engines, 115 papers, 22/115 silent, 82/93 threshold, 50 at t=1: all read from paper.cols.txt (some across a column break). Peng 68 vendors, 15/68, best vendor 26, 36 simple sites, IRS undetectable via scan API alone: same. Wang's contradiction with Zhu is stated as Wang's claim, not re-derived.
External sources
Fetched 2026-08-27, re-checked by scripts/external_checks_virustotal.sh:
- docs.virustotal.com/reference/public-vs-premium-api — 500/day, 4/min, no commercial.
- docs.virustotal.com/reference/overview — v3 default, v2 not deprecated.
- docs.virustotal.com/reference/url-object, /reference/files, /reference/domains-object, /reference/ip-object — URL/domain/IP
last_analysis_statsfive keys and four per-engine categories; file object also documentsconfirmed-timeout,failure,type-unsupported. Domain and IP have nofirst_submission_date.timeoutis a stats bucket, not a per-engine category. - gtidocs.virustotal.com/docs/vt-migration-guide — existing automations keep working.
- gtidocs.virustotal.com/docs/google-threat-intelligence-customer-migration — VirusTotal support channel for GTI customers ended 2 December 2025 (already past). An earlier draft of the content page wrote 2026-12-02; that was a year-slip and was corrected before review freeze.
- www.virustotal.com/gui/contact-us/legal — subject line “I have an academic research request” (fetched 2026-08-27). Not a self-serve 20k/day form.
Rejected: SEO pricing pages quoting $1,500–$4,000/mo for Premium. No primary source. Not on the page.
Academic access: no standalone quota-application form. The contact-form subject is the live path; four corpus papers still name an academic licence; one names 20k/day.
What could not be established
- A complete citation-only map of the 277. A REFERENCES-heading heuristic found 6 cite-only of 132 with a heading; 139 papers have no REFERENCES heading in
.cols, so the heuristic is not a population filter. - A complete threshold census of the 277. Residue 47/98.
- Whether OVERVIEW.md's 239 and this script's 262 are the same papers under a different fold. Not mixed on the page.
- Live engine count today (needs an API key). Page tells the reader to read
last_analysis_statson their object. - A published academic quota number other than what papers already named (20k/day). The contact form does not state a quota.
Published script
pages/vt_label.py. Stdlib. –demo fixture is internally consistent (2 malicious of 4 engines). Requires the v3 data.attributes wrapper; missing last_analysis_stats is a KeyError. Undocumented stats keys are a ValueError. File objects must include the three extra stats keys and they count toward total. Domain and IP objects have no first_submission_date. Advertised flags: a JSON path, –demo, –threshold N with N >= 1. Giving both or neither, or N < 1, exits 2.
Bibliography keys added
Collision-checked against a fresh export of live literature:bibliography (not the stale pages/literature_bibliography.txt). peng2019_opening and vallina2020_misshapes already live. Added: zhu2020_label, zhu2020_vtset, wang2023_remeasuring.
zhu2020_label is USENIX: no DOI in the index. Authors hand-written from the paper header (Shuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin, Ziyi Zhang, Linhai Song, Gang Wang). scripts/fetch_authors.py returned BIT/BUPT/USTC as authors — the known affiliation-glue bug (audit-usenix-author-lists). Do not use that cache row.
Report output (unedited)
- report_virustotal-output.txt
======================================================================== A. CORPUS ======================================================================== corpus papers 5859 empirical 5118 crawled 1120 web platform 1622 classified 4439 missing paper.cols.txt 4 ======================================================================== B. POPULATION (schema UNION, upper bound on true use) ======================================================================== tools[].name matches VT (any role) 263 used or produced 262 classification.resourceName matches (any role) 211 used or produced 209 population.sourceList matches 62 UNION used/produced/source 277 UNION any role 279 of UNION: web platform 107 38.6% of UNION: crawled 107 38.6% tool-used with category classification-service 254 96.9% of tool-used PAGE POPULATION: the UNION of 277 is the headline upper bound. The web slice (107) is the student who is measuring the web. The rest are mostly file/APK malware papers using the same instrument. Topic-classifier use (website-category) is counted below and sent to design:website_classification. Do not mix OVERVIEW.md folded-tool 239 / 4th with this 262 used-or-produced. distinct raw strings (no fold) 64 raw strings (count is tuples, not papers): 482 VirusTotal 14 VirusTotal API 5 VirusTotal Intelligence 4 VirusTotal feed 4 VirusTotal Intelligence API 3 VirusTotal internal data 3 VirusTotal Relations 3 VirusTotal Retrohunt 2 Virus Total 2 VirusTotal intelligence API 2 VirusTotal IP and graph APIs 2 VirusTotal Premium API 2 VirusTotal URL feed 2 VirusTotal's URL reputation service 1 30% VirusTotal detection threshold (custom) 1 AMD reports and VirusTotal reports 1 Bazaar and VirusTotal 1 Drebin dataset and VirusTotal 1 filtered VirusTotal APK corpus 1 ForcePoint engine via VirusTotal 1 Google Play and third-party Android markets plus VirusTotal 1 Google Safe Browsing and VirusTotal 1 Hacking forums and VirusTotal 1 Malsign, Malcert, Symantec data set, Samples from WINE and VirusTotal 1 MalwareBazaar, Hybrid Analysis, VirusTotal, and direct botnet downloads 1 MalwareConfig, Shodan, VirusTotal, @Scum, and ReversingLabs 1 MalwareConfig, Shodan, VirusTotal, and ReversingLabs 1 Mozilla's PDF.js test suite and VirusTotal 1 PDF.js test suite, VirusTotal, and V8 regression test suite 1 SEISMIC; MineSweeper; Musch et al.; VirusTotal; VirusShare; NoCoin; MadeWithWasm 1 six VirusTotal machine-learning engines 1 VirusShare, VirusTotal, and the AMD dataset 1 VirusTotal and abuse.ch 1 VirusTotal and Github 1 VirusTotal and malware.lu 1 VirusTotal and MalwareBazaar 1 VirusTotal and VirusShare 1 VirusTotal antivirus detections 1 VirusTotal antivirus reports 1 VirusTotal API and Google SafeBrowsing 1 VirusTotal AV engines 1 VirusTotal AV-engine threshold (t=4) 1 VirusTotal Balanced Dataset 1 VirusTotal blacklists 1 VirusTotal CVE tags and AV-vendor scanner 1 VirusTotal distribute API 1 VirusTotal Hunting 1 VirusTotal Intelligence Search 1 VirusTotal malware configurations 1 VirusTotal private API v3.0 1 VirusTotal public API 1 VirusTotal Public API v2.0 1 VirusTotal report APIs 1 VirusTotal score 1 VirusTotal URL Feed 1 VirusTotal vhash 1 VirusTotal-labeled malware subset 1 VirusTotal, certificate-matched potentially benign samples 1 VirusTotal, HybridAnalysis, and MetaDefender 1 VirusTotal, MetaDefender, and HybridAnalysis 1 VirusTotal, MetaMask, SEAL-ISAC, Google Safe Browsing, WalletGuard, Phishfort, and ChainPatrol 1 VirusTotal, Qihoo 360, and Baidu 1 VirusTotal, URLQuery, Malware Domain List, and VxVault 1 VX Heaven, VirusShare, and VirusTotal ======================================================================== C. FULL-TEXT SWEEP versus schema ======================================================================== full-text /virus total|virustotal/i 332 missing=4 schema-used ∩ full-text: both=277 schema-only=0 ft-only=55 0 schema-only means the schema does not invent papers the full text never names. It does NOT mean every used label is true use. ft-only includes bibliography hits. ft-only count 55 ======================================================================== D. CLASSIFICATION TARGET (used VT resource; papers, multi-valued) ======================================================================== Target Papers Share of 209 ---------------------------------------------------------------------- ------ ------------ malware 86 41.1% domain 42 20.1% mobile-app 37 17.7% website-category 16 7.7% ip-address 11 5.3% web-request 10 4.8% vulnerability 5 2.4% other:downloaded software 1 0.5% other:advertiser binaries and software families 1 0.5% other:exposed URLs 1 0.5% other:malicious URLs 1 0.5% other:VirusTotal engine detection labels 1 0.5% other:PDF documents as malicious 1 0.5% other:website blacklist status 1 0.5% other:STIX indicator values as malicious or non-malicious 1 0.5% other:threat type of files 1 0.5% other:shared files, proxy IPs, VPN configurations, and HTTP injections 1 0.5% other:malware behavior risk reports 1 0.5% user-generated-text 1 0.5% other:cryptomining processes 1 0.5% class-used papers 209 ======================================================================== E. LOOKUP KIND (folded from classification.target of used VT resources) ======================================================================== Lookup kind Papers Share of 209 ----------- ------ ------------ file 92 44.0% apk 37 17.7% url 12 5.7% domain 43 20.6% ip 11 5.3% topic 16 7.7% other 9 4.3% topic = website-category. That use is design:website_classification, not this page. topic papers 16 oracle (class-used minus topic-only possible mix) class-used 209; papers with a non-topic VT target 195 topic-only (no other VT target on the paper) 14 ======================================================================== F. YEAR AND VENUE of UNION ======================================================================== Window Papers Share of 277 Web ---------- ------ ------------ --- 2010–2014 23 8.3% 10 2015–2018 62 22.4% 27 2019–2021 71 25.6% 24 2022–2024 76 27.4% 29 2025–2026* 45 16.2% 17 2025–2026* is provisional: CCS/IMC 2026 not held; IEEE S&P/WWW 2026 incompletely selected. Venue Papers Share of 277 ------- ------ ------------ USENIX 59 21.3% CCS 54 19.5% IEEE-SP 48 17.3% NDSS 46 16.6% WWW 33 11.9% IMC 31 11.2% PETS 6 2.2% ======================================================================== G. PAPERS THAT STUDY VIRUSTOTAL (title/slug) ======================================================================== title/slug about VT 4 2019/IMC/opening-the-blackbox-of-virustotal-analyzing-online-phishing-scan-engines studies-url Opening the Blackbox of VirusTotal: Analyzing Online Phishing Scan Engines. 2020/CCS/benchmarking-label-dynamics-of-virustotal-engines studies-file-demo Benchmarking Label Dynamics of VirusTotal Engines. 2020/USENIX/measuring-and-modeling-the-label-dynamics-of-online-anti-malware-engines studies-file Measuring and Modeling the Label Dynamics of Online Anti-Malware Engines 2023/IMC/re-measuring-the-label-dynamics-of-online-anti-malware-engines-from-millions-of studies-file Re-measuring the Label Dynamics of Online Anti-Malware Engines from Millions of Samples. STUDIES_VT vs title/slug OK both directions ======================================================================== H. THRESHOLD PROBE (upper bound; classifyThreshold on first matching context) ======================================================================== UNION papers matching THRESHOLD_RE 98 35.4% of 277 This is an UPPER BOUND. Clustering thresholds, F-beta, and "t = 0.6" still match. Family Papers Share of 98 ------------- ------ ----------- any-engine-t1 10 10.2% t2-to-t5 19 19.4% t6-or-more 16 16.3% homograph 6 6.1% unmapped 47 48.0% probe minus homograph family 92 still an upper bound on "stated an AV-engine threshold" unmapped residue 47 UNMAPPED 2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem | ctions, the higher is the probability that a sample is indeed infected with malware. In Virustotal reports, this ratio is commonly known as detection ratio. In contrast, Anubis calculates a severity score (Section 4.3.2) that reflects how malicious a sample behaved inside the ana UNMAPPED 2013/WWW/the-role-of-web-hosting-providers-in-detecting-compromised-websites | of 25/43 (25 antivirus engines detecting it, out of 43 it was tested against), and sb.exe, a copy of the 2011 Ramnit worm, detected by 36 out of 42 antivirus products according to VirusTotal. In order to make sure the malicious files were not reachable by any web visitor, but onl UNMAPPED 2015/USENIX/webwitness-investigating-categorizing-and-mitigating-malware-download-paths | cond level domains (e2LDs) of popular benign sites (e.g., microsoft.com, google. com, etc.). For the remaining downloads, we scan them with more than 40 antivirus (AV) engines, using virustotal.com. In addition, we rescan them periodically because many "fresh" malware files are n UNMAPPED 2014/NDSS/execute-this-analyzing-unsafe-and-malicious-dynamic-code-loading-in-android-appl | us applications on both the original PJApps sample and the downloader application we developed. When presented with the PJApps sample, 33 out of 46 anti-virus applications used by VirusTotal and all 7 used by AndroTotal correctly flagged the APK as malicious. However, no anti-vir UNMAPPED 2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal | ompared to the anti-virus products employed by VirusTotal. Algorithms TP rate FP rate F-score ROC Area 10-fold Cross Validation. We choose Nt = 40 and Nf = All Features 0.980 0.020 0.980 0.998 log2 (# of features) + 1, for our experiments. We observe that in- FI+FL+FD+FU 0.868 0. UNMAPPED 2015/IEEE-SP/the-attack-of-the-clones-a-study-of-the-impact-of-shared-code-on-vulnerability-p | ng rate was high, initially, followed by a drop and then by a second wave of patching activity (suggested by the inflection in the curve at t = 43 days). The second wave started on 25 May 2011, when the vulnerability survival was at 86%. According to analyst reports, a surge of a UNMAPPED 2016/IMC/an-analysis-of-the-privacy-and-security-risks-of-android-vpn-permission-enabled | rison of Android permissions (x-axis) requested by VPN apps and the top-1,000 non-VPN apps. VPN Apps Free # App ID Class Rating # Installs AV-rank # Trackers Premium Free All non-VPN Apps 1 OkVpn [35] Prem. 4.2 1K 24 0 65% 28% 33% 19% 2 EasyVpn [15] Prem. 4.0 50K 22 1 13% 10 UNMAPPED 2016/USENIX/towards-measuring-and-mitigating-social-engineering-software-download-attacks | ed executable files. To increase AV detections we "aged" the downloads in our dataset for a period of two months, before scanning them with more than 40 AV engines using virustotal.com. Notice that AV labels are mainly used for confirmation purposes. The actual labeling of SE att UNMAPPED 2016/WWW/no-honor-among-thieves-a-large-scale-analysis-of-malicious-web-shells | g the directory structure of the compromised website, such as, http://vict.im/admin/domainfonder.php? act=ls&d=/home/victim/public_html/&sort=0a. We recorded compromised websites all over the world, logging many instances of shells on websites of local businesses like an order s UNMAPPED 2017/CCS/hiding-in-plain-sight-a-longitudinal-study-of-combosquatting-abuse | ce. 2016. OPERATION DUST STORM. https://www.cylance.com/ hubfs/2015_cylance_website/assets/operation-dust-storm/Op_Dust_ Storm_Report.pdf?t=1477417126448. (February 2016). [31] Artem Dinaburg. 2011. Bitsquatting: DNS Hijacking without Exploitation. In Proceedings of BlackHat S UNMAPPED 2017/USENIX/6thsense-a-context-aware-sensor-based-attack-detector-for-smart-devices | ut these two only reported risks without clearly identifying any explicit malicious behaviour. Hence, it is difficult to Adversary Model Detection Ratio Threat-1 2/60 Threat-2 2/60 Threat-3 3/62 Table 8: VirusTotal scan result for the adversary models. detect the senso UNMAPPED 2017/USENIX/binsim-trace-based-semantic-binary-diffing-via-system-call-sliced-segment-equiva | t2(unsigned int n) 4: n = (n & (0x33333333)) + 1: void BitCount1(unsigned int n) 2: { ((n >> 2) & (0x33333333)); 2: { 3: unsigned int count = 0; 5: n = (n & (0x0f0f0f0f)) + 3: unsigned int count = 0; 4: while (n != 0 ) { ((n >> 4) & (0x0f0f0f0f)); 4: for (count = 0; n; n >>= UNMAPPED 2018/CCS/towards-paving-the-way-for-large-scale-windows-malware-analysis-generic-binary-u | de performance boost and 100% success rate. In the packed benign program experiments with three popular web browsers, we find that more that 20 anti-virus scanners generate false alarms, and all of the other three unpacking tools fail to extract the original code. BinUnpack's ou UNMAPPED 2018/IMC/beyond-google-play-a-large-scale-comparative-study-of-chinese-android-app-market | ndroid App Markets IMC '18, October 31-November 2, 2018, Boston, MA, USA Table 4: Percentage of apps labeled as malware in each market by AV-rank. 0.30 AV-rank (% apps) Market >= 1 >= 10 >= 20 0.25 Google Play 17.03 2.09 0.32 Percentage of Apps 0.20 Tencent Myapp 34.15 UNMAPPED 2018/IMC/characterizing-the-internet-host-population-using-deep-learning-a-universal-and | gia Tech Information Security Center. Malware Passive DNS Data. https: Wide Web. ACM, 639-648. //impactcybertrust.org/dataset_view?idDataset=520. [11] Hamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub, Kang G Shin, and Karl Aberer. 2018. Polisis: Automated Analysis and UNMAPPED 2019/CCS/hidenoseek-camouflaging-malicious-javascript-in-benign-asts | mples were detected (Donxref1 5 for classification purpose. HideNoSeek is a novel camouflage attimes and PowerShell 3 times), and by at most 2 AV-vendors. Even tack that rests upon the assumption that malicious obfuscation though the detection accuracy is very low, we envision UNMAPPED 2019/CCS/malmax-multi-aspect-execution-for-automated-dynamic-web-server-malware-analysis | [70]. Fourth, ClamAV is an open-source antivirus [20]. Fifth, we also use VirusTotal [1], an online aggregate service that scans files with more than 50 antivirus systems. There are also online PHP malware detection and deobfuscation services, such as unPHP [69] and shellray [49] UNMAPPED 2019/NDSS/mind-your-own-business-a-longitudinal-study-of-threats-and-vulnerabilities-in-enterprises | bilities. Even more worryingly, at 10 industries (between 78 and 199 days) is way above the least 10% of vulnerable servers are affected by more than 15 average 50% patch time across all applications (56 days). The vulnerabilities. One important observation is that 1.5M servers s UNMAPPED 2019/USENIX/reading-the-tea-leaves-a-comparative-analysis-of-threat-intelligence | load a file to be scanned. Upon submission, erage of VirusTotal as an oracle to detect targeted threats that these files will be scanned by more than 70 antivirus scanners, are not of broader interest. which creates a report on how many antivirus scanners mark To further understa UNMAPPED 2019/USENIX/tesseract-eliminating-experimental-bias-in-malware-classification-across-space-a | (N â 1) is a normalization factor so that AUT â [0, 1]. The perfect classifier with robustness to time decay in the time window S has AUT = 1. By default, AUT is computed as the area under point estimates, as they capture the trend of the classifier over time more closely; if UNMAPPED 2019/WWW/revisiting-mobile-advertising-threats-with-madlife | cyclmnrepv.com. Listing 1 shows the coinhive14 script used in 6(a). We submitted the embedded JavaScript file15 to VirusTotal, where 33 out of 58 scanners reported this script. We later found out that our discovery was confirmed by both Symantec [30] and Malwarebytes [40]. T UNMAPPED 2019/WWW/the-chain-of-implicit-trust-an-analysis-of-the-web-third-party-resources-loading | e solution which aggregates the scanning capabilities pro- they allow third-parties to load further third-parties on their behalf. vided by more than 68 AV tools, scanning engines and datasets. It The propensity to form dependency chains is marginally higher has been commonly use UNMAPPED 2019/WWW/understanding-the-evolution-of-mobile-app-ecosystems-a-longitudinal-measurement | e whether Google Play is moving towards higher security levels during its evolution. Table 4: Distribution of potential malware over time. AV-rank (# apps, % apps) Year â¥1 ⥠10 ⥠20 Google Play 2014 261,480 (17.17%) 44,664 (2.93%) 9,324 (0.61%) Google Play 2015 250,484 (15 UNMAPPED 2020/CCS/lies-in-the-air-characterizing-fake-base-station-spam-ecosystem-in-china | ase Stations. http://m.sohu.c om/n/444726367/. [15] 2016. Mobile Security Reports by Qihoo 360. http://zt.360.cn/2015/reportlist.htm l?list=1. [16] 2016. Research Reports: 2016 Fake Base Station of China. http://zt.360.cn /1101061855.php?dtid=1101061451&did=1101741409. [17] 20 UNMAPPED 2020/NDSS/flowprint-semi-supervised-mobile-app-fingerprinting-on-encrypted-network-traffic | destinations that belong to the same app. Our ci [t] · cj [t] experiments in Section V demonstrate that this method of (ci ? cj )norm = PT t=0 (4) fingerprint generation can be used for both app recognition t=0 max(ci [t], cj [t]) and detection of previously unseen apps. Using t UNMAPPED 2020/NDSS/prevalence-and-impact-of-low-entropy-packing-schemes-in-the-malware-ecosystem | he instruction tween 2013 and 2019. We only selected PE samples classified " mov WORD PTR [0x1000], 0x4142 " at the address as malicious by more than 20 antivirus engines, and such that 0x1234, PD manages the size directive adding the tuples the entropy of each section, of the en UNMAPPED 2020/PETS/the-tv-is-smart-and-full-of-trackers-measuring-smart-tv-advertising-and-tracking | s://firebog.net, 2019. [Online; accessed 2019-04-29]. [9] MoaAB: Mother of All AD-BLOCKING. https://forum.xdadevelopers.com/showthread.php?t=1916098, 2019. [Online; accessed 2019-04-22]. [10] Kromtech Alliance Corp. Stopad for tv. https://stopad.io/ tv, 2019. [11] Hooman Mohaj UNMAPPED 2021/USENIX/phishpedia-a-hybrid-deep-learning-based-approach-to-visually-identify-phishing-w | them discuss and come to a consensus. Then, we use VirusTotal [9] to check whether it reports the same results. VirusTotal is equipped with more than 70 engines for malicious webpage detection (e.g., Google Safebrowsing). If a real phishing webpage is reported by a specific solut UNMAPPED 2021/USENIX/understanding-malicious-cross-library-data-harvesting-on-android | before. To further libraries assess whether existing techniques can detect XLDH libraries, we leveraged VirusTotal [38], which aggregates more than 70 antivirus products, to scan all the XLDH libraries we found. Interestingly, no single product in the VirusTotal can detect a UNMAPPED 2023/CCS/efficient-query-based-attack-against-ml-based-android-malware-detection-under-ze | adversarial Android malware generated by AdvDroidZero, indicating a 100% ASR against these products. For Avira, AdvDroidZero reduces the detection ratio from 30.98% to 5.63%. For Microsoft, AdvDroidZero decreases the detection ratio from 57.74% to 7.04%. These results demons UNMAPPED 2023/IMC/re-measuring-the-label-dynamics-of-online-anti-malware-engines-from-millions-of | tion results in VirusTotal (see Section 5). We mainly focus on how the number of engines that detect the sample as malicious (which we call AV-Rank) varies over time for a given sample. We find an almost 50/50 split between samples with changes in AV-Rank and those that remain st UNMAPPED 2023/IMC/wolf-in-sheeps-clothing-evaluating-security-risks-of-the-undelegated-record-on-d | 23. Domain Names, Websites, and Hosting. https://sg.godaddy.com/. [26] Google. 2023. Google Scholar. https://scholar.google.com/scholar?start=0&as_ sdt=2005&sciodt=0,5&cites=1499698348405075976&scipsc=. [27] Google. 2023. Public DNS-Google for Developers. https://developers.goog UNMAPPED 2023/CCS/under-the-dark-a-systematical-study-of-stealthy-mining-pools-ab-use-in-the-wild | e source for identifying malicious activities, which is a publicly available open threat intelligence platform that synthesizes data from more than 70 anti-virus engines. The intelligence report for stealthy mining pool can be categorized into two folds, the IP analysis report UNMAPPED 2024/NDSS/like-comment-get-scammed-characterizing-comment-scams-on-media-platforms | In order to evaluate the current online blocklist for those websites, we utilize VirusTotal API, which is an online service that integrates more than 90 antivirus scanners and URL/domain blocklisting services [39]. Following standard VirusTotal labeling practices[47], We define a UNMAPPED 2023/WWW/measuring-and-evading-turkmenistans-internet-censorship-a-case-study-in-large-sc | ily refect the opinions of the sponsors. REFERENCES [1] 2010. Tor Metrics. https://metrics.torproject.org/userstatsrelay-country.html?start=2021-01-01&end=2022-09-28&country= tm&events=off Accessed September 2022. [2] 2019. Turkmenistan Blocks DNS-over-HTTPS Resolvers. https: UNMAPPED 2017/IEEE-SP/a-lustrum-of-malware-network-communication-evolution-and-insights | 2] DGArchive. https://dgarchive.caad.fkie.fraunhofer.de/, 2016. [13] DNS-BH - Malware Domain Blocklist. http://www.malwaredomains. com/?cat=140, 2016. [14] DynDNS. http://dyn.com/remote-access, 2016. [15] Find Domain Names for Your DynDNS Pro Plan. http://dyn.com/ remote-acces UNMAPPED 2016/IEEE-SP/sending-out-an-sms-characterizing-the-security-of-the-sms-ecosystem-with-public | July 2015 and has shared over 2,802 Bitly links. The SPAM campaigns, phishing campaigns, and even one black destination domain has a 0/65 detection ratio on VirusTotal. market as discussed in Section V-A. In this section, we will We were surprised at the low spam volume observ UNMAPPED 2025/USENIX/irblock-a-large-scale-measurement-study-of-the-great-firewall-of-iran | .org. [3] Data explorer | cloudflare radar - http versions time series for as58224. https://radar.cloudflare. com/explorer?dataSet=http&dt=12w&loc=58224& groupBy=http_version. [4] DB-IP: IP Geolocation API & Free Address Database. https://db-ip.com. [5] Dynamic UDP port UNMAPPED 2026/NDSS/actively-understanding-the-dynamics-and-risks-of-the-threat-intelligence-ecosystem | available and no human in the loop for registration). We included five additional well-known vendors given our prior knowledge. The full list of 40 vendors considered in this paper is in Table XI. Although there is no agreed upon categorization in the literature, we group vendor UNMAPPED 2026/USENIX/cracks-in-the-walled-garden-dissecting-the-gray-market-of-unauthorized-ios-app-d | hannels. Their presence highlights 1 Search format: "https://itunes.apple.com/search?term={Baseapp}&country= {Country}&entity=software&limit=1" the broader scope of the unofficial iOS distribution ecosystem and raises legal and ethical concerns. 7.2 Dylib-Based Modification Me UNMAPPED 2018/IEEE-SP/the-spyware-used-in-intimate-partner-violence | sis We also evaluate whether Virustotal [57], an aggregator of many anti-virus engines, can be used to identify IPS apps. Virustotal hosts more than 60 anti-virus engines (AV engines), and a large number of tools for static and dynamic analysis of content. Access to the Virust UNMAPPED 2012/IEEE-SP/abusing-file-processing-in-malware-detectors-for-fun-and-profit | ifferent header 1 header 2 contents will be extracted depending on which program is length chksum file 1 length chksum file 2 used. 20 out of 36 scanners fail to detect the infection. Other werewolf files that can be parsed according to regular TAR archive multiple formats a UNMAPPED 2016/IEEE-SP/cloak-of-visibility-detecting-when-machines-browse-a-different-web | ew of the cloaking websites we identified are distributing malware. For example, saomin.com, delivers to mobile user an Android app that is flagged as malicious by 19 AntiVirus engines on VirusTotal. In another case, the user was encouraged to install a malicious browser extensio UNMAPPED 2025/IMC/decoy-databases-analyzing-attacks-on-public-facing-databases | readability. 9 HOST=$ { s e r v e r / / : â } 10 PORT=$ { s e r v e r / / â : } 11 [ [ x " $ { HOST } " == x " $ { PORT } " ] ] && PORT=80 12 1 NewConnect 13 e x e c 3 < >/ dev / t c p / $ { HOST } / $PORT 2 JDWPâ Handshake 14 echo âen " GET $ {DOC} HTTP / 1 . 0 \ r \ n UNMAPPED 2026/NDSS/phishlang-a-real-time-fully-client-side-phishing-detection-framework-using-mobilebert | ng form rendered only after CAPTCHA interac- interpret. The GPT prompt used for this task is provided in tion <iframe> with width=1, height=1, or the next page. opacity: 0 Clickjacking [95, 16] z-index stacking to overlay invisible login forms We also used a GPT prompt later UNMAPPED 2021/IEEE-SP/survivalism-systematic-analysis-of-windows-malware-living-off-the-land | J [26] Impact Cyber Trust, "GT Malware Netflow Daily Feed," 2020. [Online]. Available: https://impactcybertrust.org/dataset{ }view?idDataset=1143 [27] D. Kim, B. J. Kwon, and T. Dumitras, "Certified Malware: Measuring breaches of trust in the windows code-signing PKI," Proceed UNMAPPED 2022/IEEE-SP/symbexcel-automated-analysis-and-understanding-of-malicious-excel-4-0-macros | e antivirus engine. The median detection rate WsatConfig.exe starts. This technique is particularly interest- of the public samples is 28 out of 75 engines. However, the median ing since it is significantly different from most observed malicious detection rate for the domains and Zhu et al. USENIX 2020 surveyed 115 papers (2008–2018, Google Scholar, not this corpus): 22 of 115 did not describe their processing; of the remaining 93, 82 used a threshold; 50 set t=1; 9 set 1<t<5; 15 set t>=5; 4 set t<50%; 4 set t>=50%; 10 used a reputable subset. ======================================================================== I. API TIER (hand map; sweep must match API_TIER keys both ways) ======================================================================== tight API-tier sweep of UNION 15 Role Papers Share of 15 ---------------- ------ ----------- used-academic 4 26.7% used-private 4 26.7% used-premium 1 6.7% used-public 2 13.3% samples-academic 1 6.7% describes-public 1 6.7% cites-public-v2 1 6.7% citation 1 6.7% used an academic/private/premium/public API (hand) 11 4.0% of UNION used-academic 4 20K/day academic license (children websites 2024) 1 paper names 20K/day/per academic license API_TIER vs sweep OK both directions 2011/CCS/bitshred-feature-hashing-malware-for-scalable-triage-and-semantic-analysis used-private 2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal describes-public 2016/IMC/an-analysis-of-the-privacy-and-security-risks-of-android-vpn-permission-enabled used-public 2017/CCS/certified-malware-measuring-breaches-of-trust-in-the-windows-code-signing-pki used-private 2019/IMC/opening-the-blackbox-of-virustotal-analyzing-online-phishing-scan-engines cites-public-v2 2019/WWW/a-multi-modal-neural-embeddings-approach-for-detecting-mobile-counterfeit-apps used-private 2019/WWW/the-chain-of-implicit-trust-an-analysis-of-the-web-third-party-resources-loading citation 2020/IEEE-SP/pmp-cost-effective-forced-execution-with-probabilistic-memory-pre-planning samples-academic 2021/NDSS/minos-a-lightweight-real-time-cryptojacking-detection-system used-premium 2021/WWW/twiti-social-listening-for-threat-intelligence used-private 2022/CCS/phishing-url-detection-a-network-based-approach-robust-to-evasion used-academic 2022/USENIX/helping-hands-measuring-the-impact-of-a-large-threat-intelligence-sharing-commun used-academic 2024/IEEE-SP/targeted-and-troublesome-tracking-and-advertising-on-childrens-websites used-academic 2024/PETS/a-black-box-privacy-analysis-of-messaging-service-providers-chat-message-process used-academic 2025/IMC/fishing-for-smishing-understanding-sms-phishing-infrastructure-and-strategies-by used-public ======================================================================== J. AVCLASS full-text (corpus, not only UNION) ======================================================================== full-text AVClass/AVClass2 47 of 5859 of which in the VT UNION 41 ======================================================================== K. DETECTION.PREVALENCE tuples that name VirusTotal ======================================================================== prevalence tuples naming VT 167 across 119 papers of 277 2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem More than 22% of samples successfully infected the whole system Even though not each purportedly infected file leads to malicious activities, we could observe that more than 22% of our samples managed to 2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem about 55% of samples included malware considering fresh reports with the same Virustotal detection percentage, about 55% of our samples would include malware. 2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem 36.32% (1,268 samples) were previously unknown more than 36.32% (1, 268 samples) of our cracks and keygens were previously unknown to Virustotal and had no existing report. 2012/CCS/vanity-cracks-and-malware-insights-into-the-anti-copy-protection-ecosystem 243 of 2,285 possibly infected samples (10.63%) out of 2, 285 possibly infected samples, only 243 (10.63%) used a packer that was detected by Virustotal. 2013/WWW/bitsquatting-exploiting-bit-flips-for-fun-or-profit 2.3% flagged one executable as packed malware; 28.6% flagged a fake antivirus Five other domains, e.g., microskft.com and microsogt.com, were redirecting the unsuspecting user to the domain errorfix.com. That site was 2014/CCS/a-nearly-four-year-longitudinal-study-of-search-engine-poisoning 19.5% of unclassified results appeared malicious according to VirusTotal. When we observe a difference in the HTML returned between the two treatments, we infer there might have been cloaking. 2014/IEEE-SP/hunting-the-red-fox-online-understanding-and-detection-of-mass-redirect-script-i 409 infected JS files, with no false positives Altogether, our approach captured 409 infected JS files (with 277 URLs). All of them were confirmed through VirusTotal and manual analysis, 2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google 20 of 40 randomly chosen samples were likely zero-day malware We analyzed 40 samples randomly chosen from this set and concluded that 20 of them were indeed problematic through manual analysis, likely t 2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google 70.1% The coverage of MassVet, with regard to the collective result of all 54 scanners, is 70.1%, better than what could be achieved by any indivi 2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google 9.46% FDR and 1% FPR This gives us a false detection rate (FDR: false positives vs. all detected) of 9.46% and a false positive rate (FPR: false positives vs. al 2015/USENIX/finding-unknown-malice-in-10-seconds-mass-vetting-for-new-threats-at-the-google 379 apps disappeared within 90 days 40 days after uploading 3,711 apps ... to VirusTotal, we found that 250 of them disappeared from Google Play. 90 days later, another 129 app 2015/CCS/certified-pup-abuse-in-authenticode-code-signing Median 1.3 days; 8% were observed by VirusTotal over a month later. Overall, it takes VT a median of 1.3 days to observe a sample, but the distribution is long-tailed. 2015/USENIX/webwitness-investigating-categorizing-and-mitigating-malware-download-paths 5,536 downloads labeled malicious Using the malicious executable identification process defined in Section 2.2, we labeled 5, 536 downloads as malicious. 2014/IMC/the-dark-alleys-of-madison-avenue-understanding-malicious-advertisements 6,601 incidents; about 1% of 673,596 advertisements In general, we identified 6,601 incidents in which the advertisements triggered our detection framework. Surprisingly, we observed that abou 2014/IMC/the-dark-alleys-of-madison-avenue-understanding-malicious-advertisements 68 incidents Malicious executables 68 2014/IMC/the-dark-alleys-of-madison-avenue-understanding-malicious-advertisements 31 incidents Malicious Flash 31 2015/WWW/understanding-malvertising-through-ad-injecting-browser-extensions roughly 4% on top-1000 Alexa websites none of the ads originally embedded on the top-1000 Alexa websites were malicious, whereas we found that roughly 4% of extension-injected ad 2014/USENIX/a-look-at-targeted-attacks-through-the-lense-of-an-ngo No zero-day vulnerabilities were found; some were exploited within a week of disclosure. We find no evidence of the use of zero-day vulnerabilities against our dataset, but several uses of disclosed vulnerabilities within the sam 2014/USENIX/a-look-at-targeted-attacks-through-the-lense-of-an-ngo No single antivirus detected all malicious documents. No single AV detected all malicious documents despite their use of well-known vulnerabilities. 2014/NDSS/execute-this-analyzing-unsafe-and-malicious-dynamic-code-loading-in-android-appl PJApps detected by 33/46 VirusTotal and 7/7 AndroTotal engines; downloader detected by none However, no anti-virus was able to detect the malicious nature of our downloder application. 2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal 80.6 days on average before discovery Nevertheless, the distribution has a long tail, with an average of 80.6 days (approximately 2.7 months) before discovery. 2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal 9.24 days before VirusTotal detection on average On average, we detect malware 9.24 days before the first VirusTotal detection. 2015/CCS/the-dropper-effect-insights-into-malware-distribution-with-downloader-graph-anal 41.41% of binaries in malicious IGs were known malicious to other AV vendors On average 41.41% of the binaries that construct the IGs are known to be malicious also by other AV vendors 2016/CCS/acing-the-ioc-game-toward-automatic-discovery-and-analysis-of-open-source-cyber IPs and domains often took more than 12 days; malware hashes usually within 2 days Particularly, for IPs and domains, the whole process often took more than 12 days. On the other hand, the malware hashes were often quickly 2016/IMC/an-analysis-of-the-privacy-and-security-risks-of-android-vpn-permission-enabled 38% had at least one positive report; 4% had AV-rank higher than 5 38% of the analyzed VPN apps have at least one positive malware report according to VirusTotal but only 4% of them have an "AV-rank" higher ======================================================================== L. STUDIES-VT QUOTES (load-bearing; checked against paper.cols.txt) ======================================================================== 2019/IMC/opening-the-blackbox-of-virustotal-analyzing-online-phishing-scan-engines quote-prefix-in-cols=yes we show that vendors have trouble flagging all phishing sites, and even the best vendors missed 30% of our phishing sites 2020/USENIX/measuring-and-modeling-the-label-dynamics-of-online-anti-malware-engines quote-prefix-in-cols=yes 50 papers set t = 1: a file is 2020/CCS/benchmarking-label-dynamics-of-virustotal-engines quote-prefix-in-cols=yes we present VTSet, which contains daily VirusTotal labels on more than 14,000 files over one year 2023/IMC/re-measuring-the-label-dynamics-of-online-anti-malware-engines-from-millions-of quote-prefix-in-cols=yes Our dataset involves all the scan data in VirusTotal over a 14-month period, including over 571 million samples and 847 million reports in total ======================================================================== Z. NON-CORPUS FIGURES (primary sources; re-fetched by external_checks_virustotal.sh) ======================================================================== Public API rate: 500 requests per day and 4 requests per minute source: docs.virustotal.com/reference/public-vs-premium-api fetched 2026-08-27 Public API must not be used in commercial products or services same page API v3 is the default; v2 "for the time being, will not be deprecated" source: docs.virustotal.com/reference/overview last_analysis_stats URL/domain/IP keys: harmless, malicious, suspicious, timeout, undetected file object also has confirmed-timeout, failure, type-unsupported (docs.virustotal.com/reference/files) domain and IP objects have last_analysis_results with the same four per-engine categories as URL domain and IP objects have no first_submission_date (docs.virustotal.com/reference/domains-object and /reference/ip-object) No standalone academic quota form; contact-us/legal has subject "I have an academic research request" (fetched 2026-08-27) Wang IMC 2023 PE-file threshold recommendation t=1 to 24; overall low-grey bands 1-11 and 28-50 277 minus 4 title/slug studies = 273 remaining records (still an extractor upper bound) last_analysis_date and first_submission_date are UTC unix timestamps on the object Google Threat Intelligence migration: existing VT API automations keep working source: gtidocs.virustotal.com/docs/vt-migration-guide VirusTotal support channel for GTI customers discontinued 2 December 2025 (already past as of this sitting) source: gtidocs.virustotal.com/docs/google-threat-intelligence-customer-migration Vallina et al. academic key 20k/day (2019); children-websites paper names 20K/day/per academic license (IEEE S&P 2024) Peng IMC 2019: 68 URL vendors; 15 of 68 detected at least one of 36 simple phishing sites; best vendor 26; IRS undetectable via VT scan API alone; 66 experimental websites 100k URLs at 500/day = 200 days (arithmetic; same figure on design:website_classification) file object identifier is SHA-256 Zhu survey window 2008-2018 (Google Scholar, not this corpus) Zhu USENIX 2020: 14,423 PE files, 65 engines, >1 year; 1,760,484 hazard flips and 811,325 non-hazard flips; t=1 is not a good threshold Zhu CCS 2020 demo: VTSet, daily labels on more than 14,000 files over one year Wang IMC 2023: 571 million samples, 847 million reports, 14 months; some findings contradict Zhu 2020 OVERVIEW.md folded used-tool ranking: VirusTotal 239 / 4.1% / 4th — different fold from this script's 262 ROLE/sweep guards OK
Review log
Freeze snapshot: out/freeze_virustotal/ taken before the three focused reviewers were launched. The content page was not edited while they ran. Model on all four passes: GPT 5.6 Luna medium (gpt-5.6-luna-medium).
Reviewer 1 — figures vs script (GPT 5.6 Luna medium)
| # | Finding | Decision |
|---|---|---|
| 1 | “Treating 70 rows as independent Bernoulli trials” — Zhu measured 65 engines; 70 is not a script figure. | Accepted. Now “Zhu's 65 engine rows”. |
| 2 | “Everyone else is using it.” overstates the 277, which is an extractor upper bound. | Accepted. Now: the other 273 records are not title/slug studies; still an upper bound, not a verified-user census. |
Confirmed by this reviewer and held: report exit 0 and byte-identical to freeze; demo equals the <code> block; lookup/threshold/year/venue/API-tier tables; 14 topic-only / 195 non-topic; OVERVIEW 239 labelled as a different fold; Zhu 115 table scoped as Google Scholar; 277 labelled upper bound.
Re-run after edits: one leftover. “VirusTotal is the service everyone else used” in the lead still overclaimed verified use. Accepted. Lead now says “the usual aggregator,” with the 239/4th ranking in the next sentence.
Reviewer 2 — citations and quotes (GPT 5.6 Luna medium)
| # | Finding | Decision |
|---|---|---|
| 1 | zhu2020_label BibTeX authors still TODO in out/vt_bib_raw.txt. | Accepted. Authors from the USENIX paper header: Shuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin, Ziyi Zhang, Linhai Song, Gang Wang. No DOI. |
| 2 | WRAP said Wang “does not bless t = 1 either.” Wang's PE-file recommendation is t in 1–24; grey-share trend contradicts Zhu. | Accepted. WRAP and the Wang paragraph now state the contradiction and the 1–24 PE range, and that this is not a default to copy. |
| 3 | “Zhu's measurement says not to use it” is broader than Zhu's PE-file result. | Accepted. Now “Zhu's PE-file measurement says it is not a good threshold.” |
| 4 | VTSet BibTeX title omitted “Demo:”. | Accepted. Title restored to “Demo: Benchmarking Label Dynamics of VirusTotal Engines.” |
Citekeys on the page are exactly the five intended. Quotes listed in the freeze provenance table remain in .cols.
Reviewer 3 — external currency (GPT 5.6 Luna medium)
| # | Finding | Decision |
|---|---|---|
| 1 | external_checks_virustotal.sh exited 2 (unescaped won't in grep); section F heading still said 2026-12-02. | Accepted. Quoting fixed; heading is 2025-12-02; failures exit 1. |
| 2 | Academic access: live contact form has subject “I have an academic research request.” | Accepted. Page and website_classification now name that form and still refuse a self-serve 20k/day assumption. |
| 3 | URL last_analysis_results categories do not include timeout; file stats may add confirmed-timeout / failure / type-unsupported. | Accepted. Page text split stats vs per-engine categories. vt_label.py now ValueErrors on undocumented stats keys and includes the three file keys in total when present. Demo output unchanged. |
Confirmed and held: 500/day and 4/min; v3 default / v2 not deprecated; v3 paths; GTI automations keep working; support cutoff 2 December 2025 already past; HTTPS URLs on the freeze page fetched; no Premium dollar figures.
Reviewer 4 — generic, no checklist (GPT 5.6 Luna medium)
| # | Finding | Decision |
|---|---|---|
| 1 | Published script documented only file/URL/domain and always required first_submission_date; IP objects have no such field. | Accepted. Script now accepts file / url / domain / ip_address. File and URL print first_submission_date; domain and IP omit the line. Unsupported types ValueError. |
| 2 | try/except KeyError: pass around optional file stats. | Accepted. File objects require confirmed-timeout / failure / type-unsupported (direct access). URL/domain/IP objects do not print those keys. |
| 3 | –threshold 0 and negatives labelled every object malicious. | Accepted. N < 1 exits 2. |
| 4 | When majority equals 1, 2, 4 or 10, that row was relabelled “majority” and the t=N row vanished. | Accepted. t = 1, 2, 4, 10 always print; majority is a separate row. Demo output unchanged (majority = 3). |
| 5 | Schema sentence cited only URL and file docs for all four object types. | Accepted. Domain and IP object docs linked; per-engine categories on those objects match URL (four, no timeout). |
The page otherwise answered its question. Provenance focused-review log was honest; this section is the generic pass (no GENERIC_REVIEW placeholder). Re-run after those five edits: no leftover defects.
