IDA Pro and VirusTotal Plugin

Marco Ramilli
Date
13 February 2012
Read
Share
This morning I came across an interesting article from HexBlog titled: VirusTotal Plugin for IDA Pro. I took a look to the date, and actually it's not really new, but I believe it is still very actual. What a nice idea having the possibility to monitor your binary directly from VirusTotal ! If you are a malware writer this will increase your productively a lot, in fact you might test your binary on most of the known antivirus engines and if it is catch, dynamically you are able to modify it and resubmit it to antivirus engines for a second round of test. An of course you could follow on this way as many time as you like.
Lets see how to install the plugin:
  1. You need to install on your platform simplejson (from here). It's a photon package for json ontology
  2. You need IDAPython 1.5.1 (from here)
  3. You need the plugin from here (BboeVt module) and VirusTotal plugin
  4. Copy the BboeVt module to you Python site-package
  5. Copy VirusTotal.py plugin to $IDAplugins folder
Lets see hot to use it:
  1. Run IDAPRO and open a database
  2. invoke VirusTotal Plugin (Alt-F8)
That's it !
A huge thank you to hexblog folks !

Marco Ramilli
Date
13 February 2012
Read
Share
← Go back
Latest Posts

i-SOON Data Leak: Key Points

Introduction i-SOON (上海安洵), a prominent contractor for various Chinese government agencies such […]

Date
26.02.2024
Duration
5 min
Text
Marco Ramilli

X Gold Badges: a new proliferating market

When I saw a threat actor hijacking the X account of Google's […]

Date
08.01.2024
Duration
5 min
Text
Marco Ramilli

Technical Data Sheet: LOCKBIT 3.0

LOCKBIT 3.0 is a notorious Ransomware Group that was first identified on […]

Date
20.12.2023
Duration
5 min
Text
Marco Ramilli
1 2 3 236
Back to Top
magnifier