RL Blog

Topics

All Blog PostsAppSec & Supply Chain SecurityDev & DevSecOpsProducts & TechnologySecurity OperationsThreat Research

Follow us

XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBluesky

Subscribe

Get the best of RL Blog delivered to your in-box weekly. Stay up to date on key trends, analysis and best practices across threat intelligence and software supply chain security.

ReversingLabs: The More Powerful, Cost-Effective Alternative to VirusTotalSee Why
Skip to main content
Contact UsSupportLoginBlogCommunity
reversinglabsReversingLabs: Home
Solutions
Secure Software OnboardingSecure Build & ReleaseProtect Virtual MachinesIntegrate Safe Open SourceGo Beyond the SBOM
Increase Email Threat ResilienceDetect Malware in File Shares & StorageAdvanced Malware Analysis SuiteICAP Enabled Solutions
Scalable File AnalysisHigh-Fidelity Threat IntelligenceCurated Ransomware FeedAutomate Malware Analysis Workflows
Products & Technology
Spectra Assure®Software Supply Chain SecuritySpectra DetectHigh-Speed, High-Volume, Large File AnalysisSpectra AnalyzeIn-Depth Malware Analysis & Hunting for the SOCSpectra IntelligenceAuthoritative Reputation Data & Intelligence
Spectra CoreIntegrations
Industry
Energy & UtilitiesFinanceHealthcareHigh TechPublic Sector
Partners
Become a PartnerValue-Added PartnersTechnology PartnersMarketplacesOEM Partners
Alliances
Resources
BlogContent LibraryCybersecurity GlossaryConversingLabs PodcastEvents & WebinarsLearning with ReversingLabsWeekly Insights Newsletter
Customer StoriesDemo VideosDocumentationOpenSource YARA Rules
Company
About UsLeadershipCareersSeries B Investment
EventsRL at RSAC
Press ReleasesIn the News
Pricing
Software Supply Chain SecurityMalware Analysis and Threat Hunting
Request a demo
Menu
Products & TechnologyJune 14, 2018

A Risk Not Worth Taking

Company’s are putting their data at risk by using VirusTotal, even when safer, superior options exist

FacebookFacebookXX / TwitterLinkedInLinkedInblueskyBlueskyEmail Us
A Risk Not Worth Taking

Over the last few months, almost all global companies have been focused on implementing changes across their IT systems and websites to meet GDPR compliance. But how many have considered how their existing security practices are affected by this new privacy law?

Recently at the FS-ISAC event in Boca Raton, Florida the topic of GDPR and security practices was discussed and interestingly one area of great risk was how companies utilize the VirusTotal open source malware database and the privacy concerns its use creates.

One threat intelligence researcher from a large retail bank commenting, “When I do a YARA query in VirusTotal with keywords like company name/username/ password/ etc., I am shocked at the sensitive and classified documents that appear.”

It was clear that many security teams do not understand the risk of VirusTotal’s open source structure. It was also clear that many researchers use VirusTotal “on the side” even though its use may not be approved by their company.

Another large global financial company researcher said his team monitors VirusTotal because, “You can actually catch the bad guys testing their latest malware against the AV scanners and that is a great source of early intelligence for the team.”

The discussion ended with GDPR compliance and what would happen if someone accidentally loaded a file into VirusTotal that is suspected of infection but also contained a list of EU client PII data. There were many comments that once a file is loaded, it is very difficult to get it out. One SOC director saying, “It is too late, you are done.”

So why do companies take the risk of using VirusTotal at all?

Mostly because they are unaware there are better alternatives. ReversingLabs, for example, offers the largest, most up-to-date and complete file intelligence service on the market. You can read all about our service and how it compares to VirusTotal here.

1) Over 40 billion samples of malware and goodware, with millions of samples added daily.

2) Trusted intelligence not dependent on crowdsourcing – get the highest fidelity intelligence from curated, continuous file harvesting backed by over 15 years of in-house threat research and proprietary analysis technology.

3) 100% private – private file analysis and private data corpus not accessible to the public.

4) Better and faster hunting - more file context means better YARA hunting and a more extensive Retro-search capability.

5) Real enterprise-class support – not only to help product usage but also to support your hunting efforts.

So, stop putting your company at risk – give us a call!


Explore RL's Spectra suite: Spectra Assure for software supply chain security, Spectra Detect for scalable file analysis, Spectra Analyze for malware analysis and threat hunting, and Spectra Intelligence for reputation data and intelligence.

Tags:Products & Technology

More Blog Posts

QR Code Phishing Is Evolving: Here’s How Your Detection Can Keep Up

QR Code Phishing Evolves: How to Keep Up

Here's what you need to know about the rise of quishing — and how your threat hunting team can get out in front of it.

Learn More about QR Code Phishing Evolves: How to Keep Up
QR Code Phishing Evolves: How to Keep Up
Why RL Built Spectra Assure Community

Why RL Built Spectra Assure Community

We set out to help dev and AppSec teams secure the village: OSS dependencies, malware, more. Learn how.

Learn More about Why RL Built Spectra Assure Community
Why RL Built Spectra Assure Community
How a Simple YARA Rule Catches What AV Misses

ClickFix: YARA Rules Catch What AV Misses

Learn about the antivirus detection gap — and how to develop a simple YARA rule using Spectra Analyze.

Learn More about ClickFix: YARA Rules Catch What AV Misses
ClickFix: YARA Rules Catch What AV Misses
Polyglot File Examination with Spectra Analyze

How to Examine Polyglot Files with Spectra Analyze

Here's how to assess a sample using Spectra Analyze in your environment — and create a YARA rule.

Learn More about How to Examine Polyglot Files with Spectra Analyze
How to Examine Polyglot Files with Spectra Analyze

Spectra Assure Free Trial

Get your 14-day free trial of Spectra Assure for Software Supply Chain Security

Get Free TrialMore about Spectra Assure Free Trial
Blog
Events
About Us
Webinars
In the News
Careers
Demo Videos
Cybersecurity Glossary
Contact Us
reversinglabsReversingLabs: Home
Privacy PolicyCookiesImpressum
All rights reserved ReversingLabs © 2026
XX / TwitterLinkedInLinkedInFacebookFacebookInstagramInstagramYouTubeYouTubeblueskyBlueskyRSSRSS
Back to Top