VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware Infrastructure

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com


VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure.

Announced on October 8, 2026, the update records exposed services, port activity, banners, and server fingerprints alongside existing threat intelligence.

The change helps researchers look beyond an IP address’s detection score. Earlier reports showed hosting details, passive DNS records, and files that contacted an address. The new data shows what a server exposes now, helping analysts find related hosts that have no malware detections.

A new Ports tab lists open, closed, and recently closed ports, together with service names, software versions, and timestamps. Records also include SSH host keys, RDP fingerprints, HTTP headers, and operating system details inferred from service responses.

VirusTotal keeps records when ports stop responding. Researchers can therefore check when a suspected C2 service was last seen online and compare that date with changes elsewhere in a campaign. This history adds context that a current detection score cannot provide.

VirusTotal Adds Daily Internet Scanning

The official announcement describes searches through the web interface and API. Queries such as entity:ip open_port:22 find exposed SSH services.

Bracket syntax ties conditions to specific ports, preventing a product on one port from being incorrectly matched with a version on another. These searches build on the methods covered in Cybersecuritynews.com’s VirusTotal threat research guide.

One investigation started with 91.219.237[.]110, an address listed in APT28 and Havoc collections. Its SSH fingerprint led researchers to 185.146.232[.]3, which had no detections, collections, or communicating files. Both hosts shared an OpenSSH build, nginx configuration, and an unusual certificate name, b4ck.my.

Searching that certificate name uncovered a third address, 96.9.125[.]59. Port timestamps suggested one server was being retired around the time another appeared.

However, VirusTotal warned that older malware links do not establish current ownership or APT28 attribution because IP addresses can change hands.

Fingerprint matches also need careful checks. Some SSH keys appeared across more than 1,400 cloud addresses because server templates reused them. An open port alone is similarly weak evidence. Searching Cobalt Strike’s default team server port returned over 1.5 million addresses, including hosts answering on many ports.

Another example exposed a NOX Stealer login panel at 5.175.221[.]206 on port 8443. The host also exposed SMB and RDP, with scan data identifying Windows Server 2022, nginx 1.24.0, and PHP 8.3.33. Combining those traits reduced a search from 4.5 million hosts to ten candidates, not ten confirmed malicious servers.

When the panel changed its name to BOMBAY Stealer, browser analysis captured the new title while the exposed services stayed unchanged. Researchers also searched FTP banners containing “conhost,” finding five addresses tied to command-delivery patterns discussed in E4del and PINHOLE research.

Port data is available through API records and history endpoints, but not yet through IP Livehunt rules. Saved searches run on a schedule offer a workaround. Teams planning automation can consult Cybersecuritynews.com’s VirusTotal access overview and API documentation and check their account limits.

Stops threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC

The post VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware Infrastructure appeared first on Cyber Security News.