VYPR
researchPublished Oct 9, 2026· 1 source

VirusTotal Enhances Threat Hunting with Daily Public IPv4 Space Scanning

VirusTotal now scans the entire public IPv4 address space daily, providing security researchers with new tools to discover command-and-control servers and map malware infrastructure.

VirusTotal has rolled out a significant enhancement to its threat intelligence platform, introducing daily scans of the entire public IPv4 address space. This new capability aims to equip security teams with more robust methods for identifying command-and-control (C2) servers and tracking the infrastructure used by malware campaigns.

The update, announced on October 8, 2026, goes beyond simply recording IP addresses with known malware detections. It now captures and analyzes exposed services, detailed port activity, network banners, and server fingerprints. This richer dataset allows researchers to uncover related hosts and infrastructure that might otherwise go unnoticed, even if they don't have direct malware detections associated with them.

Previously, VirusTotal provided hosting details, passive DNS records, and files that communicated with an IP address. The new 'Ports' tab offers a granular view of open, closed, and recently closed ports, along with associated service names, software versions, and precise timestamps. This historical data on port activity and service changes is crucial for understanding the evolution of threat actor infrastructure and tracking campaigns over time.

Researchers can leverage this historical data to determine when a suspected C2 service was last active and correlate these changes with other events within a campaign. This context is invaluable for attribution and understanding the operational tempo of threat actors, offering insights that a simple detection score cannot provide.

The platform's web interface and API have been updated to support new search queries. For instance, researchers can now search for specific exposed services, such as entity:ip open_port:22 to find hosts exposing SSH services. The use of bracket syntax allows for precise conditions tied to specific ports, preventing misattributions where a product on one port might be incorrectly matched with a version on another.

While the new scanning capabilities offer powerful new avenues for investigation, VirusTotal cautions against drawing definitive conclusions solely based on shared fingerprints or open ports. For example, identical SSH keys can appear across thousands of cloud addresses due to reused server templates, and a single open port might be common. The platform emphasizes the need for careful cross-referencing and corroboration of findings.

Examples of its utility include identifying a NOX Stealer login panel by combining traits like Windows Server 2022, nginx, and PHP versions, significantly narrowing down search results. Similarly, searching for FTP banners containing "conhost" helped uncover addresses linked to command-delivery patterns discussed in specific research papers.

This enhanced scanning capability is accessible through API records and history endpoints, though not yet integrated into IP Livehunt rules. Users can implement workarounds by setting up saved searches to run on a schedule. The move represents a significant step forward in providing proactive threat intelligence, enabling defenders to better identify and disrupt malicious infrastructure before it can be fully exploited.

Synthesized by Vypr AI