VirusTotal Scans Public IPv4 Space for C2 Servers and Malware Infrastructure
Key Takeaways VirusTotal has launched daily scans of the entire public IPv4 space. This new capability enables security teams to identify command-and-control (C2) servers and map out malware...
Key Takeaways
- VirusTotal has launched daily scans of the entire public IPv4 space.
- This new capability enables security teams to identify command-and-control (C2) servers and map out malware infrastructure more effectively.
- The scans capture exposed services, port activity, banners, and server fingerprints, supplementing existing threat intelligence data.
- Analysts can now pivot from known indicators to uncover previously undetected, related hosts by correlating server configurations and historical data.
VirusTotal Enhances Threat Intelligence with Daily IPv4 Scanning
VirusTotal has significantly expanded its threat intelligence capabilities by implementing daily scans of the entire public IPv4 address space. This new feature provides cybersecurity professionals with an unprecedented tool to discover command-and-control (C2) servers and meticulously track the infrastructure supporting malware operations.
Table Of Content
The update, officially announced on October 8, 2026, integrates critical network reconnaissance data—including exposed services, port statuses, server banners, and unique fingerprints—directly into VirusTotal’s extensive database. This rich dataset complements existing threat intelligence, offering a more holistic view of potential threats.
This enhancement empowers security researchers to move beyond simple detection scores associated with an IP address. Previously, investigations relied on hosting details, passive DNS records, and file interactions. Now, analysts gain real-time insight into what a server is currently exposing, facilitating the identification of interconnected hosts that might not yet have any direct malware detections.
Deep Dive into New Data Points
A dedicated “Ports” tab has been introduced, meticulously listing open, closed, and recently closed ports. This section details service names, software versions, and corresponding timestamps. Additional records include SSH host keys, RDP fingerprints, HTTP headers, and operating system information inferred from service responses, providing granular detail for each scanned IP.
VirusTotal maintains historical records even when ports become unresponsive. This allows researchers to ascertain the last known online status of a suspected C2 service, enabling them to correlate this information with other changes observed in an ongoing campaign. Such historical context is invaluable and goes beyond what a current detection score alone can offer.
Leveraging New Scanning Capabilities
The official announcement outlines how these new capabilities can be accessed via both the web interface and API. For instance, queries like entity:ip open_port:22 can be used to locate exposed SSH services across the internet.
Advanced bracket syntax allows for precise condition matching to specific ports, preventing incorrect associations between a product on one port and a version on another. These sophisticated search methods build upon established threat research techniques.
One notable investigation began with the IP address 91.219.237[.]110, which was previously linked to APT28 and Havoc threat actor collections. Its unique SSH fingerprint led researchers to 185.146.232[.]3, an address that had no prior detections, collections, or associated communicating files. Both hosts shared a common OpenSSH build, identical nginx configurations, and an unusual certificate name: b4ck.my.
Further investigation, by searching for the distinctive certificate name, uncovered a third related address: 96.9.125[.]59. Analysis of port timestamps suggested a pattern where one server was potentially being retired as another came online, indicating dynamic infrastructure changes.
However, VirusTotal has issued a crucial caveat: older malware links do not definitively establish current ownership or APT28 attribution, as IP addresses can be reassigned over time.
Similarly, fingerprint matches require careful scrutiny. Some SSH keys have been observed across more than 1,400 cloud addresses, often due to the reuse of server templates. An open port, by itself, is also weak evidence; a search for Cobalt Strike’s default team server port yielded over 1.5 million addresses, including many hosts responding on numerous other ports, highlighting the need for deeper analysis.
Another compelling example involved the discovery of a NOX Stealer login panel at 5.175.221[.]206 on port 8443. The same host also exposed SMB and RDP services, with scan data pinpointing Windows Server 2022, nginx 1.24.0, and PHP 8.3.33. Combining these specific traits significantly narrowed a search from 4.5 million hosts down to ten potential candidates, though these were not confirmed malicious servers without further investigation.
When the panel later rebranded to BOMBAY Stealer, browser analysis captured the new title, while the underlying exposed services remained constant. Researchers also successfully identified five addresses linked to command-delivery patterns, as detailed in E4del and PINHOLE research, by searching for FTP banners containing “conhost.”
The comprehensive port data is accessible through API records and history endpoints, though direct integration with IP Livehunt rules is not yet available. A workaround involves scheduling saved searches. Teams looking to automate these processes should consult the VirusTotal access overview and API documentation, also ensuring they are aware of their account limits.
What You Should Do
- Integrate VirusTotal’s New Capabilities: Leverage the daily IPv4 scans to augment your existing threat hunting and intelligence gathering processes.
- Utilize Advanced Search Queries: Experiment with the new query syntax (e.g.,
entity:ip open_port:XXand bracket conditions) to find specific exposed services and configurations relevant to known threats. - Correlate Data Points: Do not rely solely on single indicators. Combine port data, service versions, banners, fingerprints, and historical records to build a more accurate picture of suspicious infrastructure.
- Verify Attributions: Exercise caution when attributing ownership or threat actor links based on historical IP data, as IP addresses can change hands.
- Automate Where Possible: For large-scale operations, explore API access for port data and consider scheduled saved searches as a workaround for current Livehunt limitations.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.