Get Help Now
    24/7 Support

    Find firmware malware with VirusTotal

    Now VirusTotal is able to characterize firmware images in detail. Such analysis can help a digital forensics investigator to understand if the acquired image contains malicious code.

    Here are the new tool’s main capabilities:

    • Apple Mac BIOS detection and reporting.
    • Strings-based brand heuristic detection, to identify target systems.
    • Extraction of certificates both from the firmware image and from executable files contained in it.
    • PCI class code enumeration, allowing device class identification.
    • ACPI tables tags extraction.
    • NVAR variable names enumeration.
    • Option ROM extraction, entry point decompilation and PCI feature listing.
    • Extraction of BIOS Portable Executables and identification of potential Windows Executables contained within the image.
    • SMBIOS characteristics reporting.

    Additional information tab has a new field – Source Details, where you’ll find attribution information for the uploaded file:

    Malware_forensics_firmware_weare4n6

    For more information about the tool check this link.



    DISCLAIMER: THIS POST IS FOR INFORMATIONAL PURPOSES ONLY AND IS NOT TO BE CONSIDERED LEGAL ADVICE ON ANY SUBJECT MATTER. DIGITAL FORENSICS CORP. IS NOT A LAWFIRM AND DOES NOT PROVIDE LEGAL ADVICE OR SERVICES. By viewing posts, the reader understands there is no attorney-client relationship, the post should not be used as a substitute for legal advice from a licensed professional attorney, and readers are urged to consult their own legal counsel on any specific legal questions concerning a specific situation.