Today marks a leap forward in threat intelligence as VirusTotal rolls out daily scanning across the public IPv4 address space, aiming to uncover otherwise hidden command-and-control servers (C2) and malware infrastructure.
What’s New: Data Beyond Detection Scores
Effective October 8, 2026, the update broadens VirusTotal’s scope beyond just scoring IP addresses for maliciousness. It now continuously captures exposed services, port activity, banner information, server fingerprints, and more—all alongside its existing threat intelligence. Previously, users could view passive DNS records, hosting details, and files communicating with an address; now they also see what a server is currently exposing, even if no malware detections are associated. This fills a gap in identifying related hosts that fly under the radar.
Deeper Insights via Ports, Fingerprints, and History
A new Ports tab reveals open, closed, and recently closed ports, with data including service names, versions, timestamps, HTTP headers, SSH host keys, RDP fingerprints, and inferred operating system details. Historical port data is preserved for when services go offline—letting researchers pinpoint when a suspected C2 channel was last active and correlate that with other signs of attack campaigns.
Use Cases: Hunting for Hidden Malware Structures
The most notable addition is support for refined searches through VirusTotal’s web interface and API. Teams can use syntax such as entity:ip open_port:22 to filter for exposed SSH services, and port-specific conditions ensure that version labels or banners aren’t misattributed across ports. In one case, investigators followed an SSH fingerprint from a known APT28 collection address to another IP that had no detection history—yet shared critical features like SSH build, nginx setup, and an odd certificate name “b4ck.my.” That led to discovering a third address, where server retirement and activation roughly lined up with the others, suggesting a live infrastructure shift.
Another scenario uncovered a login panel for NOX Stealer on port 8443, also exposing SMB and RDP. Identifiable traits—Windows Server 2022, nginx 1.24.0, PHP 8.3.33—helped narrow millions of hosts down to just ten potential matches. Still, none were wholly confirmed malicious without further evidence.
Limits & Proper Use of the New Data
VirusTotal cautions that historical malware associations or ownership claims are tentative—IP addresses can change ownership, and fingerprints like SSH keys are often reused in cloud templates. An open port, by itself, is weak evidence. A scan for the default port used by Cobalt Strike’s team server returned over 1.5 million live IPs; many of them are likely benign or shared infrastructure, not uniquely malicious.
The new port-based data is accessible through VirusTotal’s API and history endpoints, though it’s not yet live in IP Livehunt rules. Analysts who need automated monitoring should consider scheduled saved searches. Account usage limits and API quota details are available in VirusTotal’s access documentation.
With these enhancements, security teams can now connect the dots between exposed services, fingerprints, and server configurations—revealing otherwise invisible parts of threat actor infrastructure.
What this means: VirusTotal’s evolution signals a shift in how threat intelligence is collected and acted on. By going past detection scores and passive data to live service exposure, analysts gain powerful tools—but must balance signal and noise carefully. Moving forward, watch how defenders integrate service-fingerprint-hunting into detection workflows, and how attackers adapt their infrastructure hygiene in response.