{"id":7221,"date":"2021-10-27T15:58:29","date_gmt":"2021-10-27T22:58:29","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=7221"},"modified":"2024-08-07T12:30:07","modified_gmt":"2024-08-07T19:30:07","slug":"new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/","title":{"rendered":"New Global Ransomware Report from VirusTotal &#038; Google (But Read the Fine Print!)"},"content":{"rendered":"<p>Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal.\u00a0 While there is some interesting information to be gained from this report, we should start with a warning:<\/p>\n<p>The \u201c<a href=\"https:\/\/storage.googleapis.com\/vtpublic\/vt-ransomware-report-2021.pdf\">Ransomware in a Global Context<\/a>\u201d report from VirusTotal is based on samples submitted to VirusTotal by analysts and other security professionals.\u00a0 But \u2018submissions\u2019 do not equate to detections, infections, investigations, or even breaches.\u00a0 In many ways, this is a \u2018usage\u2019 report of VirusTotal services and not a threat report.<\/p>\n<h3>Keep a few things in mind, and you\u2019ll do fine<\/h3>\n<p>With that said, this blog is not intended to disparage the report.\u00a0 In fact, many of the report\u2019s findings are truly interesting and may guide security teams in both general and specific areas.\u00a0 But in a world with so many threat reports it is easy to develop an automated response about how to interpret certain kinds of charts and tables.\u00a0 For example, look at this chart from the report labeled as \u201cGeographic distribution of ransomware-related submissions\u201d.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-7222\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/new-global-1.png\" alt=\"\" width=\"1212\" height=\"795\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/new-global-1.png 1212w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/new-global-1-300x197.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/new-global-1-1024x672.png 1024w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/new-global-1-768x504.png 768w\" sizes=\"auto, (max-width: 1212px) 100vw, 1212px\" \/><\/p>\n<p>A magazine article based on this chart claimed that \u201cIsrael has submitted the largest amount of ransomware samples since the start of 2020.\u201d\u00a0 But that is not what this chart is showing. This is about which countries have \u2018increased\u2019 their use of VirusTotal the most since 2020.\u00a0 It is measuring a delta, not total usage.\u00a0 So, if I was working for VirusTotal, this would tell me I could reduce my marketing budget in Israel because VirusTotal is already growing strong there. But it tells me little about ransomware activity or what I can do to improve my security.<\/p>\n<p>Readers note:\u00a0 This is the last chart I plan to include here.\u00a0 If I post all the pretty pictures here, you\u2019ll miss some of the context I\u2019m unable to include due to time, space, and typing endurance limitations. So <a href=\"https:\/\/storage.googleapis.com\/vtpublic\/vt-ransomware-report-2021.pdf\">read the full report<\/a>.<\/p>\n<h3>Death, Disaster, and Drama Rule!<\/h3>\n<p>It is apparent from figure 1 in the report that about half of all the ransomware submissions over this 21 month period took place in the first 6 months of 2020.\u00a0 This means recent data is diluted and the report has little to offer about how ransomware has changed recently.\u00a0 But the early 2020 spike aligned with the start of the global pandemic when cyber criminals were creating many COVID-19 themed attacks using both old and new techniques and methods.\u00a0 SecOps were erring on the side of caution due to work-from-home and other shifts in business processes, resulting in submissions of anything suspicious. So it would make sense that VirusTotal would see many more submissions than usual.<\/p>\n<p>And this underscores the role of \u201cdeath, disaster, and drama\u201d in driving threat actor activity.\u00a0 Global or regional events around these themes are big drivers for cybercriminals who have an attack ready to go and are just waiting for the right opportunity.\u00a0 They want a theme that will cause stress in victims where they are proven to be more susceptible to social engineering.\u00a0 For example, about <a href=\"https:\/\/grahamcluley.com\/spammed-out-japanese-tsunami-video-links-lead-to-malware-attack\/\">10 years ago a Tsunami hit Japan<\/a> with devastating consequences which cyber criminals used to attack both victims and those trying to help. This approach worked so well that, a few years ago, <a href=\"https:\/\/www.fortinet.com\/blog\/threat-research\/fake-tsunami-brings-malware-to-japan\">one cybercriminal group faked a tsunami<\/a> in an effort to target Japanese citizens.\u00a0 And there are plenty of other examples of attacks using the death of a celebrity, drama around anything raging in social media, and so on.<\/p>\n<p>Watch the news because it might just tip you off to a new wave of threats.<\/p>\n<h3>Exploits are not as common as you think<\/h3>\n<p>The VirusTotal report says only 5% of the submitted samples contained an exploit, or code designed to take advantage of an application or system vulnerability. While it is generally understood that social engineering remains the most successful tool for bypassing security, this 5% number appears deceivingly low.\u00a0 This is because the VirusTotal data includes a lot of known threats (see figure 5 in the report), and there is no sample breakdown into \u2018successful\u2019 and \u2018unsuccessful\u2019.\u00a0 So we must look at other threat reports where many security vendors conclude that \u2018exploits\u2019 are a common element of successful ransomware attacks.\u00a0 So, while 5% of overall samples may involve an exploit, it is more likely that more than 5% of \u2018successful\u2019 ransomware samples involved exploits.<\/p>\n<p>Regardless of how bad the problem may be, there are plenty of options to consider to address exploits.\u00a0 And, while security professionals know that you cannot simply match up a threat category with a security solution category, here are a few thoughts to keep in mind as you consider how your current defenses address this area of risk.\u00a0<\/p>\n<ul>\n<li>Both patching and vulnerability scanning should remain top priorities.\u00a0 And <a href=\"https:\/\/blogs.infoblox.com\/security\/ip-address-management-the-one-trick-that-ensures-accurate-vulnerability-assessments\/\">scheduling scans<\/a> as well as <a href=\"https:\/\/www.infoblox.com\/wp-content\/uploads\/infoblox-partner-solution-brief-automate-remediation-and-ease-compliance-with-infoblox-and-qualys.pdf?utm_source=blox-community&amp;utm_campaign=community-q2&amp;utm_medium=blox-community\">automating scans on incident detection<\/a>, just to ensure analysts have as much current data about an affected system as possible to speed triage and investigation.\u00a0\u00a0<\/li>\n<\/ul>\n<ul>\n<li>Social Engineering isn\u2019t all about phishing.\u00a0 While it is a general understanding that around 90% of all attacks involve email phishing, make sure users are aware of other ways it is used against them.\u00a0 Fake websites, links on waterhole sites, and malvertising continue as top risks.\u00a0 And <a href=\"https:\/\/blogs.infoblox.com\/security\/a-fresh-look-at-lookalike-domains\/\">Lookalike URL usage<\/a> in all of these attack vehicles is growing to counter users who are being better trained on how to check the true destination of links in email and in a browser.\u00a0\u00a0<\/li>\n<\/ul>\n<h3>Actors are not families<\/h3>\n<p>Due to the long period covered by the VirusTotal report, it is hard to make out some details from this data alone.\u00a0 However, combined with other data on specific threats, the VirusTotal report helps to shed additional perspective.\u00a0 We\u2019ll drill into the Gandcrab ransomware family which saw more sample submissions than any other.\u00a0<\/p>\n<p>Additional research into Gandcrab\u2019s history and the chain of attack behaviors reveals that it was first seen in 2018, and saw a great deal of success in the first half of 2019.\u00a0 But, in June of 2019, the threat actors behind Gandcrab announced that they would be shutting down their operations. So why would a piece of ransomware that essentially \u2018shut down\u2019 6 months before the beginning of this report period be of such interest to security analysts and researchers using VirusTotal?<\/p>\n<p>It is because the actors only shifted their focus to a sister family of threats that became known as Sodinokibi and, later that year, officially reemerged with a name you may be more familiar with, <a href=\"https:\/\/blogs.infoblox.com\/cyber-threat-intelligence\/cyber-threat-advisory\/kaseya-revil-ransomware-attack\/\">REvil, which achieved fame through their Kaseya attack<\/a>.\u00a0 All 3 families are listed independently in the report in figure 5 since VirusTotal broke the data down by malware family, which has nothing to do with the \u2018actors\u2019 behind them.\u00a0 Unfortunately, you wouldn\u2019t know this if you didn\u2019t do additional research.<\/p>\n<p>But looking at these three ransomware families on the figure 5 bar chart reflects how experienced security analysts and researchers do their homework. If a researcher recently had to deal with a REvil launched attack, or were simply concerned about the possibility, they also looked at both Sodinokibi and Gandcrab to understand as much about the actors as they can.\u00a0 And with so many samples available for Gandcrab and its variants, it makes sense that there would be many more \u2018submissions\u2019 for the Gandcrab family as part of this research.\u00a0 They do this because, in this case, past behavior is an indication of future performance.\u00a0\u00a0<\/p>\n<p>Also of note, just as they disappeared after achieving too much success with Gandcrab, they have pulled the <a href=\"https:\/\/techcrunch.com\/2021\/10\/18\/revil-ransomware-group-goes-dark-after-its-tor-sites-were-hijacked\/\">same disappearing trick this year with REvil as well, twice<\/a>!\u00a0 The <a href=\"https:\/\/www.reuters.com\/technology\/exclusive-governments-turn-tables-ransomware-gang-revil-by-pushing-it-offline-2021-10-21\/\">US government shut them down<\/a> the last time.\u00a0 And we saw the same thing with the <a href=\"https:\/\/blogs.infoblox.com\/security\/to-panic-or-not-to-panic-that-is-the-question\/\">DarkSide shutdown after their Colonial Pipeline breach<\/a>.\u00a0 Overall, threat actors are getting better at knowing when to run and hide.<\/p>\n<h3>A final lesson: Don\u2019t let the headlines distract you<\/h3>\n<p>There have been many ransomware threats that have made the headlines over the last two years.\u00a0 But the VirusTotal report shows that researchers submitted samples from 130 different ransomware families during the report period.\u00a0 That means there are a lot of existing threats beyond the handful that make the headlines.\u00a0 It is vital that leadership be aware of this disparity to give them pause the next time they read an article about some new threat and have an urge to have everyone focus on it.<\/p>\n<p>Knowing what to focus on in security isn\u2019t easy. Maintaining a comprehensive view of the threat landscape and your security options will require reading more than a report.\u00a0 Listen to <a href=\"https:\/\/www.infoblox.com\/resources\/?resource_types=podcast\">podcasts<\/a>, attend <a href=\"https:\/\/www.infoblox.com\/resources\/webinars\/hack-no-reducing-your-ransomware-risk-an-intelligent-approach\/\">events<\/a>, seek out analyst reports on <a href=\"https:\/\/info.infoblox.com\/resources-whitepapers-sans-making-revolutionary-gains-in-security-on-your-endpoints\">security strategies<\/a> and <a href=\"https:\/\/info.infoblox.com\/resources-whitepapers-gartner-how-can-organizations-use-dns-to-improve-their-security-posture.html\">technology<\/a>, threat intelligence, and short-term threat reports to give you a sense of what is happening now. Find a blend of sources that fit your need, subscribe, and stay on top of them to keep your skills and security profile as strong as possible.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal.\u00a0 While there is some interesting information to be gained from this report, we should [&hellip;]<\/p>\n","protected":false},"author":334,"featured_media":5624,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[2],"tags":[288,584,361],"class_list":{"0":"post-7221","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security","8":"tag-ransomware","9":"tag-virus-total","10":"tag-network-security","11":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>New Global Ransomware Report from VirusTotal &amp; Google (But Read the Fine Print!)<\/title>\n<meta name=\"description\" content=\"New Global Ransomware Report from VirusTotal &amp; Google (But Read the Fine Print!). Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal. While there is some interesting information to be gained from this report, we should start with a warning:The \u201cRansomware in a Global Context\u201d report from VirusTotal is based on samples submitted to VirusTotal by analysts and other security professionals. But \u2018submissions\u2019 do not equate to detections, infections, investigations, or even breaches. In many ways, this is a \u2018usage\u2019 report of VirusTotal services and not a threat report.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"New Global Ransomware Report from VirusTotal &amp; Google (But Read the Fine Print!)\" \/>\n<meta property=\"og:description\" content=\"New Global Ransomware Report from VirusTotal &amp; Google (But Read the Fine Print!). Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal. While there is some interesting information to be gained from this report, we should start with a warning:The \u201cRansomware in a Global Context\u201d report from VirusTotal is based on samples submitted to VirusTotal by analysts and other security professionals. But \u2018submissions\u2019 do not equate to detections, infections, investigations, or even breaches. In many ways, this is a \u2018usage\u2019 report of VirusTotal services and not a threat report.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-27T22:58:29+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-07T19:30:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\" \/>\n\t<meta property=\"og:image:width\" content=\"293\" \/>\n\t<meta property=\"og:image:height\" content=\"249\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Bob Hansmann\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Bob Hansmann\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/\"},\"author\":{\"name\":\"Bob Hansmann\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/28fb1d8fd532fc28e3af32405568afd8\"},\"headline\":\"New Global Ransomware Report from VirusTotal &#038; Google (But Read the Fine Print!)\",\"datePublished\":\"2021-10-27T22:58:29+00:00\",\"dateModified\":\"2024-08-07T19:30:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/\"},\"wordCount\":1495,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"keywords\":[\"Ransomware\",\"Virus Total\",\"Network Security\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/\",\"name\":\"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!)\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"datePublished\":\"2021-10-27T22:58:29+00:00\",\"dateModified\":\"2024-08-07T19:30:07+00:00\",\"description\":\"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!). Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal. While there is some interesting information to be gained from this report, we should start with a warning:The \u201cRansomware in a Global Context\u201d report from VirusTotal is based on samples submitted to VirusTotal by analysts and other security professionals. But \u2018submissions\u2019 do not equate to detections, infections, investigations, or even breaches. In many ways, this is a \u2018usage\u2019 report of VirusTotal services and not a threat report.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png\",\"width\":293,\"height\":249},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"New Global Ransomware Report from VirusTotal &#038; Google (But Read the Fine Print!)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/28fb1d8fd532fc28e3af32405568afd8\",\"name\":\"Bob Hansmann\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/infoblox-author-bob-hansmann-96x96.png\",\"url\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/infoblox-author-bob-hansmann-96x96.png\",\"contentUrl\":\"https:\\\/\\\/blogs.infoblox.com\\\/wp-content\\\/uploads\\\/infoblox-author-bob-hansmann-96x96.png\",\"caption\":\"Bob Hansmann\"},\"description\":\"Bob Hansmann has spent over three decades helping global enterprises and government agencies to uplift their threat prevention, detection, investigation, and response capabilities. Working in areas ranging from threat research and engineering to product management and marketing across his career, Mr. Hansmann has helped pioneer many of today\u2019s security industry standards. This breadth of experience has given him a unique perspective on finding the optimal balance between an organization\u2019s security needs with its success criteria.\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/bob-hansmann\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!)","description":"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!). Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal. While there is some interesting information to be gained from this report, we should start with a warning:The \u201cRansomware in a Global Context\u201d report from VirusTotal is based on samples submitted to VirusTotal by analysts and other security professionals. But \u2018submissions\u2019 do not equate to detections, infections, investigations, or even breaches. In many ways, this is a \u2018usage\u2019 report of VirusTotal services and not a threat report.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/","og_locale":"en_US","og_type":"article","og_title":"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!)","og_description":"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!). Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal. While there is some interesting information to be gained from this report, we should start with a warning:The \u201cRansomware in a Global Context\u201d report from VirusTotal is based on samples submitted to VirusTotal by analysts and other security professionals. But \u2018submissions\u2019 do not equate to detections, infections, investigations, or even breaches. In many ways, this is a \u2018usage\u2019 report of VirusTotal services and not a threat report.","og_url":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/","og_site_name":"Infoblox Blog","article_published_time":"2021-10-27T22:58:29+00:00","article_modified_time":"2024-08-07T19:30:07+00:00","og_image":[{"width":293,"height":249,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","type":"image\/png"}],"author":"Bob Hansmann","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Bob Hansmann","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/"},"author":{"name":"Bob Hansmann","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/28fb1d8fd532fc28e3af32405568afd8"},"headline":"New Global Ransomware Report from VirusTotal &#038; Google (But Read the Fine Print!)","datePublished":"2021-10-27T22:58:29+00:00","dateModified":"2024-08-07T19:30:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/"},"wordCount":1495,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","keywords":["Ransomware","Virus Total","Network Security"],"articleSection":["Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/","url":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/","name":"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!)","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","datePublished":"2021-10-27T22:58:29+00:00","dateModified":"2024-08-07T19:30:07+00:00","description":"New Global Ransomware Report from VirusTotal & Google (But Read the Fine Print!). Google recently asked one of its portfolio companies, VirusTotal, to sift through global ransomware data collected from the samples submitted to their portal over the last few years to uncover data points and trends that traditional threat reports simply don\u2019t reveal. While there is some interesting information to be gained from this report, we should start with a warning:The \u201cRansomware in a Global Context\u201d report from VirusTotal is based on samples submitted to VirusTotal by analysts and other security professionals. But \u2018submissions\u2019 do not equate to detections, infections, investigations, or even breaches. In many ways, this is a \u2018usage\u2019 report of VirusTotal services and not a threat report.","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/Sanction-Risks-for-Faclicitating-Ransomeware-Payments.png","width":293,"height":249},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/security\/new-global-ransomware-report-from-virustotal-google-but-read-the-fine-print\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.infoblox.com\/blog\/category\/security\/"},{"@type":"ListItem","position":3,"name":"New Global Ransomware Report from VirusTotal &#038; Google (But Read the Fine Print!)"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/28fb1d8fd532fc28e3af32405568afd8","name":"Bob Hansmann","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/infoblox-author-bob-hansmann-96x96.png","url":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/infoblox-author-bob-hansmann-96x96.png","contentUrl":"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/infoblox-author-bob-hansmann-96x96.png","caption":"Bob Hansmann"},"description":"Bob Hansmann has spent over three decades helping global enterprises and government agencies to uplift their threat prevention, detection, investigation, and response capabilities. Working in areas ranging from threat research and engineering to product management and marketing across his career, Mr. Hansmann has helped pioneer many of today\u2019s security industry standards. This breadth of experience has given him a unique perspective on finding the optimal balance between an organization\u2019s security needs with its success criteria.","url":"https:\/\/www.infoblox.com\/blog\/author\/bob-hansmann\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/7221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/334"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=7221"}],"version-history":[{"count":3,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/7221\/revisions"}],"predecessor-version":[{"id":10515,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/7221\/revisions\/10515"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/5624"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=7221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=7221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=7221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}