VirusTotal adds daily scanning of the public IPv4 space: new Ports tab with services, banners, SSH/RDP fingerprints and port history to pivot on C2 infrastructure
VirusTotal announced on 8 October 2026 that it now scans the public IPv4 space daily and records open, closed and recently closed ports with service names, software versions, banners, HTTP headers, SSH host keys, RDP fingerprints, JARM and inferred operating system, alongside its existing IP intelligence. The data appears in a new Ports tab and can be searched in the web UI and API with modifiers such as open_port, port_service_product[80] and fingerprint, combined with asn, country, ssl_subject, threat_actor and collection. VirusTotal's worked example started from an IP in its APT28 and Havoc C2 collections and used a shared SSH host key and an unusual certificate name to find two related hosts with no detections at all. VirusTotal warns that an open port on its own is a weak signal (a Cobalt Strike default-port search returned more than 1.5 million IPs), that reused cloud images share SSH keys across many unrelated hosts, and that old malware links do not prove current ownership or attribution. Primary: VirusTotal blog; wire: Cyber Security News.
- Product
- VirusTotal (Google) IP intelligence — Ports tab and port search modifiers
- Versions
- n/a — service feature
- Exploited in Australia?
- unknown
- Patch to
- Threat-intel teams: pivot on fingerprints, banners and certificates rather than open ports alone, and confirm current ownership before blocking or attributing. Check what your own internet-facing hosts now expose in VT's port data.
Primary: VirusTotal blog — Internet scanning in VT (Oct 2026) · Cyber Security News — VirusTotal adds scanning for public IPv4 space (9 Oct 2026)
