Reference

Livehunt vt module reference

This reference provides a detailed list of the various data types that can be matched against when using attributes within the vt module.

HTTP methods

vt.Http.Method.GET
vt.Http.Method.HEAD
vt.Http.Method.PATCH
vt.Http.Method.POST
vt.Http.Method.PUT
vt.Http.Method.DELETE
vt.Http.Method.TRACE
vt.Http.Method.OPTIONS
vt.Http.Method.CONNECT

Network protocols

vt.Net.Protocol.ICMP
vt.Net.Protocol.IGMP
vt.Net.Protocol.TCP
vt.Net.Protocol.UDP
vt.Net.Protocol.ESP
vt.Net.Protocol.AH
vt.Net.Protocol.L2TP
vt.Net.Protoco.SCTP

Behaviour traits

vt.BehaviourTrait.BIG_UPSTREAM
vt.BehaviourTrait.CHECKS_BIOS
vt.BehaviourTrait.CHECKS_CPU_NAME
vt.BehaviourTrait.CHECKS_DISK_SPACE
vt.BehaviourTrait.CHECKS_GPS
vt.BehaviourTrait.CHECKS_HOSTNAME
vt.BehaviourTrait.CHECKS_MEMORY_AVAILABLE
vt.BehaviourTrait.CHECKS_NETWORK_ADAPTERS
vt.BehaviourTrait.CHECKS_PCI_BUS
vt.BehaviourTrait.CHECKS_USB_BUS
vt.BehaviourTrait.CLIPBOARD
vt.BehaviourTrait.CRYPTO
vt.BehaviourTrait.DECRYPTS_EXE
vt.BehaviourTrait.DETECT_DEBUG_ENVIRONMENT
vt.BehaviourTrait.DIRECT_CPU_CLOCK_ACCESS
vt.BehaviourTrait.EXECUTES_DROPPED_FILE
vt.BehaviourTrait.FTP_COMMUNICATION
vt.BehaviourTrait.HOSTS_MODIFIER
vt.BehaviourTrait.INSTALLS_BROWSER_EXTENSION
vt.BehaviourTrait.IRC_COMMUNICATION
vt.BehaviourTrait.LONG_SLEEPS
vt.BehaviourTrait.MACRO_ANTI_ANALYSIS
vt.BehaviourTrait.MACRO_COPY_FILE
vt.BehaviourTrait.MACRO_CREATE_DIR
vt.BehaviourTrait.MACRO_CREATE_FILE
vt.BehaviourTrait.MACRO_CREATE_OLE
vt.BehaviourTrait.MACRO_DOWNLOAD_URL
vt.BehaviourTrait.MACRO_ENUM_WINDOWS
vt.BehaviourTrait.MACRO_ENVIRON
vt.BehaviourTrait.MACRO_HANDLE_FILE
vt.BehaviourTrait.MACRO_HIDE_APP
vt.BehaviourTrait.MACRO_OPEN_FILE
vt.BehaviourTrait.MACRO_POWERSHELL
vt.BehaviourTrait.MACRO_REGISTRY
vt.BehaviourTrait.MACRO_RUN_DLL
vt.BehaviourTrait.MACRO_RUN_FILE
vt.BehaviourTrait.MACRO_SAVE_WORKBOOK
vt.BehaviourTrait.MACRO_SEND_KEYS
vt.BehaviourTrait.MACRO_WRITE_FILE
vt.BehaviourTrait.MYSQL_COMMUNICATION
vt.BehaviourTrait.OBFUSCATED
vt.BehaviourTrait.PASSWORD_DIALOG
vt.BehaviourTrait.PERSISTENCE
vt.BehaviourTrait.REFLECTION
vt.BehaviourTrait.RUNTIME_MODULES
vt.BehaviourTrait.SELF_DELETE
vt.BehaviourTrait.SENDS_SMS
vt.BehaviourTrait.SMTP_COMMUNICATION
vt.BehaviourTrait.SSH_COMMUNICATION
vt.BehaviourTrait.SUDO
vt.BehaviourTrait.SUSPICIOUS_DNS
vt.BehaviourTrait.SUSPICIOUS_UDP
vt.BehaviourTrait.TELEPHONY
vt.BehaviourTrait.TELNET_COMMUNICATION
vt.BehaviourTrait.TUNNELING

Behaviour verdicts

vt.BehaviourVerdict.ADWARE
vt.BehaviourVerdict.BANKER
vt.BehaviourVerdict.CLEAN
vt.BehaviourVerdict.EVADER
vt.BehaviourVerdict.EXPLOIT
vt.BehaviourVerdict.GREYWARE
vt.BehaviourVerdict.MALWARE
vt.BehaviourVerdict.PHISHING
vt.BehaviourVerdict.RANSOM
vt.BehaviourVerdict.RAT
vt.BehaviourVerdict.SPREADER
vt.BehaviourVerdict.TROJAN
vt.BehaviourVerdict.UNKNOWN_VERDICT

Back to top

File types

TypeType tags
vt.FileType.ACEcompressed ace
vt.FileType.ANDROIDexecutable mobile android apk
vt.FileType.APPLEapple apple-gen
vt.FileType.APPLE_PLISTapple appleplist
vt.FileType.APPLEDOUBLEapple appledouble
vt.FileType.APPLESINGLEapple applesingle
vt.FileType.ARCcompressed arc
vt.FileType.ARJcompressed arj
vt.FileType.ASDcompressed asd
vt.FileType.ASFmultimedia video asf
vt.FileType.AVImultimedia video avi
vt.FileType.AWKsource awk
vt.FileType.BMPmultimedia image bmp
vt.FileType.BZIPcompressed bzip
vt.FileType.Csource c
vt.FileType.CABcompressed cab
vt.FileType.CAPinternet cap pcap
vt.FileType.CHMhelp chm
vt.FileType.COFFexecutable coff
vt.FileType.COOKIEinternet iecookie
vt.FileType.CPPsource cpp
vt.FileType.CRXcrx chrome extension browser
vt.FileType.DEBexecutable linux deb
vt.FileType.DIBmultimedia image dib
vt.FileType.DIVXmultimedia video divx
vt.FileType.DMGexecutable mac dmg
vt.FileType.DOCdocument msoffice text word doc
vt.FileType.DOCXdocument msoffice text word docx
vt.FileType.DOS_COMexecutable dos com
vt.FileType.DOS_EXEexecutable dos mz
vt.FileType.DYALOGsource dyalog
vt.FileType.DZIPcompressed dzip
vt.FileType.EBOOKdocument ebook epub
vt.FileType.ELFexecutable linux elf
vt.FileType.EMAILinternet email
vt.FileType.EMFmultimedia image emf
vt.FileType.EOTfont opentype eof
vt.FileType.FLACmultimedia audio flac
vt.FileType.FLCmultimedia animation flc
vt.FileType.FLImultimedia animation fli
vt.FileType.FLVmultimedia video flv
vt.FileType.FORTRANsource fortran
vt.FileType.FPXmultimedia image fpx
vt.FileType.GIFmultimedia image gif
vt.FileType.GIMPmultimedia image gimp
vt.FileType.GULdocument samsungdoc text gul
vt.FileType.GZIPcompressed gzip
vt.FileType.HTMLinternet html
vt.FileType.HWPdocument hangul text hwp
vt.FileType.ICOmultimedia image ico
vt.FileType.IN_DESIGNmultimedia image indesign
vt.FileType.IPHONEexecutable mobile iphone ios
vt.FileType.ISOIMAGEcompressed isoimage
vt.FileType.JARcompressed jar
vt.FileType.JAVAsource java
vt.FileType.JAVA_BYTECODEexecutable java-bytecode class
vt.FileType.JAVASCRIPTsource javascript
vt.FileType.JNGmultimedia image jng
vt.FileType.JPEGmultimedia image jpeg jpg
vt.FileType.KGBcompressed kgb
vt.FileType.LATEXdocument latex
vt.FileType.LINUXlinux
vt.FileType.LINUX_KERNELlinux
vt.FileType.LNKwindows lnk
vt.FileType.MACH_Oexecutable mac macho
vt.FileType.MACINTOSHapple macintosh mac macintosh-gen
vt.FileType.MACINTOSH_HFSapple macintosh mac machfs
vt.FileType.MACINTOSH_LIBapple mac maclib
vt.FileType.MIDImultimedia audio midi
vt.FileType.MOVmultimedia video mov
vt.FileType.MP3multimedia audio mp3
vt.FileType.MP4multimedia audio mp4
vt.FileType.MPEGmultimedia video mpeg
vt.FileType.MSCOMPRESScompressed mscompress
vt.FileType.MSIinstaller windows msi
vt.FileType.NE_DLLexecutable windows win16 ne nedll
vt.FileType.NE_EXEexecutable windows win16 ne neexe
vt.FileType.ODFdocument openoffice math odf
vt.FileType.ODGdocument openoffice draw odg
vt.FileType.ODPdocument openoffice presentation odp
vt.FileType.ODSdocument openoffice spreadsheet ods
vt.FileType.ODTdocument openoffice text odt
vt.FileType.OGGmultimedia video ogg
vt.FileType.OUTLOOKinternet email outlook
vt.FileType.PALMOSexecutable mobile palmos
vt.FileType.PASCALsource pascal
vt.FileType.PDFdocument pdf
vt.FileType.PE_DLLexecutable windows win32 pe pedll
vt.FileType.PE_EXEexecutable windows win32 pe peexe
vt.FileType.PERLsource perl
vt.FileType.PHPsource php
vt.FileType.PKGexecutable mac pkg
vt.FileType.PNGmultimedia image png
vt.FileType.PPSXdocument msoffice presentation powerpoint slideshow ppsx
vt.FileType.PPTdocument msoffice presentation powerpoint ppt
vt.FileType.PPTXdocument msoffice presentation powerpoint pptx
vt.FileType.PSdocument ps postscript
vt.FileType.PSDmultimedia image photoshop psd
vt.FileType.PYTHONsource python
vt.FileType.QUICKTIMEmultimedia video quicktime qt
vt.FileType.RARcompressed rar
vt.FileType.RMmultimedia video realmedia rm
vt.FileType.ROMrom bios firmware
vt.FileType.RPMlinux rpm
vt.FileType.RTFdocument msoffice text word rtf
vt.FileType.RUBYsource ruby
vt.FileType.RZIPcompressed rzip
vt.FileType.SCRIPTscript
vt.FileType.SEVENZIPcompressed 7zip
vt.FileType.SHELLSCRIPTscript shell
vt.FileType.SVGmultimedia image svg
vt.FileType.SWFinternet flash swf
vt.FileType.SYMBIANexecutable mobile symbian
vt.FileType.T3GPmultimedia video 3gp
vt.FileType.TARcompressed tar
vt.FileType.TARGAmultimedia image targa
vt.FileType.TEXTtext
vt.FileType.TIFFmultimedia image tiff
vt.FileType.TORRENTlink internet bittorrent
vt.FileType.TTFfont truetype ttf
vt.FileType.WAVmultimedia audio wav
vt.FileType.WINCEexecutable mobile wince
vt.FileType.WMAmultimedia audio wma
vt.FileType.WMVmultimedia video wmv
vt.FileType.WOFFfont openfont woff
vt.FileType.XLSdocument msoffice spreadsheet excel xls
vt.FileType.XLSXdocument msoffice spreadsheet excel xlsx
vt.FileType.XMLinternet xml
vt.FileType.XPIbrowser extension firefox xpi
vt.FileType.XWDmultimedia image xwd
vt.FileType.ZIPcompressed zip
vt.FileType.ZLIBcompressed zlib

Back to top

Google TI assessment severity types

vt.GtiSeverity.SEVERITY_NONE
vt.GtiSeverity.SEVERITY_LOW
vt.GtiSeverity.SEVERITY_MEDIUM
vt.GtiSeverity.SEVERITY_HIGH

Back to top

Google TI assessment verdicts

vt.GtiVerdict.VERDICT_BENIGN
vt.GtiVerdict.VERDICT_UNDETECTED
vt.GtiVerdict.VERDICT_SUSPICIOUS
vt.GtiVerdict.VERDICT_MALICIOUS

Back to top