<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:media="http://search.yahoo.com/mrss/"><channel><title><![CDATA[Trustlook blog]]></title><description><![CDATA[Be Security Smart by Trustlook SECaaS]]></description><link>https://blog.trustlook.com/</link><image><url>https://blog.trustlook.com/favicon.png</url><title>Trustlook blog</title><link>https://blog.trustlook.com/</link></image><generator>Ghost 2.23</generator><lastBuildDate>Thu, 09 Apr 2026 08:53:45 GMT</lastBuildDate><atom:link href="https://blog.trustlook.com/rss/" rel="self" type="application/rss+xml"/><ttl>60</ttl><item><title><![CDATA[Trustlook's  Integration with OKC (OKX Chain)]]></title><description><![CDATA[<p>San Jose, California, Oct. 19, 2022, Trustlook, the global leader of  AI-powered cybersecurity, today announced an integration with OKC (OKX Chain) an EVM-compatible L1 built on Cosmos with a focus on true interoperability (IBC) and maximized performance. Trustlook will provide their extensive portfolio of blockchain security products to OKC, which</p>]]></description><link>https://blog.trustlook.com/trustlook-integration-with-okc/</link><guid isPermaLink="false">635062706a27ce2bf459caa9</guid><category><![CDATA[News]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Wed, 19 Oct 2022 20:54:31 GMT</pubDate><content:encoded><![CDATA[<p>San Jose, California, Oct. 19, 2022, Trustlook, the global leader of  AI-powered cybersecurity, today announced an integration with OKC (OKX Chain) an EVM-compatible L1 built on Cosmos with a focus on true interoperability (IBC) and maximized performance. Trustlook will provide their extensive portfolio of blockchain security products to OKC, which will  allow them to create a safer web3 experience for their users.</p><p>OKC (OKX Chain) is an EVM-compatible L1 built on Cosmos with a focus on true interoperability (IBC) and maximized performance. At high scalability, developers can build and scale with low gas fees. The OKC ecosystem and infrastructure, including the all-in-one multi-chain Web3 interface, enables a seamless experience for both developers and users.</p><p>Find out more about us at<a href="https://okx.com/okc"> https://okx.com/okc</a>.</p><!--kg-card-begin: image--><figure class="kg-card kg-image-card"><img src="https://blog.trustlook.com/content/images/2022/10/OKX-OKC-Black-square.png" class="kg-image"></figure><!--kg-card-end: image-->]]></content:encoded></item><item><title><![CDATA[VirusTotal APK 病毒检测统计 20220101-20220831]]></title><description><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20220101_20220831.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20220101_20220831.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li></ul>]]></description><link>https://blog.trustlook.com/virustotal-apk-bing-du-jian-ce-tong-ji-202201-202208/</link><guid isPermaLink="false">632269d56a27ce2bf459ca93</guid><category><![CDATA[杀毒引擎评测]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Wed, 14 Sep 2022 23:56:08 GMT</pubDate><content:encoded><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20220101_20220831.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20220101_20220831.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li>
<li><strong>TPR</strong>: True Positive Rate, 恶意样本检出率</li>
<li><strong>FPR</strong>: False Positive Rate, 良性样本误报率</li>
<li><strong>TP</strong>: True Positive, 正确检出为恶意样本的数量</li>
<li><strong>FP</strong>: False Positive, 误报为恶意样本的数量</li>
<li><strong>TN</strong>: True Negative, 正确检出为良性样本的数量</li>
<li><strong>FN</strong>: False Negative, 误报为良性样本的数量</li>
</ul>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>K7GW</td>
<td>99.61%</td>
<td>0.19%</td>
<td>347789</td>
<td>4780</td>
<td>2506813</td>
<td>1374</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.47%</td>
<td>0.09%</td>
<td>347327</td>
<td>2283</td>
<td>2509310</td>
<td>1836</td>
</tr>
<tr>
<td>Fortinet</td>
<td>98.76%</td>
<td>0.13%</td>
<td>344834</td>
<td>3335</td>
<td>2508258</td>
<td>4329</td>
</tr>
<tr>
<td>Trustlook</td>
<td>98.49%</td>
<td>0.02%</td>
<td>343874</td>
<td>400</td>
<td>2511193</td>
<td>5289</td>
</tr>
<tr>
<td>Avira</td>
<td>98.46%</td>
<td>0.00%</td>
<td>343773</td>
<td>118</td>
<td>2511475</td>
<td>5390</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>96.45%</td>
<td>0.01%</td>
<td>336760</td>
<td>281</td>
<td>2511312</td>
<td>12403</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>95.67%</td>
<td>0.02%</td>
<td>334061</td>
<td>441</td>
<td>2511152</td>
<td>15102</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>90.59%</td>
<td>0.89%</td>
<td>316324</td>
<td>22373</td>
<td>2489220</td>
<td>32839</td>
</tr>
<tr>
<td>Ikarus</td>
<td>90.39%</td>
<td>0.14%</td>
<td>315599</td>
<td>3455</td>
<td>2508138</td>
<td>33564</td>
</tr>
<tr>
<td>Microsoft</td>
<td>89.95%</td>
<td>0.02%</td>
<td>314082</td>
<td>478</td>
<td>2511115</td>
<td>35081</td>
</tr>
<tr>
<td>McAfee</td>
<td>89.17%</td>
<td>0.03%</td>
<td>311346</td>
<td>701</td>
<td>2510892</td>
<td>37817</td>
</tr>
<tr>
<td>Sophos</td>
<td>87.92%</td>
<td>0.01%</td>
<td>306982</td>
<td>268</td>
<td>2511325</td>
<td>42181</td>
</tr>
<tr>
<td>DrWeb</td>
<td>86.38%</td>
<td>0.09%</td>
<td>301601</td>
<td>2277</td>
<td>2509316</td>
<td>47562</td>
</tr>
<tr>
<td>Tencent</td>
<td>86.17%</td>
<td>0.12%</td>
<td>300868</td>
<td>2960</td>
<td>2508633</td>
<td>48295</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>84.37%</td>
<td>0.07%</td>
<td>294604</td>
<td>1703</td>
<td>2509890</td>
<td>54559</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>83.07%</td>
<td>0.02%</td>
<td>290046</td>
<td>533</td>
<td>2511060</td>
<td>59117</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>80.29%</td>
<td>2.08%</td>
<td>280327</td>
<td>52256</td>
<td>2459337</td>
<td>68836</td>
</tr>
<tr>
<td>Alibaba</td>
<td>74.36%</td>
<td>0.01%</td>
<td>259624</td>
<td>281</td>
<td>2511312</td>
<td>89539</td>
</tr>
<tr>
<td>Symantec</td>
<td>66.21%</td>
<td>0.01%</td>
<td>231184</td>
<td>163</td>
<td>2511430</td>
<td>117979</td>
</tr>
<tr>
<td>MAX</td>
<td>62.09%</td>
<td>0.00%</td>
<td>216791</td>
<td>36</td>
<td>2511557</td>
<td>132372</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>61.75%</td>
<td>0.03%</td>
<td>215604</td>
<td>824</td>
<td>2510769</td>
<td>133559</td>
</tr>
<tr>
<td>Cyren</td>
<td>58.51%</td>
<td>0.00%</td>
<td>204286</td>
<td>116</td>
<td>2511477</td>
<td>144877</td>
</tr>
<tr>
<td>AVG</td>
<td>54.84%</td>
<td>0.02%</td>
<td>191491</td>
<td>578</td>
<td>2511015</td>
<td>157672</td>
</tr>
<tr>
<td>Avast</td>
<td>54.80%</td>
<td>0.02%</td>
<td>191337</td>
<td>576</td>
<td>2511017</td>
<td>157826</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>54.61%</td>
<td>0.14%</td>
<td>190680</td>
<td>3617</td>
<td>2507976</td>
<td>158483</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>54.40%</td>
<td>0.01%</td>
<td>189946</td>
<td>353</td>
<td>2511240</td>
<td>159217</td>
</tr>
<tr>
<td>Comodo</td>
<td>24.09%</td>
<td>0.05%</td>
<td>84102</td>
<td>1316</td>
<td>2510277</td>
<td>265061</td>
</tr>
<tr>
<td>Zillya</td>
<td>22.71%</td>
<td>0.08%</td>
<td>79284</td>
<td>2106</td>
<td>2509487</td>
<td>269879</td>
</tr>
<tr>
<td>F-Secure</td>
<td>15.71%</td>
<td>0.00%</td>
<td>54868</td>
<td>30</td>
<td>2511563</td>
<td>294295</td>
</tr>
<tr>
<td>Rising</td>
<td>15.28%</td>
<td>0.02%</td>
<td>53335</td>
<td>441</td>
<td>2511152</td>
<td>295828</td>
</tr>
<tr>
<td>GData</td>
<td>14.34%</td>
<td>0.00%</td>
<td>50078</td>
<td>23</td>
<td>2511570</td>
<td>299085</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>12.91%</td>
<td>0.36%</td>
<td>45086</td>
<td>8967</td>
<td>2502626</td>
<td>304077</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>12.83%</td>
<td>0.03%</td>
<td>44807</td>
<td>665</td>
<td>2510928</td>
<td>304356</td>
</tr>
<tr>
<td>BitDefender</td>
<td>10.99%</td>
<td>0.00%</td>
<td>38388</td>
<td>15</td>
<td>2511578</td>
<td>310775</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>10.69%</td>
<td>0.00%</td>
<td>37333</td>
<td>14</td>
<td>2511579</td>
<td>311830</td>
</tr>
<tr>
<td>ClamAV</td>
<td>10.07%</td>
<td>0.23%</td>
<td>35167</td>
<td>5817</td>
<td>2505776</td>
<td>313996</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>8.06%</td>
<td>0.02%</td>
<td>28147</td>
<td>442</td>
<td>2511151</td>
<td>321016</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>7.03%</td>
<td>0.01%</td>
<td>24543</td>
<td>214</td>
<td>2511379</td>
<td>324620</td>
</tr>
<tr>
<td>Arcabit</td>
<td>6.40%</td>
<td>0.00%</td>
<td>22340</td>
<td>42</td>
<td>2511551</td>
<td>326823</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>5.70%</td>
<td>0.00%</td>
<td>19897</td>
<td>12</td>
<td>2511581</td>
<td>329266</td>
</tr>
<tr>
<td>Yandex</td>
<td>5.67%</td>
<td>0.00%</td>
<td>19811</td>
<td>56</td>
<td>2511537</td>
<td>329352</td>
</tr>
<tr>
<td>VIPRE</td>
<td>4.74%</td>
<td>0.00%</td>
<td>16557</td>
<td>12</td>
<td>2511581</td>
<td>332606</td>
</tr>
<tr>
<td>VBA32</td>
<td>1.46%</td>
<td>0.02%</td>
<td>5099</td>
<td>466</td>
<td>2511127</td>
<td>344064</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>1.23%</td>
<td>0.00%</td>
<td>4308</td>
<td>9</td>
<td>2511584</td>
<td>344855</td>
</tr>
<tr>
<td>Panda</td>
<td>1.03%</td>
<td>0.00%</td>
<td>3592</td>
<td>25</td>
<td>2511568</td>
<td>345571</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.49%</td>
<td>0.00%</td>
<td>1708</td>
<td>56</td>
<td>2511537</td>
<td>347455</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.21%</td>
<td>0.01%</td>
<td>734</td>
<td>249</td>
<td>2511344</td>
<td>348429</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.14%</td>
<td>0.00%</td>
<td>500</td>
<td>5</td>
<td>2511588</td>
<td>348663</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.07%</td>
<td>0.00%</td>
<td>244</td>
<td>5</td>
<td>2511588</td>
<td>348919</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.05%</td>
<td>0.00%</td>
<td>188</td>
<td>13</td>
<td>2511580</td>
<td>348975</td>
</tr>
<tr>
<td>Zoner</td>
<td>0.05%</td>
<td>0.00%</td>
<td>171</td>
<td>32</td>
<td>2511561</td>
<td>348992</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.03%</td>
<td>0.00%</td>
<td>117</td>
<td>0</td>
<td>2511593</td>
<td>349046</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>10</td>
<td>0</td>
<td>2511593</td>
<td>349153</td>
</tr>
<tr>
<td>CMC</td>
<td>0.00%</td>
<td>0.00%</td>
<td>7</td>
<td>0</td>
<td>2511593</td>
<td>349156</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.03%</td>
<td>1</td>
<td>809</td>
<td>2510784</td>
<td>349162</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>2511593</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>349163</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>2860756</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>如有任何疑问, 欢迎随时邮件联系 lxu@trustlook.com. 谢谢.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK Malware Detection Data 20220101-20220831]]></title><description><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-malware-detection-data-202201-202208/</link><guid isPermaLink="false">6322693f6a27ce2bf459ca82</guid><category><![CDATA[VirusTotal]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Wed, 14 Sep 2022 23:54:30 GMT</pubDate><content:encoded><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of live feed samples. Then we look at detection results from AV vendors and rate them by how many malware they have detected and how many benign samples they have misclassified. </p><p>We generate a CSV file recording the detection results everyday. In the CSV file, from left to right, the columns are MD5 hash of the APK, label where 1 means positive (malicious) and 0 means negative (benign), and one column for each vendor showing its detection results where 1 means positive and 0 means negative. </p><p>We publish the detection results and zip the CSV files to AWS S3. For this test, you can download the detection data from:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20220101_20220831.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20220101_20220831.zip</a></p><p>The monthly results are summarized in the table below and here is a simple explanation of the columns in the table:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: AV engine vendor</li>
<li><strong>TPR</strong>: True Positive Rate, percentage of positive (malware) samples being correctly classified as positive</li>
<li><strong>FPR</strong>: False Positive Rate, percentage of negative (goodware) samples being misclassified as positive</li>
<li><strong>TP</strong>: True Positive, number of positive (malware) samples being correctly classified as positive</li>
<li><strong>FP</strong>: False Positive, number of negative (goodware) samples being misclassified as positive</li>
<li><strong>TN</strong>: True Negative, number of negative (goodware) samples being correctly classified as negative</li>
<li><strong>FN</strong>: False Negative, number of positive (malware) samples being misclassified as negative</li>
</ul>
<!--kg-card-end: markdown--><p></p><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>K7GW</td>
<td>99.61%</td>
<td>0.19%</td>
<td>347789</td>
<td>4780</td>
<td>2506813</td>
<td>1374</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.47%</td>
<td>0.09%</td>
<td>347327</td>
<td>2283</td>
<td>2509310</td>
<td>1836</td>
</tr>
<tr>
<td>Fortinet</td>
<td>98.76%</td>
<td>0.13%</td>
<td>344834</td>
<td>3335</td>
<td>2508258</td>
<td>4329</td>
</tr>
<tr>
<td>Trustlook</td>
<td>98.49%</td>
<td>0.02%</td>
<td>343874</td>
<td>400</td>
<td>2511193</td>
<td>5289</td>
</tr>
<tr>
<td>Avira</td>
<td>98.46%</td>
<td>0.00%</td>
<td>343773</td>
<td>118</td>
<td>2511475</td>
<td>5390</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>96.45%</td>
<td>0.01%</td>
<td>336760</td>
<td>281</td>
<td>2511312</td>
<td>12403</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>95.67%</td>
<td>0.02%</td>
<td>334061</td>
<td>441</td>
<td>2511152</td>
<td>15102</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>90.59%</td>
<td>0.89%</td>
<td>316324</td>
<td>22373</td>
<td>2489220</td>
<td>32839</td>
</tr>
<tr>
<td>Ikarus</td>
<td>90.39%</td>
<td>0.14%</td>
<td>315599</td>
<td>3455</td>
<td>2508138</td>
<td>33564</td>
</tr>
<tr>
<td>Microsoft</td>
<td>89.95%</td>
<td>0.02%</td>
<td>314082</td>
<td>478</td>
<td>2511115</td>
<td>35081</td>
</tr>
<tr>
<td>McAfee</td>
<td>89.17%</td>
<td>0.03%</td>
<td>311346</td>
<td>701</td>
<td>2510892</td>
<td>37817</td>
</tr>
<tr>
<td>Sophos</td>
<td>87.92%</td>
<td>0.01%</td>
<td>306982</td>
<td>268</td>
<td>2511325</td>
<td>42181</td>
</tr>
<tr>
<td>DrWeb</td>
<td>86.38%</td>
<td>0.09%</td>
<td>301601</td>
<td>2277</td>
<td>2509316</td>
<td>47562</td>
</tr>
<tr>
<td>Tencent</td>
<td>86.17%</td>
<td>0.12%</td>
<td>300868</td>
<td>2960</td>
<td>2508633</td>
<td>48295</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>84.37%</td>
<td>0.07%</td>
<td>294604</td>
<td>1703</td>
<td>2509890</td>
<td>54559</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>83.07%</td>
<td>0.02%</td>
<td>290046</td>
<td>533</td>
<td>2511060</td>
<td>59117</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>80.29%</td>
<td>2.08%</td>
<td>280327</td>
<td>52256</td>
<td>2459337</td>
<td>68836</td>
</tr>
<tr>
<td>Alibaba</td>
<td>74.36%</td>
<td>0.01%</td>
<td>259624</td>
<td>281</td>
<td>2511312</td>
<td>89539</td>
</tr>
<tr>
<td>Symantec</td>
<td>66.21%</td>
<td>0.01%</td>
<td>231184</td>
<td>163</td>
<td>2511430</td>
<td>117979</td>
</tr>
<tr>
<td>MAX</td>
<td>62.09%</td>
<td>0.00%</td>
<td>216791</td>
<td>36</td>
<td>2511557</td>
<td>132372</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>61.75%</td>
<td>0.03%</td>
<td>215604</td>
<td>824</td>
<td>2510769</td>
<td>133559</td>
</tr>
<tr>
<td>Cyren</td>
<td>58.51%</td>
<td>0.00%</td>
<td>204286</td>
<td>116</td>
<td>2511477</td>
<td>144877</td>
</tr>
<tr>
<td>AVG</td>
<td>54.84%</td>
<td>0.02%</td>
<td>191491</td>
<td>578</td>
<td>2511015</td>
<td>157672</td>
</tr>
<tr>
<td>Avast</td>
<td>54.80%</td>
<td>0.02%</td>
<td>191337</td>
<td>576</td>
<td>2511017</td>
<td>157826</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>54.61%</td>
<td>0.14%</td>
<td>190680</td>
<td>3617</td>
<td>2507976</td>
<td>158483</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>54.40%</td>
<td>0.01%</td>
<td>189946</td>
<td>353</td>
<td>2511240</td>
<td>159217</td>
</tr>
<tr>
<td>Comodo</td>
<td>24.09%</td>
<td>0.05%</td>
<td>84102</td>
<td>1316</td>
<td>2510277</td>
<td>265061</td>
</tr>
<tr>
<td>Zillya</td>
<td>22.71%</td>
<td>0.08%</td>
<td>79284</td>
<td>2106</td>
<td>2509487</td>
<td>269879</td>
</tr>
<tr>
<td>F-Secure</td>
<td>15.71%</td>
<td>0.00%</td>
<td>54868</td>
<td>30</td>
<td>2511563</td>
<td>294295</td>
</tr>
<tr>
<td>Rising</td>
<td>15.28%</td>
<td>0.02%</td>
<td>53335</td>
<td>441</td>
<td>2511152</td>
<td>295828</td>
</tr>
<tr>
<td>GData</td>
<td>14.34%</td>
<td>0.00%</td>
<td>50078</td>
<td>23</td>
<td>2511570</td>
<td>299085</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>12.91%</td>
<td>0.36%</td>
<td>45086</td>
<td>8967</td>
<td>2502626</td>
<td>304077</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>12.83%</td>
<td>0.03%</td>
<td>44807</td>
<td>665</td>
<td>2510928</td>
<td>304356</td>
</tr>
<tr>
<td>BitDefender</td>
<td>10.99%</td>
<td>0.00%</td>
<td>38388</td>
<td>15</td>
<td>2511578</td>
<td>310775</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>10.69%</td>
<td>0.00%</td>
<td>37333</td>
<td>14</td>
<td>2511579</td>
<td>311830</td>
</tr>
<tr>
<td>ClamAV</td>
<td>10.07%</td>
<td>0.23%</td>
<td>35167</td>
<td>5817</td>
<td>2505776</td>
<td>313996</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>8.06%</td>
<td>0.02%</td>
<td>28147</td>
<td>442</td>
<td>2511151</td>
<td>321016</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>7.03%</td>
<td>0.01%</td>
<td>24543</td>
<td>214</td>
<td>2511379</td>
<td>324620</td>
</tr>
<tr>
<td>Arcabit</td>
<td>6.40%</td>
<td>0.00%</td>
<td>22340</td>
<td>42</td>
<td>2511551</td>
<td>326823</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>5.70%</td>
<td>0.00%</td>
<td>19897</td>
<td>12</td>
<td>2511581</td>
<td>329266</td>
</tr>
<tr>
<td>Yandex</td>
<td>5.67%</td>
<td>0.00%</td>
<td>19811</td>
<td>56</td>
<td>2511537</td>
<td>329352</td>
</tr>
<tr>
<td>VIPRE</td>
<td>4.74%</td>
<td>0.00%</td>
<td>16557</td>
<td>12</td>
<td>2511581</td>
<td>332606</td>
</tr>
<tr>
<td>VBA32</td>
<td>1.46%</td>
<td>0.02%</td>
<td>5099</td>
<td>466</td>
<td>2511127</td>
<td>344064</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>1.23%</td>
<td>0.00%</td>
<td>4308</td>
<td>9</td>
<td>2511584</td>
<td>344855</td>
</tr>
<tr>
<td>Panda</td>
<td>1.03%</td>
<td>0.00%</td>
<td>3592</td>
<td>25</td>
<td>2511568</td>
<td>345571</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.49%</td>
<td>0.00%</td>
<td>1708</td>
<td>56</td>
<td>2511537</td>
<td>347455</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.21%</td>
<td>0.01%</td>
<td>734</td>
<td>249</td>
<td>2511344</td>
<td>348429</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.14%</td>
<td>0.00%</td>
<td>500</td>
<td>5</td>
<td>2511588</td>
<td>348663</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.07%</td>
<td>0.00%</td>
<td>244</td>
<td>5</td>
<td>2511588</td>
<td>348919</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.05%</td>
<td>0.00%</td>
<td>188</td>
<td>13</td>
<td>2511580</td>
<td>348975</td>
</tr>
<tr>
<td>Zoner</td>
<td>0.05%</td>
<td>0.00%</td>
<td>171</td>
<td>32</td>
<td>2511561</td>
<td>348992</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.03%</td>
<td>0.00%</td>
<td>117</td>
<td>0</td>
<td>2511593</td>
<td>349046</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>10</td>
<td>0</td>
<td>2511593</td>
<td>349153</td>
</tr>
<tr>
<td>CMC</td>
<td>0.00%</td>
<td>0.00%</td>
<td>7</td>
<td>0</td>
<td>2511593</td>
<td>349156</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.03%</td>
<td>1</td>
<td>809</td>
<td>2510784</td>
<td>349162</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>2511593</td>
<td>349163</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>2511593</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>349163</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>2860756</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p></p><p>Please send an email to lxu@trustlook.com if you have any comments. Thanks.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK Malware Detection Data 2021-11]]></title><description><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-malware-detection-data-2021-11/</link><guid isPermaLink="false">61a9ac4641be69042719461e</guid><category><![CDATA[VirusTotal]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Fri, 03 Dec 2021 05:34:22 GMT</pubDate><content:encoded><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of live feed samples. Then we look at detection results from AV vendors and rate them by how many malware they have detected and how many benign samples they have misclassified. </p><p>We generate a CSV file recording the detection results everyday. In the CSV file, from left to right, the columns are MD5 hash of the APK, label where 1 means positive (malicious) and 0 means negative (benign), and one column for each vendor showing its detection results where 1 means positive and 0 means negative. </p><p>On a monthly basis, we publish the detection results and zip the CSV files to AWS S3. For this month, you can download the detection data from:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211101_20211130.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211101_20211130.zip</a></p><p>The monthly results are summarized in the table below and here is a simple explanation of the columns in the table:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: AV engine vendor</li>
<li><strong>TPR</strong>: True Positive Rate, percentage of positive (malware) samples being correctly classified as positive</li>
<li><strong>FPR</strong>: False Positive Rate, percentage of negative (goodware) samples being misclassified as positive</li>
<li><strong>TP</strong>: True Positive, number of positive (malware) samples being correctly classified as positive</li>
<li><strong>FP</strong>: False Positive, number of negative (goodware) samples being misclassified as positive</li>
<li><strong>TN</strong>: True Negative, number of negative (goodware) samples being correctly classified as negative</li>
<li><strong>FN</strong>: False Negative, number of positive (malware) samples being misclassified as negative</li>
</ul>
<!--kg-card-end: markdown--><p></p><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>Fortinet</td>
<td>99.73%</td>
<td>0.05%</td>
<td>17964</td>
<td>154</td>
<td>317562</td>
<td>48</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.66%</td>
<td>0.02%</td>
<td>17951</td>
<td>53</td>
<td>317663</td>
<td>61</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.01%</td>
<td>0.05%</td>
<td>17834</td>
<td>171</td>
<td>317545</td>
<td>178</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>98.92%</td>
<td>0.38%</td>
<td>17818</td>
<td>1207</td>
<td>316509</td>
<td>194</td>
</tr>
<tr>
<td>Avira</td>
<td>98.63%</td>
<td>0.00%</td>
<td>17766</td>
<td>9</td>
<td>317707</td>
<td>246</td>
</tr>
<tr>
<td>DrWeb</td>
<td>97.72%</td>
<td>0.05%</td>
<td>17602</td>
<td>165</td>
<td>317551</td>
<td>410</td>
</tr>
<tr>
<td>Ikarus</td>
<td>95.35%</td>
<td>0.03%</td>
<td>17175</td>
<td>83</td>
<td>317633</td>
<td>837</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>94.96%</td>
<td>0.01%</td>
<td>17104</td>
<td>38</td>
<td>317678</td>
<td>908</td>
</tr>
<tr>
<td>McAfee</td>
<td>93.86%</td>
<td>0.01%</td>
<td>16906</td>
<td>18</td>
<td>317698</td>
<td>1106</td>
</tr>
<tr>
<td>Trustlook</td>
<td>93.69%</td>
<td>0.02%</td>
<td>16876</td>
<td>66</td>
<td>317650</td>
<td>1136</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>93.65%</td>
<td>0.01%</td>
<td>16868</td>
<td>22</td>
<td>317694</td>
<td>1144</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>92.99%</td>
<td>0.01%</td>
<td>16749</td>
<td>17</td>
<td>317699</td>
<td>1263</td>
</tr>
<tr>
<td>Microsoft</td>
<td>91.13%</td>
<td>0.02%</td>
<td>16414</td>
<td>61</td>
<td>317655</td>
<td>1598</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>86.62%</td>
<td>0.01%</td>
<td>15602</td>
<td>39</td>
<td>317677</td>
<td>2410</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>80.61%</td>
<td>1.55%</td>
<td>14519</td>
<td>4938</td>
<td>312778</td>
<td>3493</td>
</tr>
<tr>
<td>Tencent</td>
<td>78.95%</td>
<td>0.08%</td>
<td>14220</td>
<td>245</td>
<td>317471</td>
<td>3792</td>
</tr>
<tr>
<td>Sophos</td>
<td>78.53%</td>
<td>0.01%</td>
<td>14145</td>
<td>26</td>
<td>317690</td>
<td>3867</td>
</tr>
<tr>
<td>Symantec</td>
<td>75.87%</td>
<td>0.01%</td>
<td>13665</td>
<td>18</td>
<td>317698</td>
<td>4347</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>64.73%</td>
<td>0.01%</td>
<td>11660</td>
<td>46</td>
<td>317670</td>
<td>6352</td>
</tr>
<tr>
<td>Alibaba</td>
<td>64.50%</td>
<td>0.00%</td>
<td>11617</td>
<td>7</td>
<td>317709</td>
<td>6395</td>
</tr>
<tr>
<td>Cyren</td>
<td>61.87%</td>
<td>0.01%</td>
<td>11144</td>
<td>23</td>
<td>317693</td>
<td>6868</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>59.12%</td>
<td>0.08%</td>
<td>10649</td>
<td>245</td>
<td>317471</td>
<td>7363</td>
</tr>
<tr>
<td>AVG</td>
<td>52.25%</td>
<td>0.02%</td>
<td>9412</td>
<td>53</td>
<td>317663</td>
<td>8600</td>
</tr>
<tr>
<td>Avast</td>
<td>52.17%</td>
<td>0.02%</td>
<td>9396</td>
<td>53</td>
<td>317663</td>
<td>8616</td>
</tr>
<tr>
<td>MAX</td>
<td>48.91%</td>
<td>0.00%</td>
<td>8809</td>
<td>1</td>
<td>317715</td>
<td>9203</td>
</tr>
<tr>
<td>Comodo</td>
<td>33.40%</td>
<td>0.05%</td>
<td>6016</td>
<td>164</td>
<td>317552</td>
<td>11996</td>
</tr>
<tr>
<td>Zillya</td>
<td>22.51%</td>
<td>0.05%</td>
<td>4054</td>
<td>169</td>
<td>317547</td>
<td>13958</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>14.43%</td>
<td>0.47%</td>
<td>2599</td>
<td>1502</td>
<td>316214</td>
<td>15413</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>14.35%</td>
<td>0.01%</td>
<td>2585</td>
<td>43</td>
<td>317673</td>
<td>15427</td>
</tr>
<tr>
<td>ClamAV</td>
<td>12.54%</td>
<td>0.09%</td>
<td>2258</td>
<td>273</td>
<td>317443</td>
<td>15754</td>
</tr>
<tr>
<td>GData</td>
<td>12.22%</td>
<td>0.00%</td>
<td>2201</td>
<td>0</td>
<td>317716</td>
<td>15811</td>
</tr>
<tr>
<td>BitDefender</td>
<td>11.11%</td>
<td>0.00%</td>
<td>2002</td>
<td>0</td>
<td>317716</td>
<td>16010</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>10.90%</td>
<td>0.00%</td>
<td>1963</td>
<td>0</td>
<td>317716</td>
<td>16049</td>
</tr>
<tr>
<td>Yandex</td>
<td>7.80%</td>
<td>0.01%</td>
<td>1405</td>
<td>17</td>
<td>317699</td>
<td>16607</td>
</tr>
<tr>
<td>F-Secure</td>
<td>7.60%</td>
<td>0.00%</td>
<td>1369</td>
<td>1</td>
<td>317715</td>
<td>16643</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>7.47%</td>
<td>0.00%</td>
<td>1346</td>
<td>3</td>
<td>317713</td>
<td>16666</td>
</tr>
<tr>
<td>Arcabit</td>
<td>6.16%</td>
<td>0.00%</td>
<td>1110</td>
<td>1</td>
<td>317715</td>
<td>16902</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>6.12%</td>
<td>0.00%</td>
<td>1103</td>
<td>0</td>
<td>317716</td>
<td>16909</td>
</tr>
<tr>
<td>Rising</td>
<td>5.06%</td>
<td>0.01%</td>
<td>911</td>
<td>16</td>
<td>317700</td>
<td>17101</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>3.09%</td>
<td>0.01%</td>
<td>556</td>
<td>41</td>
<td>317675</td>
<td>17456</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>2.65%</td>
<td>0.02%</td>
<td>477</td>
<td>58</td>
<td>317658</td>
<td>17535</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>2.17%</td>
<td>0.00%</td>
<td>390</td>
<td>0</td>
<td>317716</td>
<td>17622</td>
</tr>
<tr>
<td>Zoner</td>
<td>1.47%</td>
<td>0.00%</td>
<td>264</td>
<td>15</td>
<td>317701</td>
<td>17748</td>
</tr>
<tr>
<td>VBA32</td>
<td>0.82%</td>
<td>0.01%</td>
<td>148</td>
<td>30</td>
<td>317686</td>
<td>17864</td>
</tr>
<tr>
<td>Panda</td>
<td>0.52%</td>
<td>0.00%</td>
<td>94</td>
<td>4</td>
<td>317712</td>
<td>17918</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.52%</td>
<td>0.00%</td>
<td>93</td>
<td>15</td>
<td>317701</td>
<td>17919</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.32%</td>
<td>0.00%</td>
<td>57</td>
<td>5</td>
<td>317711</td>
<td>17955</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.30%</td>
<td>0.00%</td>
<td>54</td>
<td>2</td>
<td>317714</td>
<td>17958</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.10%</td>
<td>0.00%</td>
<td>18</td>
<td>1</td>
<td>317715</td>
<td>17994</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.08%</td>
<td>0.00%</td>
<td>14</td>
<td>0</td>
<td>317716</td>
<td>17998</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.04%</td>
<td>0.00%</td>
<td>7</td>
<td>0</td>
<td>317716</td>
<td>18005</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.01%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>317716</td>
<td>18010</td>
</tr>
<tr>
<td>CMC</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>317716</td>
<td>18011</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>317716</td>
<td>18011</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>317716</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>18012</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>335728</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p></p><p>Please send an email to lxu@trustlook.com if you have any comments. Thanks.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK 病毒检测统计 2021-11]]></title><description><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211101_20211130.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211101_20211130.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong></li></ul>]]></description><link>https://blog.trustlook.com/virustotal-apk-bing-du-jian-ce-tong-ji-2021-11/</link><guid isPermaLink="false">61a9ac0e41be690427194612</guid><category><![CDATA[杀毒引擎评测]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Fri, 03 Dec 2021 05:33:42 GMT</pubDate><content:encoded><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211101_20211130.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211101_20211130.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li>
<li><strong>TPR</strong>: True Positive Rate, 恶意样本检出率</li>
<li><strong>FPR</strong>: False Positive Rate, 良性样本误报率</li>
<li><strong>TP</strong>: True Positive, 正确检出为恶意样本的数量</li>
<li><strong>FP</strong>: False Positive, 误报为恶意样本的数量</li>
<li><strong>TN</strong>: True Negative, 正确检出为良性样本的数量</li>
<li><strong>FN</strong>: False Negative, 误报为良性样本的数量</li>
</ul>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>Fortinet</td>
<td>99.73%</td>
<td>0.05%</td>
<td>17964</td>
<td>154</td>
<td>317562</td>
<td>48</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.66%</td>
<td>0.02%</td>
<td>17951</td>
<td>53</td>
<td>317663</td>
<td>61</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.01%</td>
<td>0.05%</td>
<td>17834</td>
<td>171</td>
<td>317545</td>
<td>178</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>98.92%</td>
<td>0.38%</td>
<td>17818</td>
<td>1207</td>
<td>316509</td>
<td>194</td>
</tr>
<tr>
<td>Avira</td>
<td>98.63%</td>
<td>0.00%</td>
<td>17766</td>
<td>9</td>
<td>317707</td>
<td>246</td>
</tr>
<tr>
<td>DrWeb</td>
<td>97.72%</td>
<td>0.05%</td>
<td>17602</td>
<td>165</td>
<td>317551</td>
<td>410</td>
</tr>
<tr>
<td>Ikarus</td>
<td>95.35%</td>
<td>0.03%</td>
<td>17175</td>
<td>83</td>
<td>317633</td>
<td>837</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>94.96%</td>
<td>0.01%</td>
<td>17104</td>
<td>38</td>
<td>317678</td>
<td>908</td>
</tr>
<tr>
<td>McAfee</td>
<td>93.86%</td>
<td>0.01%</td>
<td>16906</td>
<td>18</td>
<td>317698</td>
<td>1106</td>
</tr>
<tr>
<td>Trustlook</td>
<td>93.69%</td>
<td>0.02%</td>
<td>16876</td>
<td>66</td>
<td>317650</td>
<td>1136</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>93.65%</td>
<td>0.01%</td>
<td>16868</td>
<td>22</td>
<td>317694</td>
<td>1144</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>92.99%</td>
<td>0.01%</td>
<td>16749</td>
<td>17</td>
<td>317699</td>
<td>1263</td>
</tr>
<tr>
<td>Microsoft</td>
<td>91.13%</td>
<td>0.02%</td>
<td>16414</td>
<td>61</td>
<td>317655</td>
<td>1598</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>86.62%</td>
<td>0.01%</td>
<td>15602</td>
<td>39</td>
<td>317677</td>
<td>2410</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>80.61%</td>
<td>1.55%</td>
<td>14519</td>
<td>4938</td>
<td>312778</td>
<td>3493</td>
</tr>
<tr>
<td>Tencent</td>
<td>78.95%</td>
<td>0.08%</td>
<td>14220</td>
<td>245</td>
<td>317471</td>
<td>3792</td>
</tr>
<tr>
<td>Sophos</td>
<td>78.53%</td>
<td>0.01%</td>
<td>14145</td>
<td>26</td>
<td>317690</td>
<td>3867</td>
</tr>
<tr>
<td>Symantec</td>
<td>75.87%</td>
<td>0.01%</td>
<td>13665</td>
<td>18</td>
<td>317698</td>
<td>4347</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>64.73%</td>
<td>0.01%</td>
<td>11660</td>
<td>46</td>
<td>317670</td>
<td>6352</td>
</tr>
<tr>
<td>Alibaba</td>
<td>64.50%</td>
<td>0.00%</td>
<td>11617</td>
<td>7</td>
<td>317709</td>
<td>6395</td>
</tr>
<tr>
<td>Cyren</td>
<td>61.87%</td>
<td>0.01%</td>
<td>11144</td>
<td>23</td>
<td>317693</td>
<td>6868</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>59.12%</td>
<td>0.08%</td>
<td>10649</td>
<td>245</td>
<td>317471</td>
<td>7363</td>
</tr>
<tr>
<td>AVG</td>
<td>52.25%</td>
<td>0.02%</td>
<td>9412</td>
<td>53</td>
<td>317663</td>
<td>8600</td>
</tr>
<tr>
<td>Avast</td>
<td>52.17%</td>
<td>0.02%</td>
<td>9396</td>
<td>53</td>
<td>317663</td>
<td>8616</td>
</tr>
<tr>
<td>MAX</td>
<td>48.91%</td>
<td>0.00%</td>
<td>8809</td>
<td>1</td>
<td>317715</td>
<td>9203</td>
</tr>
<tr>
<td>Comodo</td>
<td>33.40%</td>
<td>0.05%</td>
<td>6016</td>
<td>164</td>
<td>317552</td>
<td>11996</td>
</tr>
<tr>
<td>Zillya</td>
<td>22.51%</td>
<td>0.05%</td>
<td>4054</td>
<td>169</td>
<td>317547</td>
<td>13958</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>14.43%</td>
<td>0.47%</td>
<td>2599</td>
<td>1502</td>
<td>316214</td>
<td>15413</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>14.35%</td>
<td>0.01%</td>
<td>2585</td>
<td>43</td>
<td>317673</td>
<td>15427</td>
</tr>
<tr>
<td>ClamAV</td>
<td>12.54%</td>
<td>0.09%</td>
<td>2258</td>
<td>273</td>
<td>317443</td>
<td>15754</td>
</tr>
<tr>
<td>GData</td>
<td>12.22%</td>
<td>0.00%</td>
<td>2201</td>
<td>0</td>
<td>317716</td>
<td>15811</td>
</tr>
<tr>
<td>BitDefender</td>
<td>11.11%</td>
<td>0.00%</td>
<td>2002</td>
<td>0</td>
<td>317716</td>
<td>16010</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>10.90%</td>
<td>0.00%</td>
<td>1963</td>
<td>0</td>
<td>317716</td>
<td>16049</td>
</tr>
<tr>
<td>Yandex</td>
<td>7.80%</td>
<td>0.01%</td>
<td>1405</td>
<td>17</td>
<td>317699</td>
<td>16607</td>
</tr>
<tr>
<td>F-Secure</td>
<td>7.60%</td>
<td>0.00%</td>
<td>1369</td>
<td>1</td>
<td>317715</td>
<td>16643</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>7.47%</td>
<td>0.00%</td>
<td>1346</td>
<td>3</td>
<td>317713</td>
<td>16666</td>
</tr>
<tr>
<td>Arcabit</td>
<td>6.16%</td>
<td>0.00%</td>
<td>1110</td>
<td>1</td>
<td>317715</td>
<td>16902</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>6.12%</td>
<td>0.00%</td>
<td>1103</td>
<td>0</td>
<td>317716</td>
<td>16909</td>
</tr>
<tr>
<td>Rising</td>
<td>5.06%</td>
<td>0.01%</td>
<td>911</td>
<td>16</td>
<td>317700</td>
<td>17101</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>3.09%</td>
<td>0.01%</td>
<td>556</td>
<td>41</td>
<td>317675</td>
<td>17456</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>2.65%</td>
<td>0.02%</td>
<td>477</td>
<td>58</td>
<td>317658</td>
<td>17535</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>2.17%</td>
<td>0.00%</td>
<td>390</td>
<td>0</td>
<td>317716</td>
<td>17622</td>
</tr>
<tr>
<td>Zoner</td>
<td>1.47%</td>
<td>0.00%</td>
<td>264</td>
<td>15</td>
<td>317701</td>
<td>17748</td>
</tr>
<tr>
<td>VBA32</td>
<td>0.82%</td>
<td>0.01%</td>
<td>148</td>
<td>30</td>
<td>317686</td>
<td>17864</td>
</tr>
<tr>
<td>Panda</td>
<td>0.52%</td>
<td>0.00%</td>
<td>94</td>
<td>4</td>
<td>317712</td>
<td>17918</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.52%</td>
<td>0.00%</td>
<td>93</td>
<td>15</td>
<td>317701</td>
<td>17919</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.32%</td>
<td>0.00%</td>
<td>57</td>
<td>5</td>
<td>317711</td>
<td>17955</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.30%</td>
<td>0.00%</td>
<td>54</td>
<td>2</td>
<td>317714</td>
<td>17958</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.10%</td>
<td>0.00%</td>
<td>18</td>
<td>1</td>
<td>317715</td>
<td>17994</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.08%</td>
<td>0.00%</td>
<td>14</td>
<td>0</td>
<td>317716</td>
<td>17998</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.04%</td>
<td>0.00%</td>
<td>7</td>
<td>0</td>
<td>317716</td>
<td>18005</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.01%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>317716</td>
<td>18010</td>
</tr>
<tr>
<td>CMC</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>317716</td>
<td>18011</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>317716</td>
<td>18011</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>317716</td>
<td>18012</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>317716</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>18012</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>335728</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>如有任何疑问, 欢迎随时邮件联系 lxu@trustlook.com. 谢谢.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK 病毒检测统计 2021-10]]></title><description><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211001_20211031.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211001_20211031.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong></li></ul>]]></description><link>https://blog.trustlook.com/virustotal-apk-bing-du-jian-ce-tong-ji-2021-10/</link><guid isPermaLink="false">61a5a5ce41be690427194604</guid><category><![CDATA[杀毒引擎评测]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Wed, 01 Dec 2021 04:22:00 GMT</pubDate><content:encoded><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211001_20211031.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211001_20211031.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li>
<li><strong>TPR</strong>: True Positive Rate, 恶意样本检出率</li>
<li><strong>FPR</strong>: False Positive Rate, 良性样本误报率</li>
<li><strong>TP</strong>: True Positive, 正确检出为恶意样本的数量</li>
<li><strong>FP</strong>: False Positive, 误报为恶意样本的数量</li>
<li><strong>TN</strong>: True Negative, 正确检出为良性样本的数量</li>
<li><strong>FN</strong>: False Negative, 误报为良性样本的数量</li>
</ul>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>ESET-NOD32</td>
<td>99.63%</td>
<td>0.04%</td>
<td>7517</td>
<td>66</td>
<td>165131</td>
<td>28</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.48%</td>
<td>0.10%</td>
<td>7506</td>
<td>159</td>
<td>165038</td>
<td>39</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.44%</td>
<td>0.10%</td>
<td>7503</td>
<td>164</td>
<td>165033</td>
<td>42</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>98.91%</td>
<td>0.82%</td>
<td>7463</td>
<td>1352</td>
<td>163845</td>
<td>82</td>
</tr>
<tr>
<td>DrWeb</td>
<td>98.22%</td>
<td>0.09%</td>
<td>7411</td>
<td>142</td>
<td>165055</td>
<td>134</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.14%</td>
<td>0.06%</td>
<td>7405</td>
<td>101</td>
<td>165096</td>
<td>140</td>
</tr>
<tr>
<td>Avira</td>
<td>97.80%</td>
<td>0.00%</td>
<td>7379</td>
<td>4</td>
<td>165193</td>
<td>166</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>96.39%</td>
<td>0.05%</td>
<td>7273</td>
<td>85</td>
<td>165112</td>
<td>272</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>94.98%</td>
<td>0.02%</td>
<td>7166</td>
<td>29</td>
<td>165168</td>
<td>379</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>94.13%</td>
<td>0.01%</td>
<td>7102</td>
<td>20</td>
<td>165177</td>
<td>443</td>
</tr>
<tr>
<td>Trustlook</td>
<td>93.76%</td>
<td>0.00%</td>
<td>7074</td>
<td>7</td>
<td>165190</td>
<td>471</td>
</tr>
<tr>
<td>McAfee</td>
<td>92.60%</td>
<td>0.02%</td>
<td>6987</td>
<td>34</td>
<td>165163</td>
<td>558</td>
</tr>
<tr>
<td>Microsoft</td>
<td>87.28%</td>
<td>0.03%</td>
<td>6585</td>
<td>52</td>
<td>165145</td>
<td>960</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>84.96%</td>
<td>0.02%</td>
<td>6410</td>
<td>35</td>
<td>165162</td>
<td>1135</td>
</tr>
<tr>
<td>Sophos</td>
<td>83.46%</td>
<td>0.02%</td>
<td>6297</td>
<td>27</td>
<td>165170</td>
<td>1248</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>78.52%</td>
<td>0.02%</td>
<td>5924</td>
<td>41</td>
<td>165156</td>
<td>1621</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>74.16%</td>
<td>0.10%</td>
<td>5595</td>
<td>173</td>
<td>165024</td>
<td>1950</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>74.04%</td>
<td>2.22%</td>
<td>5586</td>
<td>3675</td>
<td>161522</td>
<td>1959</td>
</tr>
<tr>
<td>Tencent</td>
<td>69.65%</td>
<td>0.11%</td>
<td>5255</td>
<td>184</td>
<td>165013</td>
<td>2290</td>
</tr>
<tr>
<td>Cyren</td>
<td>64.15%</td>
<td>0.02%</td>
<td>4840</td>
<td>30</td>
<td>165167</td>
<td>2705</td>
</tr>
<tr>
<td>Symantec</td>
<td>57.99%</td>
<td>0.00%</td>
<td>4375</td>
<td>3</td>
<td>165194</td>
<td>3170</td>
</tr>
<tr>
<td>Alibaba</td>
<td>56.30%</td>
<td>0.00%</td>
<td>4248</td>
<td>6</td>
<td>165191</td>
<td>3297</td>
</tr>
<tr>
<td>AVG</td>
<td>55.26%</td>
<td>0.01%</td>
<td>4169</td>
<td>22</td>
<td>165175</td>
<td>3376</td>
</tr>
<tr>
<td>Avast</td>
<td>55.14%</td>
<td>0.01%</td>
<td>4160</td>
<td>22</td>
<td>165175</td>
<td>3385</td>
</tr>
<tr>
<td>MAX</td>
<td>52.72%</td>
<td>0.00%</td>
<td>3978</td>
<td>0</td>
<td>165197</td>
<td>3567</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>48.32%</td>
<td>0.01%</td>
<td>3646</td>
<td>19</td>
<td>165178</td>
<td>3899</td>
</tr>
<tr>
<td>Comodo</td>
<td>42.32%</td>
<td>0.07%</td>
<td>3193</td>
<td>120</td>
<td>165077</td>
<td>4352</td>
</tr>
<tr>
<td>Zillya</td>
<td>30.88%</td>
<td>0.06%</td>
<td>2330</td>
<td>93</td>
<td>165104</td>
<td>5215</td>
</tr>
<tr>
<td>ClamAV</td>
<td>17.81%</td>
<td>0.07%</td>
<td>1344</td>
<td>113</td>
<td>165084</td>
<td>6201</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>15.79%</td>
<td>0.43%</td>
<td>1191</td>
<td>713</td>
<td>164484</td>
<td>6354</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>15.40%</td>
<td>0.01%</td>
<td>1162</td>
<td>24</td>
<td>165173</td>
<td>6383</td>
</tr>
<tr>
<td>GData</td>
<td>15.06%</td>
<td>0.00%</td>
<td>1136</td>
<td>1</td>
<td>165196</td>
<td>6409</td>
</tr>
<tr>
<td>BitDefender</td>
<td>14.25%</td>
<td>0.00%</td>
<td>1075</td>
<td>0</td>
<td>165197</td>
<td>6470</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>14.12%</td>
<td>0.00%</td>
<td>1065</td>
<td>0</td>
<td>165197</td>
<td>6480</td>
</tr>
<tr>
<td>Yandex</td>
<td>10.40%</td>
<td>0.00%</td>
<td>785</td>
<td>7</td>
<td>165190</td>
<td>6760</td>
</tr>
<tr>
<td>F-Secure</td>
<td>9.94%</td>
<td>0.00%</td>
<td>750</td>
<td>1</td>
<td>165196</td>
<td>6795</td>
</tr>
<tr>
<td>Arcabit</td>
<td>8.56%</td>
<td>0.00%</td>
<td>646</td>
<td>1</td>
<td>165196</td>
<td>6899</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>8.40%</td>
<td>0.00%</td>
<td>634</td>
<td>0</td>
<td>165197</td>
<td>6911</td>
</tr>
<tr>
<td>Zoner</td>
<td>7.20%</td>
<td>0.00%</td>
<td>543</td>
<td>4</td>
<td>165193</td>
<td>7002</td>
</tr>
<tr>
<td>Rising</td>
<td>6.03%</td>
<td>0.01%</td>
<td>455</td>
<td>10</td>
<td>165187</td>
<td>7090</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>5.99%</td>
<td>0.01%</td>
<td>452</td>
<td>21</td>
<td>165176</td>
<td>7093</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>4.53%</td>
<td>0.02%</td>
<td>342</td>
<td>34</td>
<td>165163</td>
<td>7203</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>2.92%</td>
<td>0.00%</td>
<td>220</td>
<td>0</td>
<td>165197</td>
<td>7325</td>
</tr>
<tr>
<td>VBA32</td>
<td>1.02%</td>
<td>0.01%</td>
<td>77</td>
<td>9</td>
<td>165188</td>
<td>7468</td>
</tr>
<tr>
<td>Panda</td>
<td>0.34%</td>
<td>0.00%</td>
<td>26</td>
<td>0</td>
<td>165197</td>
<td>7519</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.28%</td>
<td>0.01%</td>
<td>21</td>
<td>15</td>
<td>165182</td>
<td>7524</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.28%</td>
<td>0.00%</td>
<td>21</td>
<td>0</td>
<td>165197</td>
<td>7524</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.19%</td>
<td>0.00%</td>
<td>14</td>
<td>0</td>
<td>165197</td>
<td>7531</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.05%</td>
<td>0.00%</td>
<td>4</td>
<td>0</td>
<td>165197</td>
<td>7541</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.04%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>165197</td>
<td>7542</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.04%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>165197</td>
<td>7542</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.04%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>165197</td>
<td>7542</td>
</tr>
<tr>
<td>CMC</td>
<td>0.03%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>165197</td>
<td>7543</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.03%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>165197</td>
<td>7543</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>165197</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>7545</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>172742</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>如有任何疑问, 欢迎随时邮件联系 lxu@trustlook.com. 谢谢.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK Malware Detection Data 2021-10]]></title><description><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-malware-detection-data-2021-10/</link><guid isPermaLink="false">61a5a52941be6904271945f7</guid><category><![CDATA[VirusTotal]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Wed, 01 Dec 2021 04:21:00 GMT</pubDate><content:encoded><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of live feed samples. Then we look at detection results from AV vendors and rate them by how many malware they have detected and how many benign samples they have misclassified. </p><p>We generate a CSV file recording the detection results everyday. In the CSV file, from left to right, the columns are MD5 hash of the APK, label where 1 means positive (malicious) and 0 means negative (benign), and one column for each vendor showing its detection results where 1 means positive and 0 means negative. </p><p>On a monthly basis, we publish the detection results and zip the CSV files to AWS S3. For this month, you can download the detection data from:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211001_20211031.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20211001_20211031.zip</a></p><p>The monthly results are summarized in the table below and here is a simple explanation of the columns in the table:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: AV engine vendor</li>
<li><strong>TPR</strong>: True Positive Rate, percentage of positive (malware) samples being correctly classified as positive</li>
<li><strong>FPR</strong>: False Positive Rate, percentage of negative (goodware) samples being misclassified as positive</li>
<li><strong>TP</strong>: True Positive, number of positive (malware) samples being correctly classified as positive</li>
<li><strong>FP</strong>: False Positive, number of negative (goodware) samples being misclassified as positive</li>
<li><strong>TN</strong>: True Negative, number of negative (goodware) samples being correctly classified as negative</li>
<li><strong>FN</strong>: False Negative, number of positive (malware) samples being misclassified as negative</li>
</ul>
<!--kg-card-end: markdown--><p></p><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>ESET-NOD32</td>
<td>99.63%</td>
<td>0.04%</td>
<td>7517</td>
<td>66</td>
<td>165131</td>
<td>28</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.48%</td>
<td>0.10%</td>
<td>7506</td>
<td>159</td>
<td>165038</td>
<td>39</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.44%</td>
<td>0.10%</td>
<td>7503</td>
<td>164</td>
<td>165033</td>
<td>42</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>98.91%</td>
<td>0.82%</td>
<td>7463</td>
<td>1352</td>
<td>163845</td>
<td>82</td>
</tr>
<tr>
<td>DrWeb</td>
<td>98.22%</td>
<td>0.09%</td>
<td>7411</td>
<td>142</td>
<td>165055</td>
<td>134</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.14%</td>
<td>0.06%</td>
<td>7405</td>
<td>101</td>
<td>165096</td>
<td>140</td>
</tr>
<tr>
<td>Avira</td>
<td>97.80%</td>
<td>0.00%</td>
<td>7379</td>
<td>4</td>
<td>165193</td>
<td>166</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>96.39%</td>
<td>0.05%</td>
<td>7273</td>
<td>85</td>
<td>165112</td>
<td>272</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>94.98%</td>
<td>0.02%</td>
<td>7166</td>
<td>29</td>
<td>165168</td>
<td>379</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>94.13%</td>
<td>0.01%</td>
<td>7102</td>
<td>20</td>
<td>165177</td>
<td>443</td>
</tr>
<tr>
<td>Trustlook</td>
<td>93.76%</td>
<td>0.00%</td>
<td>7074</td>
<td>7</td>
<td>165190</td>
<td>471</td>
</tr>
<tr>
<td>McAfee</td>
<td>92.60%</td>
<td>0.02%</td>
<td>6987</td>
<td>34</td>
<td>165163</td>
<td>558</td>
</tr>
<tr>
<td>Microsoft</td>
<td>87.28%</td>
<td>0.03%</td>
<td>6585</td>
<td>52</td>
<td>165145</td>
<td>960</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>84.96%</td>
<td>0.02%</td>
<td>6410</td>
<td>35</td>
<td>165162</td>
<td>1135</td>
</tr>
<tr>
<td>Sophos</td>
<td>83.46%</td>
<td>0.02%</td>
<td>6297</td>
<td>27</td>
<td>165170</td>
<td>1248</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>78.52%</td>
<td>0.02%</td>
<td>5924</td>
<td>41</td>
<td>165156</td>
<td>1621</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>74.16%</td>
<td>0.10%</td>
<td>5595</td>
<td>173</td>
<td>165024</td>
<td>1950</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>74.04%</td>
<td>2.22%</td>
<td>5586</td>
<td>3675</td>
<td>161522</td>
<td>1959</td>
</tr>
<tr>
<td>Tencent</td>
<td>69.65%</td>
<td>0.11%</td>
<td>5255</td>
<td>184</td>
<td>165013</td>
<td>2290</td>
</tr>
<tr>
<td>Cyren</td>
<td>64.15%</td>
<td>0.02%</td>
<td>4840</td>
<td>30</td>
<td>165167</td>
<td>2705</td>
</tr>
<tr>
<td>Symantec</td>
<td>57.99%</td>
<td>0.00%</td>
<td>4375</td>
<td>3</td>
<td>165194</td>
<td>3170</td>
</tr>
<tr>
<td>Alibaba</td>
<td>56.30%</td>
<td>0.00%</td>
<td>4248</td>
<td>6</td>
<td>165191</td>
<td>3297</td>
</tr>
<tr>
<td>AVG</td>
<td>55.26%</td>
<td>0.01%</td>
<td>4169</td>
<td>22</td>
<td>165175</td>
<td>3376</td>
</tr>
<tr>
<td>Avast</td>
<td>55.14%</td>
<td>0.01%</td>
<td>4160</td>
<td>22</td>
<td>165175</td>
<td>3385</td>
</tr>
<tr>
<td>MAX</td>
<td>52.72%</td>
<td>0.00%</td>
<td>3978</td>
<td>0</td>
<td>165197</td>
<td>3567</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>48.32%</td>
<td>0.01%</td>
<td>3646</td>
<td>19</td>
<td>165178</td>
<td>3899</td>
</tr>
<tr>
<td>Comodo</td>
<td>42.32%</td>
<td>0.07%</td>
<td>3193</td>
<td>120</td>
<td>165077</td>
<td>4352</td>
</tr>
<tr>
<td>Zillya</td>
<td>30.88%</td>
<td>0.06%</td>
<td>2330</td>
<td>93</td>
<td>165104</td>
<td>5215</td>
</tr>
<tr>
<td>ClamAV</td>
<td>17.81%</td>
<td>0.07%</td>
<td>1344</td>
<td>113</td>
<td>165084</td>
<td>6201</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>15.79%</td>
<td>0.43%</td>
<td>1191</td>
<td>713</td>
<td>164484</td>
<td>6354</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>15.40%</td>
<td>0.01%</td>
<td>1162</td>
<td>24</td>
<td>165173</td>
<td>6383</td>
</tr>
<tr>
<td>GData</td>
<td>15.06%</td>
<td>0.00%</td>
<td>1136</td>
<td>1</td>
<td>165196</td>
<td>6409</td>
</tr>
<tr>
<td>BitDefender</td>
<td>14.25%</td>
<td>0.00%</td>
<td>1075</td>
<td>0</td>
<td>165197</td>
<td>6470</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>14.12%</td>
<td>0.00%</td>
<td>1065</td>
<td>0</td>
<td>165197</td>
<td>6480</td>
</tr>
<tr>
<td>Yandex</td>
<td>10.40%</td>
<td>0.00%</td>
<td>785</td>
<td>7</td>
<td>165190</td>
<td>6760</td>
</tr>
<tr>
<td>F-Secure</td>
<td>9.94%</td>
<td>0.00%</td>
<td>750</td>
<td>1</td>
<td>165196</td>
<td>6795</td>
</tr>
<tr>
<td>Arcabit</td>
<td>8.56%</td>
<td>0.00%</td>
<td>646</td>
<td>1</td>
<td>165196</td>
<td>6899</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>8.40%</td>
<td>0.00%</td>
<td>634</td>
<td>0</td>
<td>165197</td>
<td>6911</td>
</tr>
<tr>
<td>Zoner</td>
<td>7.20%</td>
<td>0.00%</td>
<td>543</td>
<td>4</td>
<td>165193</td>
<td>7002</td>
</tr>
<tr>
<td>Rising</td>
<td>6.03%</td>
<td>0.01%</td>
<td>455</td>
<td>10</td>
<td>165187</td>
<td>7090</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>5.99%</td>
<td>0.01%</td>
<td>452</td>
<td>21</td>
<td>165176</td>
<td>7093</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>4.53%</td>
<td>0.02%</td>
<td>342</td>
<td>34</td>
<td>165163</td>
<td>7203</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>2.92%</td>
<td>0.00%</td>
<td>220</td>
<td>0</td>
<td>165197</td>
<td>7325</td>
</tr>
<tr>
<td>VBA32</td>
<td>1.02%</td>
<td>0.01%</td>
<td>77</td>
<td>9</td>
<td>165188</td>
<td>7468</td>
</tr>
<tr>
<td>Panda</td>
<td>0.34%</td>
<td>0.00%</td>
<td>26</td>
<td>0</td>
<td>165197</td>
<td>7519</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.28%</td>
<td>0.01%</td>
<td>21</td>
<td>15</td>
<td>165182</td>
<td>7524</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.28%</td>
<td>0.00%</td>
<td>21</td>
<td>0</td>
<td>165197</td>
<td>7524</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.19%</td>
<td>0.00%</td>
<td>14</td>
<td>0</td>
<td>165197</td>
<td>7531</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.05%</td>
<td>0.00%</td>
<td>4</td>
<td>0</td>
<td>165197</td>
<td>7541</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.04%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>165197</td>
<td>7542</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.04%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>165197</td>
<td>7542</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.04%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>165197</td>
<td>7542</td>
</tr>
<tr>
<td>CMC</td>
<td>0.03%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>165197</td>
<td>7543</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.03%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>165197</td>
<td>7543</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>165197</td>
<td>7545</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>165197</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>7545</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>172742</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p></p><p>Please send an email to lxu@trustlook.com if you have any comments. Thanks.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK Malware Detection Data 2021-09]]></title><description><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-malware-detection-data-2021-09/</link><guid isPermaLink="false">61a5a4f641be6904271945ea</guid><category><![CDATA[VirusTotal]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Tue, 30 Nov 2021 04:14:14 GMT</pubDate><content:encoded><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of live feed samples. Then we look at detection results from AV vendors and rate them by how many malware they have detected and how many benign samples they have misclassified. </p><p>We generate a CSV file recording the detection results everyday. In the CSV file, from left to right, the columns are MD5 hash of the APK, label where 1 means positive (malicious) and 0 means negative (benign), and one column for each vendor showing its detection results where 1 means positive and 0 means negative. </p><p>On a monthly basis, we publish the detection results and zip the CSV files to AWS S3. For this month, you can download the detection data from:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210901_20210930.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210901_20210930.zip</a></p><p>The monthly results are summarized in the table below and here is a simple explanation of the columns in the table:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: AV engine vendor</li>
<li><strong>TPR</strong>: True Positive Rate, percentage of positive (malware) samples being correctly classified as positive</li>
<li><strong>FPR</strong>: False Positive Rate, percentage of negative (goodware) samples being misclassified as positive</li>
<li><strong>TP</strong>: True Positive, number of positive (malware) samples being correctly classified as positive</li>
<li><strong>FP</strong>: False Positive, number of negative (goodware) samples being misclassified as positive</li>
<li><strong>TN</strong>: True Negative, number of negative (goodware) samples being correctly classified as negative</li>
<li><strong>FN</strong>: False Negative, number of positive (malware) samples being misclassified as negative</li>
</ul>
<!--kg-card-end: markdown--><p></p><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>K7GW</td>
<td>99.73%</td>
<td>0.10%</td>
<td>10871</td>
<td>207</td>
<td>205774</td>
<td>29</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.65%</td>
<td>0.03%</td>
<td>10862</td>
<td>54</td>
<td>205927</td>
<td>38</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.61%</td>
<td>0.09%</td>
<td>10858</td>
<td>180</td>
<td>205801</td>
<td>42</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>98.89%</td>
<td>0.72%</td>
<td>10779</td>
<td>1484</td>
<td>204497</td>
<td>121</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.28%</td>
<td>0.06%</td>
<td>10712</td>
<td>132</td>
<td>205849</td>
<td>188</td>
</tr>
<tr>
<td>DrWeb</td>
<td>98.07%</td>
<td>0.09%</td>
<td>10690</td>
<td>182</td>
<td>205799</td>
<td>210</td>
</tr>
<tr>
<td>Avira</td>
<td>98.06%</td>
<td>0.01%</td>
<td>10688</td>
<td>14</td>
<td>205967</td>
<td>212</td>
</tr>
<tr>
<td>Trustlook</td>
<td>96.25%</td>
<td>0.00%</td>
<td>10491</td>
<td>10</td>
<td>205971</td>
<td>409</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>94.47%</td>
<td>0.02%</td>
<td>10297</td>
<td>31</td>
<td>205950</td>
<td>603</td>
</tr>
<tr>
<td>McAfee</td>
<td>94.14%</td>
<td>0.03%</td>
<td>10261</td>
<td>54</td>
<td>205927</td>
<td>639</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>93.65%</td>
<td>0.02%</td>
<td>10208</td>
<td>35</td>
<td>205946</td>
<td>692</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>92.50%</td>
<td>0.05%</td>
<td>10082</td>
<td>104</td>
<td>205877</td>
<td>818</td>
</tr>
<tr>
<td>Microsoft</td>
<td>90.21%</td>
<td>0.02%</td>
<td>9833</td>
<td>44</td>
<td>205937</td>
<td>1067</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>86.45%</td>
<td>0.03%</td>
<td>9423</td>
<td>56</td>
<td>205925</td>
<td>1477</td>
</tr>
<tr>
<td>Sophos</td>
<td>80.59%</td>
<td>0.01%</td>
<td>8784</td>
<td>25</td>
<td>205956</td>
<td>2116</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>76.53%</td>
<td>0.02%</td>
<td>8342</td>
<td>43</td>
<td>205938</td>
<td>2558</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>73.94%</td>
<td>2.69%</td>
<td>8059</td>
<td>5536</td>
<td>200445</td>
<td>2841</td>
</tr>
<tr>
<td>Cyren</td>
<td>68.58%</td>
<td>0.02%</td>
<td>7475</td>
<td>41</td>
<td>205940</td>
<td>3425</td>
</tr>
<tr>
<td>Tencent</td>
<td>67.96%</td>
<td>0.12%</td>
<td>7408</td>
<td>251</td>
<td>205730</td>
<td>3492</td>
</tr>
<tr>
<td>Symantec</td>
<td>66.94%</td>
<td>0.00%</td>
<td>7296</td>
<td>4</td>
<td>205977</td>
<td>3604</td>
</tr>
<tr>
<td>Alibaba</td>
<td>63.95%</td>
<td>0.00%</td>
<td>6971</td>
<td>8</td>
<td>205973</td>
<td>3929</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>63.48%</td>
<td>0.09%</td>
<td>6919</td>
<td>185</td>
<td>205796</td>
<td>3981</td>
</tr>
<tr>
<td>MAX</td>
<td>55.36%</td>
<td>0.00%</td>
<td>6034</td>
<td>4</td>
<td>205977</td>
<td>4866</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>48.06%</td>
<td>0.02%</td>
<td>5239</td>
<td>36</td>
<td>205945</td>
<td>5661</td>
</tr>
<tr>
<td>AVG</td>
<td>42.71%</td>
<td>0.02%</td>
<td>4655</td>
<td>31</td>
<td>205950</td>
<td>6245</td>
</tr>
<tr>
<td>Avast</td>
<td>42.56%</td>
<td>0.02%</td>
<td>4639</td>
<td>31</td>
<td>205950</td>
<td>6261</td>
</tr>
<tr>
<td>Comodo</td>
<td>28.25%</td>
<td>0.09%</td>
<td>3079</td>
<td>186</td>
<td>205795</td>
<td>7821</td>
</tr>
<tr>
<td>Zillya</td>
<td>26.37%</td>
<td>0.08%</td>
<td>2874</td>
<td>157</td>
<td>205824</td>
<td>8026</td>
</tr>
<tr>
<td>GData</td>
<td>16.16%</td>
<td>0.00%</td>
<td>1761</td>
<td>1</td>
<td>205980</td>
<td>9139</td>
</tr>
<tr>
<td>Yandex</td>
<td>14.40%</td>
<td>0.00%</td>
<td>1570</td>
<td>4</td>
<td>205977</td>
<td>9330</td>
</tr>
<tr>
<td>ClamAV</td>
<td>14.33%</td>
<td>0.08%</td>
<td>1562</td>
<td>174</td>
<td>205807</td>
<td>9338</td>
</tr>
<tr>
<td>BitDefender</td>
<td>14.19%</td>
<td>0.00%</td>
<td>1547</td>
<td>1</td>
<td>205980</td>
<td>9353</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>14.02%</td>
<td>0.00%</td>
<td>1528</td>
<td>0</td>
<td>205981</td>
<td>9372</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>11.43%</td>
<td>0.48%</td>
<td>1246</td>
<td>991</td>
<td>204990</td>
<td>9654</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>9.48%</td>
<td>0.01%</td>
<td>1033</td>
<td>27</td>
<td>205954</td>
<td>9867</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>9.45%</td>
<td>0.00%</td>
<td>1030</td>
<td>0</td>
<td>205981</td>
<td>9870</td>
</tr>
<tr>
<td>F-Secure</td>
<td>9.39%</td>
<td>0.00%</td>
<td>1024</td>
<td>1</td>
<td>205980</td>
<td>9876</td>
</tr>
<tr>
<td>Arcabit</td>
<td>8.06%</td>
<td>0.00%</td>
<td>879</td>
<td>1</td>
<td>205980</td>
<td>10021</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>4.09%</td>
<td>0.00%</td>
<td>446</td>
<td>0</td>
<td>205981</td>
<td>10454</td>
</tr>
<tr>
<td>Zoner</td>
<td>4.08%</td>
<td>0.00%</td>
<td>445</td>
<td>8</td>
<td>205973</td>
<td>10455</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>3.80%</td>
<td>0.02%</td>
<td>414</td>
<td>36</td>
<td>205945</td>
<td>10486</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>3.25%</td>
<td>0.03%</td>
<td>354</td>
<td>65</td>
<td>205916</td>
<td>10546</td>
</tr>
<tr>
<td>Rising</td>
<td>1.98%</td>
<td>0.01%</td>
<td>216</td>
<td>14</td>
<td>205967</td>
<td>10684</td>
</tr>
<tr>
<td>VBA32</td>
<td>0.94%</td>
<td>0.01%</td>
<td>103</td>
<td>28</td>
<td>205953</td>
<td>10797</td>
</tr>
<tr>
<td>Panda</td>
<td>0.58%</td>
<td>0.00%</td>
<td>63</td>
<td>1</td>
<td>205980</td>
<td>10837</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.30%</td>
<td>0.01%</td>
<td>33</td>
<td>27</td>
<td>205954</td>
<td>10867</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.26%</td>
<td>0.00%</td>
<td>28</td>
<td>1</td>
<td>205980</td>
<td>10872</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.08%</td>
<td>0.00%</td>
<td>9</td>
<td>0</td>
<td>205981</td>
<td>10891</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.04%</td>
<td>0.00%</td>
<td>4</td>
<td>0</td>
<td>205981</td>
<td>10896</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.03%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>205981</td>
<td>10897</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.02%</td>
<td>0.00%</td>
<td>2</td>
<td>1</td>
<td>205980</td>
<td>10898</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.02%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>205981</td>
<td>10898</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>205981</td>
<td>10899</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>CMC</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>205981</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>10900</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>216881</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p></p><p>Please send an email to lxu@trustlook.com if you have any comments. Thanks.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK 病毒检测统计 2021-09]]></title><description><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210901_20210930.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210901_20210930.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong></li></ul>]]></description><link>https://blog.trustlook.com/virustotal-apk-bing-du-jian-ce-tong-ji-2021-09/</link><guid isPermaLink="false">61a5a4bd41be6904271945de</guid><category><![CDATA[杀毒引擎评测]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Tue, 30 Nov 2021 04:13:27 GMT</pubDate><content:encoded><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210901_20210930.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210901_20210930.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li>
<li><strong>TPR</strong>: True Positive Rate, 恶意样本检出率</li>
<li><strong>FPR</strong>: False Positive Rate, 良性样本误报率</li>
<li><strong>TP</strong>: True Positive, 正确检出为恶意样本的数量</li>
<li><strong>FP</strong>: False Positive, 误报为恶意样本的数量</li>
<li><strong>TN</strong>: True Negative, 正确检出为良性样本的数量</li>
<li><strong>FN</strong>: False Negative, 误报为良性样本的数量</li>
</ul>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>K7GW</td>
<td>99.73%</td>
<td>0.10%</td>
<td>10871</td>
<td>207</td>
<td>205774</td>
<td>29</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.65%</td>
<td>0.03%</td>
<td>10862</td>
<td>54</td>
<td>205927</td>
<td>38</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.61%</td>
<td>0.09%</td>
<td>10858</td>
<td>180</td>
<td>205801</td>
<td>42</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>98.89%</td>
<td>0.72%</td>
<td>10779</td>
<td>1484</td>
<td>204497</td>
<td>121</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.28%</td>
<td>0.06%</td>
<td>10712</td>
<td>132</td>
<td>205849</td>
<td>188</td>
</tr>
<tr>
<td>DrWeb</td>
<td>98.07%</td>
<td>0.09%</td>
<td>10690</td>
<td>182</td>
<td>205799</td>
<td>210</td>
</tr>
<tr>
<td>Avira</td>
<td>98.06%</td>
<td>0.01%</td>
<td>10688</td>
<td>14</td>
<td>205967</td>
<td>212</td>
</tr>
<tr>
<td>Trustlook</td>
<td>96.25%</td>
<td>0.00%</td>
<td>10491</td>
<td>10</td>
<td>205971</td>
<td>409</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>94.47%</td>
<td>0.02%</td>
<td>10297</td>
<td>31</td>
<td>205950</td>
<td>603</td>
</tr>
<tr>
<td>McAfee</td>
<td>94.14%</td>
<td>0.03%</td>
<td>10261</td>
<td>54</td>
<td>205927</td>
<td>639</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>93.65%</td>
<td>0.02%</td>
<td>10208</td>
<td>35</td>
<td>205946</td>
<td>692</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>92.50%</td>
<td>0.05%</td>
<td>10082</td>
<td>104</td>
<td>205877</td>
<td>818</td>
</tr>
<tr>
<td>Microsoft</td>
<td>90.21%</td>
<td>0.02%</td>
<td>9833</td>
<td>44</td>
<td>205937</td>
<td>1067</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>86.45%</td>
<td>0.03%</td>
<td>9423</td>
<td>56</td>
<td>205925</td>
<td>1477</td>
</tr>
<tr>
<td>Sophos</td>
<td>80.59%</td>
<td>0.01%</td>
<td>8784</td>
<td>25</td>
<td>205956</td>
<td>2116</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>76.53%</td>
<td>0.02%</td>
<td>8342</td>
<td>43</td>
<td>205938</td>
<td>2558</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>73.94%</td>
<td>2.69%</td>
<td>8059</td>
<td>5536</td>
<td>200445</td>
<td>2841</td>
</tr>
<tr>
<td>Cyren</td>
<td>68.58%</td>
<td>0.02%</td>
<td>7475</td>
<td>41</td>
<td>205940</td>
<td>3425</td>
</tr>
<tr>
<td>Tencent</td>
<td>67.96%</td>
<td>0.12%</td>
<td>7408</td>
<td>251</td>
<td>205730</td>
<td>3492</td>
</tr>
<tr>
<td>Symantec</td>
<td>66.94%</td>
<td>0.00%</td>
<td>7296</td>
<td>4</td>
<td>205977</td>
<td>3604</td>
</tr>
<tr>
<td>Alibaba</td>
<td>63.95%</td>
<td>0.00%</td>
<td>6971</td>
<td>8</td>
<td>205973</td>
<td>3929</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>63.48%</td>
<td>0.09%</td>
<td>6919</td>
<td>185</td>
<td>205796</td>
<td>3981</td>
</tr>
<tr>
<td>MAX</td>
<td>55.36%</td>
<td>0.00%</td>
<td>6034</td>
<td>4</td>
<td>205977</td>
<td>4866</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>48.06%</td>
<td>0.02%</td>
<td>5239</td>
<td>36</td>
<td>205945</td>
<td>5661</td>
</tr>
<tr>
<td>AVG</td>
<td>42.71%</td>
<td>0.02%</td>
<td>4655</td>
<td>31</td>
<td>205950</td>
<td>6245</td>
</tr>
<tr>
<td>Avast</td>
<td>42.56%</td>
<td>0.02%</td>
<td>4639</td>
<td>31</td>
<td>205950</td>
<td>6261</td>
</tr>
<tr>
<td>Comodo</td>
<td>28.25%</td>
<td>0.09%</td>
<td>3079</td>
<td>186</td>
<td>205795</td>
<td>7821</td>
</tr>
<tr>
<td>Zillya</td>
<td>26.37%</td>
<td>0.08%</td>
<td>2874</td>
<td>157</td>
<td>205824</td>
<td>8026</td>
</tr>
<tr>
<td>GData</td>
<td>16.16%</td>
<td>0.00%</td>
<td>1761</td>
<td>1</td>
<td>205980</td>
<td>9139</td>
</tr>
<tr>
<td>Yandex</td>
<td>14.40%</td>
<td>0.00%</td>
<td>1570</td>
<td>4</td>
<td>205977</td>
<td>9330</td>
</tr>
<tr>
<td>ClamAV</td>
<td>14.33%</td>
<td>0.08%</td>
<td>1562</td>
<td>174</td>
<td>205807</td>
<td>9338</td>
</tr>
<tr>
<td>BitDefender</td>
<td>14.19%</td>
<td>0.00%</td>
<td>1547</td>
<td>1</td>
<td>205980</td>
<td>9353</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>14.02%</td>
<td>0.00%</td>
<td>1528</td>
<td>0</td>
<td>205981</td>
<td>9372</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>11.43%</td>
<td>0.48%</td>
<td>1246</td>
<td>991</td>
<td>204990</td>
<td>9654</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>9.48%</td>
<td>0.01%</td>
<td>1033</td>
<td>27</td>
<td>205954</td>
<td>9867</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>9.45%</td>
<td>0.00%</td>
<td>1030</td>
<td>0</td>
<td>205981</td>
<td>9870</td>
</tr>
<tr>
<td>F-Secure</td>
<td>9.39%</td>
<td>0.00%</td>
<td>1024</td>
<td>1</td>
<td>205980</td>
<td>9876</td>
</tr>
<tr>
<td>Arcabit</td>
<td>8.06%</td>
<td>0.00%</td>
<td>879</td>
<td>1</td>
<td>205980</td>
<td>10021</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>4.09%</td>
<td>0.00%</td>
<td>446</td>
<td>0</td>
<td>205981</td>
<td>10454</td>
</tr>
<tr>
<td>Zoner</td>
<td>4.08%</td>
<td>0.00%</td>
<td>445</td>
<td>8</td>
<td>205973</td>
<td>10455</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>3.80%</td>
<td>0.02%</td>
<td>414</td>
<td>36</td>
<td>205945</td>
<td>10486</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>3.25%</td>
<td>0.03%</td>
<td>354</td>
<td>65</td>
<td>205916</td>
<td>10546</td>
</tr>
<tr>
<td>Rising</td>
<td>1.98%</td>
<td>0.01%</td>
<td>216</td>
<td>14</td>
<td>205967</td>
<td>10684</td>
</tr>
<tr>
<td>VBA32</td>
<td>0.94%</td>
<td>0.01%</td>
<td>103</td>
<td>28</td>
<td>205953</td>
<td>10797</td>
</tr>
<tr>
<td>Panda</td>
<td>0.58%</td>
<td>0.00%</td>
<td>63</td>
<td>1</td>
<td>205980</td>
<td>10837</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.30%</td>
<td>0.01%</td>
<td>33</td>
<td>27</td>
<td>205954</td>
<td>10867</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.26%</td>
<td>0.00%</td>
<td>28</td>
<td>1</td>
<td>205980</td>
<td>10872</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.08%</td>
<td>0.00%</td>
<td>9</td>
<td>0</td>
<td>205981</td>
<td>10891</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.04%</td>
<td>0.00%</td>
<td>4</td>
<td>0</td>
<td>205981</td>
<td>10896</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.03%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>205981</td>
<td>10897</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.02%</td>
<td>0.00%</td>
<td>2</td>
<td>1</td>
<td>205980</td>
<td>10898</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.02%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>205981</td>
<td>10898</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>205981</td>
<td>10899</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>CMC</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Babable</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>205981</td>
<td>10900</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>205981</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>10900</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>216881</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>如有任何疑问, 欢迎随时邮件联系 lxu@trustlook.com. 谢谢.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK 病毒检测统计 2021-08]]></title><description><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210801_20210831.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210801_20210831.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong></li></ul>]]></description><link>https://blog.trustlook.com/virustotal-apk-bing-du-jian-ce-tong-ji-2021-08/</link><guid isPermaLink="false">614251c641be6904271945b8</guid><category><![CDATA[杀毒引擎评测]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Wed, 15 Sep 2021 20:05:16 GMT</pubDate><content:encoded><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210801_20210831.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210801_20210831.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li>
<li><strong>TPR</strong>: True Positive Rate, 恶意样本检出率</li>
<li><strong>FPR</strong>: False Positive Rate, 良性样本误报率</li>
<li><strong>TP</strong>: True Positive, 正确检出为恶意样本的数量</li>
<li><strong>FP</strong>: False Positive, 误报为恶意样本的数量</li>
<li><strong>TN</strong>: True Negative, 正确检出为良性样本的数量</li>
<li><strong>FN</strong>: False Negative, 误报为良性样本的数量</li>
</ul>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>ESET-NOD32</td>
<td>99.52%</td>
<td>0.03%</td>
<td>17282</td>
<td>322</td>
<td>1025420</td>
<td>83</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.50%</td>
<td>0.03%</td>
<td>17279</td>
<td>310</td>
<td>1025432</td>
<td>86</td>
</tr>
<tr>
<td>K7GW</td>
<td>98.89%</td>
<td>0.10%</td>
<td>17173</td>
<td>1063</td>
<td>1024679</td>
<td>192</td>
</tr>
<tr>
<td>Avira</td>
<td>98.63%</td>
<td>0.00%</td>
<td>17127</td>
<td>42</td>
<td>1025700</td>
<td>238</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.46%</td>
<td>0.06%</td>
<td>17098</td>
<td>565</td>
<td>1025177</td>
<td>267</td>
</tr>
<tr>
<td>Trustlook</td>
<td>97.54%</td>
<td>0.04%</td>
<td>16938</td>
<td>459</td>
<td>1025283</td>
<td>427</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>97.24%</td>
<td>0.24%</td>
<td>16885</td>
<td>2504</td>
<td>1023238</td>
<td>480</td>
</tr>
<tr>
<td>DrWeb</td>
<td>96.17%</td>
<td>0.15%</td>
<td>16700</td>
<td>1521</td>
<td>1024221</td>
<td>665</td>
</tr>
<tr>
<td>McAfee</td>
<td>95.53%</td>
<td>0.01%</td>
<td>16588</td>
<td>67</td>
<td>1025675</td>
<td>777</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>92.73%</td>
<td>0.02%</td>
<td>16102</td>
<td>217</td>
<td>1025525</td>
<td>1263</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>92.31%</td>
<td>0.02%</td>
<td>16030</td>
<td>209</td>
<td>1025533</td>
<td>1335</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>92.02%</td>
<td>0.00%</td>
<td>15979</td>
<td>41</td>
<td>1025701</td>
<td>1386</td>
</tr>
<tr>
<td>Microsoft</td>
<td>88.21%</td>
<td>0.03%</td>
<td>15318</td>
<td>292</td>
<td>1025450</td>
<td>2047</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>86.97%</td>
<td>0.02%</td>
<td>15102</td>
<td>177</td>
<td>1025565</td>
<td>2263</td>
</tr>
<tr>
<td>Sophos</td>
<td>81.46%</td>
<td>0.01%</td>
<td>14145</td>
<td>138</td>
<td>1025604</td>
<td>3220</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>79.31%</td>
<td>0.04%</td>
<td>13772</td>
<td>459</td>
<td>1025283</td>
<td>3593</td>
</tr>
<tr>
<td>Symantec</td>
<td>76.69%</td>
<td>0.03%</td>
<td>13318</td>
<td>315</td>
<td>1025427</td>
<td>4047</td>
</tr>
<tr>
<td>Cyren</td>
<td>75.97%</td>
<td>0.00%</td>
<td>13192</td>
<td>44</td>
<td>1025698</td>
<td>4173</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>72.74%</td>
<td>0.10%</td>
<td>12631</td>
<td>1069</td>
<td>1024673</td>
<td>4734</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>72.54%</td>
<td>4.63%</td>
<td>12596</td>
<td>47501</td>
<td>978241</td>
<td>4769</td>
</tr>
<tr>
<td>Alibaba</td>
<td>59.01%</td>
<td>0.01%</td>
<td>10247</td>
<td>70</td>
<td>1025672</td>
<td>7118</td>
</tr>
<tr>
<td>Tencent</td>
<td>54.87%</td>
<td>0.10%</td>
<td>9528</td>
<td>1069</td>
<td>1024673</td>
<td>7837</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>54.49%</td>
<td>0.01%</td>
<td>9462</td>
<td>106</td>
<td>1025636</td>
<td>7903</td>
</tr>
<tr>
<td>AVG</td>
<td>41.22%</td>
<td>0.02%</td>
<td>7158</td>
<td>158</td>
<td>1025584</td>
<td>10207</td>
</tr>
<tr>
<td>Avast</td>
<td>40.99%</td>
<td>0.02%</td>
<td>7118</td>
<td>158</td>
<td>1025584</td>
<td>10247</td>
</tr>
<tr>
<td>MAX</td>
<td>38.65%</td>
<td>0.00%</td>
<td>6712</td>
<td>34</td>
<td>1025708</td>
<td>10653</td>
</tr>
<tr>
<td>Comodo</td>
<td>33.20%</td>
<td>0.21%</td>
<td>5765</td>
<td>2113</td>
<td>1023629</td>
<td>11600</td>
</tr>
<tr>
<td>Zillya</td>
<td>20.48%</td>
<td>0.08%</td>
<td>3557</td>
<td>771</td>
<td>1024971</td>
<td>13808</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>20.14%</td>
<td>1.12%</td>
<td>3497</td>
<td>11510</td>
<td>1014232</td>
<td>13868</td>
</tr>
<tr>
<td>ClamAV</td>
<td>17.33%</td>
<td>0.20%</td>
<td>3010</td>
<td>2005</td>
<td>1023737</td>
<td>14355</td>
</tr>
<tr>
<td>GData</td>
<td>13.41%</td>
<td>0.00%</td>
<td>2328</td>
<td>16</td>
<td>1025726</td>
<td>15037</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>12.53%</td>
<td>0.01%</td>
<td>2176</td>
<td>128</td>
<td>1025614</td>
<td>15189</td>
</tr>
<tr>
<td>Yandex</td>
<td>10.78%</td>
<td>0.00%</td>
<td>1872</td>
<td>20</td>
<td>1025722</td>
<td>15493</td>
</tr>
<tr>
<td>BitDefender</td>
<td>10.45%</td>
<td>0.00%</td>
<td>1814</td>
<td>13</td>
<td>1025729</td>
<td>15551</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>10.31%</td>
<td>0.00%</td>
<td>1790</td>
<td>15</td>
<td>1025727</td>
<td>15575</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>8.79%</td>
<td>0.07%</td>
<td>1527</td>
<td>765</td>
<td>1024977</td>
<td>15838</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>8.72%</td>
<td>0.04%</td>
<td>1515</td>
<td>370</td>
<td>1025372</td>
<td>15850</td>
</tr>
<tr>
<td>Rising</td>
<td>8.07%</td>
<td>0.02%</td>
<td>1402</td>
<td>175</td>
<td>1025567</td>
<td>15963</td>
</tr>
<tr>
<td>VBA32</td>
<td>7.66%</td>
<td>0.02%</td>
<td>1330</td>
<td>230</td>
<td>1025512</td>
<td>16035</td>
</tr>
<tr>
<td>F-Secure</td>
<td>6.59%</td>
<td>0.00%</td>
<td>1144</td>
<td>1</td>
<td>1025741</td>
<td>16221</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>6.38%</td>
<td>0.00%</td>
<td>1108</td>
<td>12</td>
<td>1025730</td>
<td>16257</td>
</tr>
<tr>
<td>Zoner</td>
<td>6.13%</td>
<td>0.01%</td>
<td>1065</td>
<td>89</td>
<td>1025653</td>
<td>16300</td>
</tr>
<tr>
<td>Arcabit</td>
<td>5.00%</td>
<td>0.00%</td>
<td>869</td>
<td>20</td>
<td>1025722</td>
<td>16496</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>3.33%</td>
<td>0.00%</td>
<td>579</td>
<td>11</td>
<td>1025731</td>
<td>16786</td>
</tr>
<tr>
<td>Panda</td>
<td>2.06%</td>
<td>0.00%</td>
<td>358</td>
<td>7</td>
<td>1025735</td>
<td>17007</td>
</tr>
<tr>
<td>Baidu</td>
<td>1.30%</td>
<td>0.01%</td>
<td>226</td>
<td>125</td>
<td>1025617</td>
<td>17139</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.98%</td>
<td>0.00%</td>
<td>170</td>
<td>31</td>
<td>1025711</td>
<td>17195</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.88%</td>
<td>0.00%</td>
<td>152</td>
<td>4</td>
<td>1025738</td>
<td>17213</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.44%</td>
<td>0.00%</td>
<td>77</td>
<td>1</td>
<td>1025741</td>
<td>17288</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.35%</td>
<td>0.00%</td>
<td>61</td>
<td>9</td>
<td>1025733</td>
<td>17304</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.29%</td>
<td>0.00%</td>
<td>50</td>
<td>0</td>
<td>1025742</td>
<td>17315</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.21%</td>
<td>0.00%</td>
<td>36</td>
<td>6</td>
<td>1025736</td>
<td>17329</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.21%</td>
<td>0.00%</td>
<td>36</td>
<td>0</td>
<td>1025742</td>
<td>17329</td>
</tr>
<tr>
<td>Babable</td>
<td>0.12%</td>
<td>0.02%</td>
<td>20</td>
<td>176</td>
<td>1025566</td>
<td>17345</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.05%</td>
<td>0.00%</td>
<td>8</td>
<td>0</td>
<td>1025742</td>
<td>17357</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.03%</td>
<td>0.00%</td>
<td>5</td>
<td>0</td>
<td>1025742</td>
<td>17360</td>
</tr>
<tr>
<td>CMC</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>1</td>
<td>1025741</td>
<td>17364</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>1025742</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>17365</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>1043107</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>如有任何疑问, 欢迎随时邮件联系 lxu@trustlook.com. 谢谢.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK Malware Detection Data 2021-08]]></title><description><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-malware-detection-data-2021-08/</link><guid isPermaLink="false">61424fa841be6904271945a8</guid><category><![CDATA[VirusTotal]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Wed, 15 Sep 2021 19:56:34 GMT</pubDate><content:encoded><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of live feed samples. Then we look at detection results from AV vendors and rate them by how many malware they have detected and how many benign samples they have misclassified. </p><p>We generate a CSV file recording the detection results everyday. In the CSV file, from left to right, the columns are MD5 hash of the APK, label where 1 means positive (malicious) and 0 means negative (benign), and one column for each vendor showing its detection results where 1 means positive and 0 means negative. </p><p>On a monthly basis, we publish the detection results and zip the CSV files to AWS S3. For this month, you can download the detection data from:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210801_20210831.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210801_20210831.zip</a></p><p>The monthly results are summarized in the table below and here is a simple explanation of the columns in the table:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: AV engine vendor</li>
<li><strong>TPR</strong>: True Positive Rate, percentage of positive (malware) samples being correctly classified as positive</li>
<li><strong>FPR</strong>: False Positive Rate, percentage of negative (goodware) samples being misclassified as positive</li>
<li><strong>TP</strong>: True Positive, number of positive (malware) samples being correctly classified as positive</li>
<li><strong>FP</strong>: False Positive, number of negative (goodware) samples being misclassified as positive</li>
<li><strong>TN</strong>: True Negative, number of negative (goodware) samples being correctly classified as negative</li>
<li><strong>FN</strong>: False Negative, number of positive (malware) samples being misclassified as negative</li>
</ul>
<!--kg-card-end: markdown--><p></p><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>ESET-NOD32</td>
<td>99.52%</td>
<td>0.03%</td>
<td>17282</td>
<td>322</td>
<td>1025420</td>
<td>83</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.50%</td>
<td>0.03%</td>
<td>17279</td>
<td>310</td>
<td>1025432</td>
<td>86</td>
</tr>
<tr>
<td>K7GW</td>
<td>98.89%</td>
<td>0.10%</td>
<td>17173</td>
<td>1063</td>
<td>1024679</td>
<td>192</td>
</tr>
<tr>
<td>Avira</td>
<td>98.63%</td>
<td>0.00%</td>
<td>17127</td>
<td>42</td>
<td>1025700</td>
<td>238</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.46%</td>
<td>0.06%</td>
<td>17098</td>
<td>565</td>
<td>1025177</td>
<td>267</td>
</tr>
<tr>
<td>Trustlook</td>
<td>97.54%</td>
<td>0.04%</td>
<td>16938</td>
<td>459</td>
<td>1025283</td>
<td>427</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>97.24%</td>
<td>0.24%</td>
<td>16885</td>
<td>2504</td>
<td>1023238</td>
<td>480</td>
</tr>
<tr>
<td>DrWeb</td>
<td>96.17%</td>
<td>0.15%</td>
<td>16700</td>
<td>1521</td>
<td>1024221</td>
<td>665</td>
</tr>
<tr>
<td>McAfee</td>
<td>95.53%</td>
<td>0.01%</td>
<td>16588</td>
<td>67</td>
<td>1025675</td>
<td>777</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>92.73%</td>
<td>0.02%</td>
<td>16102</td>
<td>217</td>
<td>1025525</td>
<td>1263</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>92.31%</td>
<td>0.02%</td>
<td>16030</td>
<td>209</td>
<td>1025533</td>
<td>1335</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>92.02%</td>
<td>0.00%</td>
<td>15979</td>
<td>41</td>
<td>1025701</td>
<td>1386</td>
</tr>
<tr>
<td>Microsoft</td>
<td>88.21%</td>
<td>0.03%</td>
<td>15318</td>
<td>292</td>
<td>1025450</td>
<td>2047</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>86.97%</td>
<td>0.02%</td>
<td>15102</td>
<td>177</td>
<td>1025565</td>
<td>2263</td>
</tr>
<tr>
<td>Sophos</td>
<td>81.46%</td>
<td>0.01%</td>
<td>14145</td>
<td>138</td>
<td>1025604</td>
<td>3220</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>79.31%</td>
<td>0.04%</td>
<td>13772</td>
<td>459</td>
<td>1025283</td>
<td>3593</td>
</tr>
<tr>
<td>Symantec</td>
<td>76.69%</td>
<td>0.03%</td>
<td>13318</td>
<td>315</td>
<td>1025427</td>
<td>4047</td>
</tr>
<tr>
<td>Cyren</td>
<td>75.97%</td>
<td>0.00%</td>
<td>13192</td>
<td>44</td>
<td>1025698</td>
<td>4173</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>72.74%</td>
<td>0.10%</td>
<td>12631</td>
<td>1069</td>
<td>1024673</td>
<td>4734</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>72.54%</td>
<td>4.63%</td>
<td>12596</td>
<td>47501</td>
<td>978241</td>
<td>4769</td>
</tr>
<tr>
<td>Alibaba</td>
<td>59.01%</td>
<td>0.01%</td>
<td>10247</td>
<td>70</td>
<td>1025672</td>
<td>7118</td>
</tr>
<tr>
<td>Tencent</td>
<td>54.87%</td>
<td>0.10%</td>
<td>9528</td>
<td>1069</td>
<td>1024673</td>
<td>7837</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>54.49%</td>
<td>0.01%</td>
<td>9462</td>
<td>106</td>
<td>1025636</td>
<td>7903</td>
</tr>
<tr>
<td>AVG</td>
<td>41.22%</td>
<td>0.02%</td>
<td>7158</td>
<td>158</td>
<td>1025584</td>
<td>10207</td>
</tr>
<tr>
<td>Avast</td>
<td>40.99%</td>
<td>0.02%</td>
<td>7118</td>
<td>158</td>
<td>1025584</td>
<td>10247</td>
</tr>
<tr>
<td>MAX</td>
<td>38.65%</td>
<td>0.00%</td>
<td>6712</td>
<td>34</td>
<td>1025708</td>
<td>10653</td>
</tr>
<tr>
<td>Comodo</td>
<td>33.20%</td>
<td>0.21%</td>
<td>5765</td>
<td>2113</td>
<td>1023629</td>
<td>11600</td>
</tr>
<tr>
<td>Zillya</td>
<td>20.48%</td>
<td>0.08%</td>
<td>3557</td>
<td>771</td>
<td>1024971</td>
<td>13808</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>20.14%</td>
<td>1.12%</td>
<td>3497</td>
<td>11510</td>
<td>1014232</td>
<td>13868</td>
</tr>
<tr>
<td>ClamAV</td>
<td>17.33%</td>
<td>0.20%</td>
<td>3010</td>
<td>2005</td>
<td>1023737</td>
<td>14355</td>
</tr>
<tr>
<td>GData</td>
<td>13.41%</td>
<td>0.00%</td>
<td>2328</td>
<td>16</td>
<td>1025726</td>
<td>15037</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>12.53%</td>
<td>0.01%</td>
<td>2176</td>
<td>128</td>
<td>1025614</td>
<td>15189</td>
</tr>
<tr>
<td>Yandex</td>
<td>10.78%</td>
<td>0.00%</td>
<td>1872</td>
<td>20</td>
<td>1025722</td>
<td>15493</td>
</tr>
<tr>
<td>BitDefender</td>
<td>10.45%</td>
<td>0.00%</td>
<td>1814</td>
<td>13</td>
<td>1025729</td>
<td>15551</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>10.31%</td>
<td>0.00%</td>
<td>1790</td>
<td>15</td>
<td>1025727</td>
<td>15575</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>8.79%</td>
<td>0.07%</td>
<td>1527</td>
<td>765</td>
<td>1024977</td>
<td>15838</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>8.72%</td>
<td>0.04%</td>
<td>1515</td>
<td>370</td>
<td>1025372</td>
<td>15850</td>
</tr>
<tr>
<td>Rising</td>
<td>8.07%</td>
<td>0.02%</td>
<td>1402</td>
<td>175</td>
<td>1025567</td>
<td>15963</td>
</tr>
<tr>
<td>VBA32</td>
<td>7.66%</td>
<td>0.02%</td>
<td>1330</td>
<td>230</td>
<td>1025512</td>
<td>16035</td>
</tr>
<tr>
<td>F-Secure</td>
<td>6.59%</td>
<td>0.00%</td>
<td>1144</td>
<td>1</td>
<td>1025741</td>
<td>16221</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>6.38%</td>
<td>0.00%</td>
<td>1108</td>
<td>12</td>
<td>1025730</td>
<td>16257</td>
</tr>
<tr>
<td>Zoner</td>
<td>6.13%</td>
<td>0.01%</td>
<td>1065</td>
<td>89</td>
<td>1025653</td>
<td>16300</td>
</tr>
<tr>
<td>Arcabit</td>
<td>5.00%</td>
<td>0.00%</td>
<td>869</td>
<td>20</td>
<td>1025722</td>
<td>16496</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>3.33%</td>
<td>0.00%</td>
<td>579</td>
<td>11</td>
<td>1025731</td>
<td>16786</td>
</tr>
<tr>
<td>Panda</td>
<td>2.06%</td>
<td>0.00%</td>
<td>358</td>
<td>7</td>
<td>1025735</td>
<td>17007</td>
</tr>
<tr>
<td>Baidu</td>
<td>1.30%</td>
<td>0.01%</td>
<td>226</td>
<td>125</td>
<td>1025617</td>
<td>17139</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.98%</td>
<td>0.00%</td>
<td>170</td>
<td>31</td>
<td>1025711</td>
<td>17195</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>0.88%</td>
<td>0.00%</td>
<td>152</td>
<td>4</td>
<td>1025738</td>
<td>17213</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.44%</td>
<td>0.00%</td>
<td>77</td>
<td>1</td>
<td>1025741</td>
<td>17288</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.35%</td>
<td>0.00%</td>
<td>61</td>
<td>9</td>
<td>1025733</td>
<td>17304</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.29%</td>
<td>0.00%</td>
<td>50</td>
<td>0</td>
<td>1025742</td>
<td>17315</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.21%</td>
<td>0.00%</td>
<td>36</td>
<td>6</td>
<td>1025736</td>
<td>17329</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.21%</td>
<td>0.00%</td>
<td>36</td>
<td>0</td>
<td>1025742</td>
<td>17329</td>
</tr>
<tr>
<td>Babable</td>
<td>0.12%</td>
<td>0.02%</td>
<td>20</td>
<td>176</td>
<td>1025566</td>
<td>17345</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.05%</td>
<td>0.00%</td>
<td>8</td>
<td>0</td>
<td>1025742</td>
<td>17357</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.03%</td>
<td>0.00%</td>
<td>5</td>
<td>0</td>
<td>1025742</td>
<td>17360</td>
</tr>
<tr>
<td>CMC</td>
<td>0.01%</td>
<td>0.00%</td>
<td>1</td>
<td>1</td>
<td>1025741</td>
<td>17364</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>1025742</td>
<td>17365</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>1025742</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>17365</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>1043107</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p></p><p>Please send an email to lxu@trustlook.com if you have any comments. Thanks.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK Malware Detection Data 2021-07]]></title><description><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-malware-detection-data-2021-07/</link><guid isPermaLink="false">611ecaa041be69042719459a</guid><category><![CDATA[VirusTotal]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Mon, 02 Aug 2021 21:18:00 GMT</pubDate><content:encoded><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of live feed samples. Then we look at detection results from AV vendors and rate them by how many malware they have detected and how many benign samples they have misclassified. </p><p>We generate a CSV file recording the detection results everyday. In the CSV file, from left to right, the columns are MD5 hash of the APK, label where 1 means positive (malicious) and 0 means negative (benign), and one column for each vendor showing its detection results where 1 means positive and 0 means negative. </p><p>On a monthly basis, we publish the detection results and zip the CSV files to AWS S3. For this month, you can download the detection data from:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210701_20210731.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210701_20210731.zip</a></p><p>The monthly results are summarized in the table below and here is a simple explanation of the columns in the table:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: AV engine vendor</li>
<li><strong>TPR</strong>: True Positive Rate, percentage of positive (malware) samples being correctly classified as positive</li>
<li><strong>FPR</strong>: False Positive Rate, percentage of negative (goodware) samples being misclassified as positive</li>
<li><strong>TP</strong>: True Positive, number of positive (malware) samples being correctly classified as positive</li>
<li><strong>FP</strong>: False Positive, number of negative (goodware) samples being misclassified as positive</li>
<li><strong>TN</strong>: True Negative, number of negative (goodware) samples being correctly classified as negative</li>
<li><strong>FN</strong>: False Negative, number of positive (malware) samples being misclassified as negative</li>
</ul>
<!--kg-card-end: markdown--><p></p><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>endor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>ESET-NOD32</td>
<td>99.62%</td>
<td>0.01%</td>
<td>23237</td>
<td>20</td>
<td>230432</td>
<td>88</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.31%</td>
<td>0.06%</td>
<td>23163</td>
<td>133</td>
<td>230319</td>
<td>162</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.25%</td>
<td>0.01%</td>
<td>23150</td>
<td>20</td>
<td>230432</td>
<td>175</td>
</tr>
<tr>
<td>Trustlook</td>
<td>99.22%</td>
<td>0.12%</td>
<td>23142</td>
<td>269</td>
<td>230183</td>
<td>183</td>
</tr>
<tr>
<td>Avira</td>
<td>98.24%</td>
<td>0.01%</td>
<td>22914</td>
<td>13</td>
<td>230439</td>
<td>411</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.20%</td>
<td>0.03%</td>
<td>22904</td>
<td>74</td>
<td>230378</td>
<td>421</td>
</tr>
<tr>
<td>DrWeb</td>
<td>97.48%</td>
<td>0.05%</td>
<td>22737</td>
<td>120</td>
<td>230332</td>
<td>588</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>96.55%</td>
<td>0.01%</td>
<td>22520</td>
<td>13</td>
<td>230439</td>
<td>805</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>96.21%</td>
<td>0.35%</td>
<td>22441</td>
<td>802</td>
<td>229650</td>
<td>884</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>94.41%</td>
<td>0.02%</td>
<td>22022</td>
<td>40</td>
<td>230412</td>
<td>1303</td>
</tr>
<tr>
<td>McAfee</td>
<td>93.53%</td>
<td>0.01%</td>
<td>21817</td>
<td>23</td>
<td>230429</td>
<td>1508</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>92.31%</td>
<td>0.02%</td>
<td>21531</td>
<td>44</td>
<td>230408</td>
<td>1794</td>
</tr>
<tr>
<td>Microsoft</td>
<td>88.28%</td>
<td>0.01%</td>
<td>20592</td>
<td>28</td>
<td>230424</td>
<td>2733</td>
</tr>
<tr>
<td>Sophos</td>
<td>87.70%</td>
<td>0.02%</td>
<td>20457</td>
<td>38</td>
<td>230414</td>
<td>2868</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>85.77%</td>
<td>0.01%</td>
<td>20007</td>
<td>30</td>
<td>230422</td>
<td>3318</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>81.11%</td>
<td>0.02%</td>
<td>18919</td>
<td>38</td>
<td>230414</td>
<td>4406</td>
</tr>
<tr>
<td>Cyren</td>
<td>79.37%</td>
<td>0.01%</td>
<td>18513</td>
<td>22</td>
<td>230430</td>
<td>4812</td>
</tr>
<tr>
<td>Symantec</td>
<td>72.24%</td>
<td>0.04%</td>
<td>16849</td>
<td>88</td>
<td>230364</td>
<td>6476</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>68.14%</td>
<td>3.41%</td>
<td>15893</td>
<td>7861</td>
<td>222591</td>
<td>7432</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>67.58%</td>
<td>0.18%</td>
<td>15763</td>
<td>423</td>
<td>230029</td>
<td>7562</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>57.52%</td>
<td>0.01%</td>
<td>13417</td>
<td>25</td>
<td>230427</td>
<td>9908</td>
</tr>
<tr>
<td>Alibaba</td>
<td>52.47%</td>
<td>0.01%</td>
<td>12239</td>
<td>16</td>
<td>230436</td>
<td>11086</td>
</tr>
<tr>
<td>Tencent</td>
<td>51.80%</td>
<td>0.26%</td>
<td>12083</td>
<td>595</td>
<td>229857</td>
<td>11242</td>
</tr>
<tr>
<td>AVG</td>
<td>37.98%</td>
<td>0.03%</td>
<td>8859</td>
<td>73</td>
<td>230379</td>
<td>14466</td>
</tr>
<tr>
<td>Avast</td>
<td>37.90%</td>
<td>0.03%</td>
<td>8841</td>
<td>72</td>
<td>230380</td>
<td>14484</td>
</tr>
<tr>
<td>MAX</td>
<td>37.87%</td>
<td>0.00%</td>
<td>8833</td>
<td>1</td>
<td>230451</td>
<td>14492</td>
</tr>
<tr>
<td>Zillya</td>
<td>24.93%</td>
<td>0.19%</td>
<td>5815</td>
<td>433</td>
<td>230019</td>
<td>17510</td>
</tr>
<tr>
<td>Comodo</td>
<td>24.16%</td>
<td>0.65%</td>
<td>5636</td>
<td>1497</td>
<td>228955</td>
<td>17689</td>
</tr>
<tr>
<td>ClamAV</td>
<td>16.59%</td>
<td>0.16%</td>
<td>3870</td>
<td>371</td>
<td>230081</td>
<td>19455</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>16.40%</td>
<td>0.02%</td>
<td>3825</td>
<td>57</td>
<td>230395</td>
<td>19500</td>
</tr>
<tr>
<td>AegisLab</td>
<td>12.40%</td>
<td>0.01%</td>
<td>2893</td>
<td>17</td>
<td>230435</td>
<td>20432</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>10.94%</td>
<td>0.95%</td>
<td>2551</td>
<td>2200</td>
<td>228252</td>
<td>20774</td>
</tr>
<tr>
<td>GData</td>
<td>9.11%</td>
<td>0.00%</td>
<td>2126</td>
<td>8</td>
<td>230444</td>
<td>21199</td>
</tr>
<tr>
<td>F-Secure</td>
<td>8.07%</td>
<td>0.00%</td>
<td>1883</td>
<td>3</td>
<td>230449</td>
<td>21442</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.72%</td>
<td>0.00%</td>
<td>1800</td>
<td>8</td>
<td>230444</td>
<td>21525</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>7.61%</td>
<td>0.00%</td>
<td>1776</td>
<td>8</td>
<td>230444</td>
<td>21549</td>
</tr>
<tr>
<td>Yandex</td>
<td>7.19%</td>
<td>0.01%</td>
<td>1678</td>
<td>14</td>
<td>230438</td>
<td>21647</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>6.02%</td>
<td>0.05%</td>
<td>1405</td>
<td>118</td>
<td>230334</td>
<td>21920</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>5.98%</td>
<td>0.06%</td>
<td>1394</td>
<td>133</td>
<td>230319</td>
<td>21931</td>
</tr>
<tr>
<td>Zoner</td>
<td>5.09%</td>
<td>0.02%</td>
<td>1188</td>
<td>39</td>
<td>230413</td>
<td>22137</td>
</tr>
<tr>
<td>Rising</td>
<td>4.71%</td>
<td>0.01%</td>
<td>1098</td>
<td>30</td>
<td>230422</td>
<td>22227</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>4.21%</td>
<td>0.00%</td>
<td>981</td>
<td>8</td>
<td>230444</td>
<td>22344</td>
</tr>
<tr>
<td>Arcabit</td>
<td>4.18%</td>
<td>0.01%</td>
<td>976</td>
<td>13</td>
<td>230439</td>
<td>22349</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>3.24%</td>
<td>0.03%</td>
<td>756</td>
<td>61</td>
<td>230391</td>
<td>22569</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.11%</td>
<td>0.03%</td>
<td>725</td>
<td>74</td>
<td>230378</td>
<td>22600</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>1.81%</td>
<td>0.00%</td>
<td>423</td>
<td>8</td>
<td>230444</td>
<td>22902</td>
</tr>
<tr>
<td>Panda</td>
<td>1.71%</td>
<td>0.00%</td>
<td>398</td>
<td>3</td>
<td>230449</td>
<td>22927</td>
</tr>
<tr>
<td>Baidu</td>
<td>1.30%</td>
<td>0.01%</td>
<td>304</td>
<td>22</td>
<td>230430</td>
<td>23021</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.94%</td>
<td>0.01%</td>
<td>220</td>
<td>14</td>
<td>230438</td>
<td>23105</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.32%</td>
<td>0.00%</td>
<td>74</td>
<td>3</td>
<td>230449</td>
<td>23251</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.27%</td>
<td>0.00%</td>
<td>62</td>
<td>2</td>
<td>230450</td>
<td>23263</td>
</tr>
<tr>
<td>Babable</td>
<td>0.25%</td>
<td>0.02%</td>
<td>59</td>
<td>49</td>
<td>230403</td>
<td>23266</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.24%</td>
<td>0.00%</td>
<td>56</td>
<td>0</td>
<td>230452</td>
<td>23269</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.08%</td>
<td>0.00%</td>
<td>19</td>
<td>0</td>
<td>230452</td>
<td>23306</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.08%</td>
<td>0.00%</td>
<td>18</td>
<td>0</td>
<td>230452</td>
<td>23307</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.04%</td>
<td>0.00%</td>
<td>10</td>
<td>0</td>
<td>230452</td>
<td>23315</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.01%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>230452</td>
<td>23322</td>
</tr>
<tr>
<td>CMC</td>
<td>0.01%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>230452</td>
<td>23323</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>230452</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>23325</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>253777</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p></p><p>Please send an email to lxu@trustlook.com if you have any comments. Thanks.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK 病毒检测统计 2021-07]]></title><description><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210701_20210731.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210701_20210731.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong></li></ul>]]></description><link>https://blog.trustlook.com/virustotal-apk-bing-du-jian-ce-tong-ji-2021-07/</link><guid isPermaLink="false">611ec9e941be69042719457f</guid><category><![CDATA[杀毒引擎评测]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Mon, 02 Aug 2021 21:15:00 GMT</pubDate><content:encoded><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每个月的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210701_20210731.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210701_20210731.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li>
<li><strong>TPR</strong>: True Positive Rate, 恶意样本检出率</li>
<li><strong>FPR</strong>: False Positive Rate, 良性样本误报率</li>
<li><strong>TP</strong>: True Positive, 正确检出为恶意样本的数量</li>
<li><strong>FP</strong>: False Positive, 误报为恶意样本的数量</li>
<li><strong>TN</strong>: True Negative, 正确检出为良性样本的数量</li>
<li><strong>FN</strong>: False Negative, 误报为良性样本的数量</li>
</ul>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>endor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>ESET-NOD32</td>
<td>99.62%</td>
<td>0.01%</td>
<td>23237</td>
<td>20</td>
<td>230432</td>
<td>88</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.31%</td>
<td>0.06%</td>
<td>23163</td>
<td>133</td>
<td>230319</td>
<td>162</td>
</tr>
<tr>
<td>Fortinet</td>
<td>99.25%</td>
<td>0.01%</td>
<td>23150</td>
<td>20</td>
<td>230432</td>
<td>175</td>
</tr>
<tr>
<td>Trustlook</td>
<td>99.22%</td>
<td>0.12%</td>
<td>23142</td>
<td>269</td>
<td>230183</td>
<td>183</td>
</tr>
<tr>
<td>Avira</td>
<td>98.24%</td>
<td>0.01%</td>
<td>22914</td>
<td>13</td>
<td>230439</td>
<td>411</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.20%</td>
<td>0.03%</td>
<td>22904</td>
<td>74</td>
<td>230378</td>
<td>421</td>
</tr>
<tr>
<td>DrWeb</td>
<td>97.48%</td>
<td>0.05%</td>
<td>22737</td>
<td>120</td>
<td>230332</td>
<td>588</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>96.55%</td>
<td>0.01%</td>
<td>22520</td>
<td>13</td>
<td>230439</td>
<td>805</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>96.21%</td>
<td>0.35%</td>
<td>22441</td>
<td>802</td>
<td>229650</td>
<td>884</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>94.41%</td>
<td>0.02%</td>
<td>22022</td>
<td>40</td>
<td>230412</td>
<td>1303</td>
</tr>
<tr>
<td>McAfee</td>
<td>93.53%</td>
<td>0.01%</td>
<td>21817</td>
<td>23</td>
<td>230429</td>
<td>1508</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>92.31%</td>
<td>0.02%</td>
<td>21531</td>
<td>44</td>
<td>230408</td>
<td>1794</td>
</tr>
<tr>
<td>Microsoft</td>
<td>88.28%</td>
<td>0.01%</td>
<td>20592</td>
<td>28</td>
<td>230424</td>
<td>2733</td>
</tr>
<tr>
<td>Sophos</td>
<td>87.70%</td>
<td>0.02%</td>
<td>20457</td>
<td>38</td>
<td>230414</td>
<td>2868</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>85.77%</td>
<td>0.01%</td>
<td>20007</td>
<td>30</td>
<td>230422</td>
<td>3318</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>81.11%</td>
<td>0.02%</td>
<td>18919</td>
<td>38</td>
<td>230414</td>
<td>4406</td>
</tr>
<tr>
<td>Cyren</td>
<td>79.37%</td>
<td>0.01%</td>
<td>18513</td>
<td>22</td>
<td>230430</td>
<td>4812</td>
</tr>
<tr>
<td>Symantec</td>
<td>72.24%</td>
<td>0.04%</td>
<td>16849</td>
<td>88</td>
<td>230364</td>
<td>6476</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>68.14%</td>
<td>3.41%</td>
<td>15893</td>
<td>7861</td>
<td>222591</td>
<td>7432</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>67.58%</td>
<td>0.18%</td>
<td>15763</td>
<td>423</td>
<td>230029</td>
<td>7562</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>57.52%</td>
<td>0.01%</td>
<td>13417</td>
<td>25</td>
<td>230427</td>
<td>9908</td>
</tr>
<tr>
<td>Alibaba</td>
<td>52.47%</td>
<td>0.01%</td>
<td>12239</td>
<td>16</td>
<td>230436</td>
<td>11086</td>
</tr>
<tr>
<td>Tencent</td>
<td>51.80%</td>
<td>0.26%</td>
<td>12083</td>
<td>595</td>
<td>229857</td>
<td>11242</td>
</tr>
<tr>
<td>AVG</td>
<td>37.98%</td>
<td>0.03%</td>
<td>8859</td>
<td>73</td>
<td>230379</td>
<td>14466</td>
</tr>
<tr>
<td>Avast</td>
<td>37.90%</td>
<td>0.03%</td>
<td>8841</td>
<td>72</td>
<td>230380</td>
<td>14484</td>
</tr>
<tr>
<td>MAX</td>
<td>37.87%</td>
<td>0.00%</td>
<td>8833</td>
<td>1</td>
<td>230451</td>
<td>14492</td>
</tr>
<tr>
<td>Zillya</td>
<td>24.93%</td>
<td>0.19%</td>
<td>5815</td>
<td>433</td>
<td>230019</td>
<td>17510</td>
</tr>
<tr>
<td>Comodo</td>
<td>24.16%</td>
<td>0.65%</td>
<td>5636</td>
<td>1497</td>
<td>228955</td>
<td>17689</td>
</tr>
<tr>
<td>ClamAV</td>
<td>16.59%</td>
<td>0.16%</td>
<td>3870</td>
<td>371</td>
<td>230081</td>
<td>19455</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>16.40%</td>
<td>0.02%</td>
<td>3825</td>
<td>57</td>
<td>230395</td>
<td>19500</td>
</tr>
<tr>
<td>AegisLab</td>
<td>12.40%</td>
<td>0.01%</td>
<td>2893</td>
<td>17</td>
<td>230435</td>
<td>20432</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>10.94%</td>
<td>0.95%</td>
<td>2551</td>
<td>2200</td>
<td>228252</td>
<td>20774</td>
</tr>
<tr>
<td>GData</td>
<td>9.11%</td>
<td>0.00%</td>
<td>2126</td>
<td>8</td>
<td>230444</td>
<td>21199</td>
</tr>
<tr>
<td>F-Secure</td>
<td>8.07%</td>
<td>0.00%</td>
<td>1883</td>
<td>3</td>
<td>230449</td>
<td>21442</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.72%</td>
<td>0.00%</td>
<td>1800</td>
<td>8</td>
<td>230444</td>
<td>21525</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>7.61%</td>
<td>0.00%</td>
<td>1776</td>
<td>8</td>
<td>230444</td>
<td>21549</td>
</tr>
<tr>
<td>Yandex</td>
<td>7.19%</td>
<td>0.01%</td>
<td>1678</td>
<td>14</td>
<td>230438</td>
<td>21647</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>6.02%</td>
<td>0.05%</td>
<td>1405</td>
<td>118</td>
<td>230334</td>
<td>21920</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>5.98%</td>
<td>0.06%</td>
<td>1394</td>
<td>133</td>
<td>230319</td>
<td>21931</td>
</tr>
<tr>
<td>Zoner</td>
<td>5.09%</td>
<td>0.02%</td>
<td>1188</td>
<td>39</td>
<td>230413</td>
<td>22137</td>
</tr>
<tr>
<td>Rising</td>
<td>4.71%</td>
<td>0.01%</td>
<td>1098</td>
<td>30</td>
<td>230422</td>
<td>22227</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>4.21%</td>
<td>0.00%</td>
<td>981</td>
<td>8</td>
<td>230444</td>
<td>22344</td>
</tr>
<tr>
<td>Arcabit</td>
<td>4.18%</td>
<td>0.01%</td>
<td>976</td>
<td>13</td>
<td>230439</td>
<td>22349</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>3.24%</td>
<td>0.03%</td>
<td>756</td>
<td>61</td>
<td>230391</td>
<td>22569</td>
</tr>
<tr>
<td>VBA32</td>
<td>3.11%</td>
<td>0.03%</td>
<td>725</td>
<td>74</td>
<td>230378</td>
<td>22600</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>1.81%</td>
<td>0.00%</td>
<td>423</td>
<td>8</td>
<td>230444</td>
<td>22902</td>
</tr>
<tr>
<td>Panda</td>
<td>1.71%</td>
<td>0.00%</td>
<td>398</td>
<td>3</td>
<td>230449</td>
<td>22927</td>
</tr>
<tr>
<td>Baidu</td>
<td>1.30%</td>
<td>0.01%</td>
<td>304</td>
<td>22</td>
<td>230430</td>
<td>23021</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.94%</td>
<td>0.01%</td>
<td>220</td>
<td>14</td>
<td>230438</td>
<td>23105</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.32%</td>
<td>0.00%</td>
<td>74</td>
<td>3</td>
<td>230449</td>
<td>23251</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.27%</td>
<td>0.00%</td>
<td>62</td>
<td>2</td>
<td>230450</td>
<td>23263</td>
</tr>
<tr>
<td>Babable</td>
<td>0.25%</td>
<td>0.02%</td>
<td>59</td>
<td>49</td>
<td>230403</td>
<td>23266</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.24%</td>
<td>0.00%</td>
<td>56</td>
<td>0</td>
<td>230452</td>
<td>23269</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.08%</td>
<td>0.00%</td>
<td>19</td>
<td>0</td>
<td>230452</td>
<td>23306</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.08%</td>
<td>0.00%</td>
<td>18</td>
<td>0</td>
<td>230452</td>
<td>23307</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.04%</td>
<td>0.00%</td>
<td>10</td>
<td>0</td>
<td>230452</td>
<td>23315</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.01%</td>
<td>0.00%</td>
<td>3</td>
<td>0</td>
<td>230452</td>
<td>23322</td>
</tr>
<tr>
<td>CMC</td>
<td>0.01%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>230452</td>
<td>23323</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>230452</td>
<td>23325</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>230452</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>23325</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>253777</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>如有任何疑问, 欢迎随时邮件联系 lxu@trustlook.com. 谢谢.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK Malware Detection Data -
 Week 29: 202100712-20210718]]></title><description><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-malware-detection-data-week-29-202100712-20210718/</link><guid isPermaLink="false">60ff5a7441be690427194554</guid><category><![CDATA[VirusTotal]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Tue, 27 Jul 2021 00:59:58 GMT</pubDate><content:encoded><![CDATA[<p>At Trustlook, we monitor live feed from VirusTotal (VT). On a daily basis, we collect APK samples from VT along with detection results from Anti-Virus (AV) vendors hosted on VT. Using a conservative labeling policy, we are able to select thousands of benign and malicious APK samples from millions of live feed samples. Then we look at detection results from AV vendors and rate them by how many malware they have detected and how many benign samples they have misclassified. </p><p>We generate a CSV file recording the detection results everyday. In the CSV file, from left to right, the columns are MD5 hash of the APK, label where 1 means positive (malicious) and 0 means negative (benign), and one column for each vendor showing its detection results where 1 means positive and 0 means negative. </p><p>On a weekly basis, we publish the detection results and zip the CSV files to AWS S3. For this week, you can download the detection data from:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210705_20210711.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210712_20210718.zip</a></p><p>The weekly results are summarized in the table below and here is a simple explanation of the columns in the table:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: AV engine vendor</li>
<li><strong>TPR</strong>: True Positive Rate, percentage of positive (malware) samples being correctly classified as positive</li>
<li><strong>FPR</strong>: False Positive Rate, percentage of negative (goodware) samples being misclassified as positive</li>
<li><strong>TP</strong>: True Positive, number of positive (malware) samples being correctly classified as positive</li>
<li><strong>FP</strong>: False Positive, number of negative (goodware) samples being misclassified as positive</li>
<li><strong>TN</strong>: True Negative, number of negative (goodware) samples being correctly classified as negative</li>
<li><strong>FN</strong>: False Negative, number of positive (malware) samples being misclassified as negative</li>
</ul>
<!--kg-card-end: markdown--><p></p><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>Fortinet</td>
<td>99.74%</td>
<td>0.01%</td>
<td>4178</td>
<td>2</td>
<td>30850</td>
<td>11</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.69%</td>
<td>0.01%</td>
<td>4176</td>
<td>3</td>
<td>30849</td>
<td>13</td>
</tr>
<tr>
<td>Avira</td>
<td>99.43%</td>
<td>0.00%</td>
<td>4165</td>
<td>1</td>
<td>30851</td>
<td>24</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.38%</td>
<td>0.06%</td>
<td>4163</td>
<td>17</td>
<td>30835</td>
<td>26</td>
</tr>
<tr>
<td>DrWeb</td>
<td>99.31%</td>
<td>0.08%</td>
<td>4160</td>
<td>24</td>
<td>30828</td>
<td>29</td>
</tr>
<tr>
<td>Trustlook</td>
<td>99.12%</td>
<td>0.17%</td>
<td>4152</td>
<td>52</td>
<td>30800</td>
<td>37</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.26%</td>
<td>0.01%</td>
<td>4116</td>
<td>4</td>
<td>30848</td>
<td>73</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>97.18%</td>
<td>0.01%</td>
<td>4071</td>
<td>2</td>
<td>30850</td>
<td>118</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>97.14%</td>
<td>0.27%</td>
<td>4069</td>
<td>84</td>
<td>30768</td>
<td>120</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>95.46%</td>
<td>0.03%</td>
<td>3999</td>
<td>10</td>
<td>30842</td>
<td>190</td>
</tr>
<tr>
<td>McAfee</td>
<td>91.55%</td>
<td>0.01%</td>
<td>3835</td>
<td>2</td>
<td>30850</td>
<td>354</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>91.05%</td>
<td>0.00%</td>
<td>3814</td>
<td>1</td>
<td>30851</td>
<td>375</td>
</tr>
<tr>
<td>Microsoft</td>
<td>88.66%</td>
<td>0.00%</td>
<td>3714</td>
<td>1</td>
<td>30851</td>
<td>475</td>
</tr>
<tr>
<td>Sophos</td>
<td>87.11%</td>
<td>0.02%</td>
<td>3649</td>
<td>7</td>
<td>30845</td>
<td>540</td>
</tr>
<tr>
<td>Cyren</td>
<td>82.88%</td>
<td>0.02%</td>
<td>3472</td>
<td>5</td>
<td>30847</td>
<td>717</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>81.69%</td>
<td>0.00%</td>
<td>3422</td>
<td>1</td>
<td>30851</td>
<td>767</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>80.00%</td>
<td>0.01%</td>
<td>3351</td>
<td>2</td>
<td>30850</td>
<td>838</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>70.83%</td>
<td>0.10%</td>
<td>2967</td>
<td>31</td>
<td>30821</td>
<td>1222</td>
</tr>
<tr>
<td>Symantec</td>
<td>54.69%</td>
<td>0.01%</td>
<td>2291</td>
<td>2</td>
<td>30850</td>
<td>1898</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>53.35%</td>
<td>0.01%</td>
<td>2235</td>
<td>3</td>
<td>30849</td>
<td>1954</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>46.93%</td>
<td>1.66%</td>
<td>1966</td>
<td>512</td>
<td>30340</td>
<td>2223</td>
</tr>
<tr>
<td>AVG</td>
<td>25.83%</td>
<td>0.03%</td>
<td>1082</td>
<td>9</td>
<td>30843</td>
<td>3107</td>
</tr>
<tr>
<td>Avast</td>
<td>25.81%</td>
<td>0.03%</td>
<td>1081</td>
<td>9</td>
<td>30843</td>
<td>3108</td>
</tr>
<tr>
<td>Alibaba</td>
<td>25.09%</td>
<td>0.01%</td>
<td>1051</td>
<td>2</td>
<td>30850</td>
<td>3138</td>
</tr>
<tr>
<td>MAX</td>
<td>23.56%</td>
<td>0.00%</td>
<td>987</td>
<td>0</td>
<td>30852</td>
<td>3202</td>
</tr>
<tr>
<td>Tencent</td>
<td>22.80%</td>
<td>0.03%</td>
<td>955</td>
<td>9</td>
<td>30843</td>
<td>3234</td>
</tr>
<tr>
<td>Comodo</td>
<td>21.20%</td>
<td>0.04%</td>
<td>888</td>
<td>11</td>
<td>30841</td>
<td>3301</td>
</tr>
<tr>
<td>Zillya</td>
<td>19.69%</td>
<td>0.07%</td>
<td>825</td>
<td>23</td>
<td>30829</td>
<td>3364</td>
</tr>
<tr>
<td>ClamAV</td>
<td>15.80%</td>
<td>0.06%</td>
<td>662</td>
<td>17</td>
<td>30835</td>
<td>3527</td>
</tr>
<tr>
<td>GData</td>
<td>9.95%</td>
<td>0.00%</td>
<td>417</td>
<td>0</td>
<td>30852</td>
<td>3772</td>
</tr>
<tr>
<td>Yandex</td>
<td>8.86%</td>
<td>0.01%</td>
<td>371</td>
<td>4</td>
<td>30848</td>
<td>3818</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>8.04%</td>
<td>0.00%</td>
<td>337</td>
<td>1</td>
<td>30851</td>
<td>3852</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.50%</td>
<td>0.00%</td>
<td>314</td>
<td>0</td>
<td>30852</td>
<td>3875</td>
</tr>
<tr>
<td>F-Secure</td>
<td>7.47%</td>
<td>0.00%</td>
<td>313</td>
<td>0</td>
<td>30852</td>
<td>3876</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>7.38%</td>
<td>0.00%</td>
<td>309</td>
<td>0</td>
<td>30852</td>
<td>3880</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>6.83%</td>
<td>0.46%</td>
<td>286</td>
<td>142</td>
<td>30710</td>
<td>3903</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>4.44%</td>
<td>0.00%</td>
<td>186</td>
<td>0</td>
<td>30852</td>
<td>4003</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>4.44%</td>
<td>0.02%</td>
<td>186</td>
<td>7</td>
<td>30845</td>
<td>4003</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>4.30%</td>
<td>0.04%</td>
<td>180</td>
<td>13</td>
<td>30839</td>
<td>4009</td>
</tr>
<tr>
<td>Arcabit</td>
<td>3.72%</td>
<td>0.00%</td>
<td>156</td>
<td>0</td>
<td>30852</td>
<td>4033</td>
</tr>
<tr>
<td>Rising</td>
<td>3.01%</td>
<td>0.01%</td>
<td>126</td>
<td>4</td>
<td>30848</td>
<td>4063</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>2.48%</td>
<td>0.00%</td>
<td>104</td>
<td>0</td>
<td>30852</td>
<td>4085</td>
</tr>
<tr>
<td>VBA32</td>
<td>2.12%</td>
<td>0.01%</td>
<td>89</td>
<td>3</td>
<td>30849</td>
<td>4100</td>
</tr>
<tr>
<td>Zoner</td>
<td>2.05%</td>
<td>0.00%</td>
<td>86</td>
<td>0</td>
<td>30852</td>
<td>4103</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>1.69%</td>
<td>0.06%</td>
<td>71</td>
<td>17</td>
<td>30835</td>
<td>4118</td>
</tr>
<tr>
<td>Panda</td>
<td>0.88%</td>
<td>0.00%</td>
<td>37</td>
<td>1</td>
<td>30851</td>
<td>4152</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.29%</td>
<td>0.00%</td>
<td>12</td>
<td>1</td>
<td>30851</td>
<td>4177</td>
</tr>
<tr>
<td>Babable</td>
<td>0.19%</td>
<td>0.01%</td>
<td>8</td>
<td>2</td>
<td>30850</td>
<td>4181</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.14%</td>
<td>0.00%</td>
<td>6</td>
<td>0</td>
<td>30852</td>
<td>4183</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.14%</td>
<td>0.00%</td>
<td>6</td>
<td>0</td>
<td>30852</td>
<td>4183</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.05%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>30852</td>
<td>4187</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.05%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>30852</td>
<td>4187</td>
</tr>
<tr>
<td>CMC</td>
<td>0.02%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>30852</td>
<td>4188</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.02%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>30852</td>
<td>4188</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>30852</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>4189</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>35041</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p></p><p>Please send an email to lxu@trustlook.com if you have any comments. Thanks.</p>]]></content:encoded></item><item><title><![CDATA[VirusTotal APK 病毒检测统计 - 第29周: 20210712-20210718]]></title><description><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每星期 7 天的的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210705_20210711.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210712_20210718.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果,</p>]]></description><link>https://blog.trustlook.com/virustotal-apk-bing-du-jian-ce-tong-ji-di-29zhou-20210712-20210718/</link><guid isPermaLink="false">60ff5a3a41be690427194547</guid><category><![CDATA[杀毒引擎评测]]></category><dc:creator><![CDATA[Lifan Xu]]></dc:creator><pubDate>Tue, 27 Jul 2021 00:59:06 GMT</pubDate><content:encoded><![CDATA[<p>VirusTotal (简称 VT), 是谷歌旗下一家免费提供可疑文件扫描服务的网站. VT 上有超过50家反病毒引擎提供实时扫描服务. 我们每天收集用户上传到 VT 的 APK 样本以及各家引擎的扫描结果, 并通过保守的策略筛选出数万的良性和恶意样本, 然后统计各家引擎的病毒检测结果.</p><p>每天, 我们会生成一个包含各家检测数据的 CSV 文件. 文件中会列出样本的 MD5 哈希值, 标签 (0 标示良性样本, 1 标示恶意样本), 以及各家的检测结果 (0 表示检测为良性样本, 1 表示检测为恶意样本). 每星期 7 天的的 CSV 文件会被打包并上传到亚马逊 AWS S3. 有兴趣的读者可以下载检验各家杀毒引擎的检测结果.</p><p>以下为检测结果的下载链接:</p><p><a href="https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210705_20210711.zip">https://virustotal-results.s3-us-west-1.amazonaws.com/VirusTotal_Results_20210712_20210718.zip</a></p><p>下面的表格列出了各家杀毒引擎的统计结果, 其中各列的含义如下:</p><!--kg-card-begin: markdown--><ul>
<li><strong>Vendor</strong>: 杀毒引擎厂商名称</li>
<li><strong>TPR</strong>: True Positive Rate, 恶意样本检出率</li>
<li><strong>FPR</strong>: False Positive Rate, 良性样本误报率</li>
<li><strong>TP</strong>: True Positive, 正确检出为恶意样本的数量</li>
<li><strong>FP</strong>: False Positive, 误报为恶意样本的数量</li>
<li><strong>TN</strong>: True Negative, 正确检出为良性样本的数量</li>
<li><strong>FN</strong>: False Negative, 误报为良性样本的数量</li>
</ul>
<!--kg-card-end: markdown--><!--kg-card-begin: markdown--><table>
<thead>
<tr>
<th>Vendor</th>
<th>TPR</th>
<th>FPR</th>
<th>TP</th>
<th>FP</th>
<th>TN</th>
<th>FN</th>
</tr>
</thead>
<tbody>
<tr>
<td>Fortinet</td>
<td>99.74%</td>
<td>0.01%</td>
<td>4178</td>
<td>2</td>
<td>30850</td>
<td>11</td>
</tr>
<tr>
<td>ESET-NOD32</td>
<td>99.69%</td>
<td>0.01%</td>
<td>4176</td>
<td>3</td>
<td>30849</td>
<td>13</td>
</tr>
<tr>
<td>Avira</td>
<td>99.43%</td>
<td>0.00%</td>
<td>4165</td>
<td>1</td>
<td>30851</td>
<td>24</td>
</tr>
<tr>
<td>K7GW</td>
<td>99.38%</td>
<td>0.06%</td>
<td>4163</td>
<td>17</td>
<td>30835</td>
<td>26</td>
</tr>
<tr>
<td>DrWeb</td>
<td>99.31%</td>
<td>0.08%</td>
<td>4160</td>
<td>24</td>
<td>30828</td>
<td>29</td>
</tr>
<tr>
<td>Trustlook</td>
<td>99.12%</td>
<td>0.17%</td>
<td>4152</td>
<td>52</td>
<td>30800</td>
<td>37</td>
</tr>
<tr>
<td>Ikarus</td>
<td>98.26%</td>
<td>0.01%</td>
<td>4116</td>
<td>4</td>
<td>30848</td>
<td>73</td>
</tr>
<tr>
<td>Kaspersky</td>
<td>97.18%</td>
<td>0.01%</td>
<td>4071</td>
<td>2</td>
<td>30850</td>
<td>118</td>
</tr>
<tr>
<td>Avast-Mobile</td>
<td>97.14%</td>
<td>0.27%</td>
<td>4069</td>
<td>84</td>
<td>30768</td>
<td>120</td>
</tr>
<tr>
<td>AhnLab-V3</td>
<td>95.46%</td>
<td>0.03%</td>
<td>3999</td>
<td>10</td>
<td>30842</td>
<td>190</td>
</tr>
<tr>
<td>McAfee</td>
<td>91.55%</td>
<td>0.01%</td>
<td>3835</td>
<td>2</td>
<td>30850</td>
<td>354</td>
</tr>
<tr>
<td>CAT-QuickHeal</td>
<td>91.05%</td>
<td>0.00%</td>
<td>3814</td>
<td>1</td>
<td>30851</td>
<td>375</td>
</tr>
<tr>
<td>Microsoft</td>
<td>88.66%</td>
<td>0.00%</td>
<td>3714</td>
<td>1</td>
<td>30851</td>
<td>475</td>
</tr>
<tr>
<td>Sophos</td>
<td>87.11%</td>
<td>0.02%</td>
<td>3649</td>
<td>7</td>
<td>30845</td>
<td>540</td>
</tr>
<tr>
<td>Cyren</td>
<td>82.88%</td>
<td>0.02%</td>
<td>3472</td>
<td>5</td>
<td>30847</td>
<td>717</td>
</tr>
<tr>
<td>McAfee-GW-Edition</td>
<td>81.69%</td>
<td>0.00%</td>
<td>3422</td>
<td>1</td>
<td>30851</td>
<td>767</td>
</tr>
<tr>
<td>NANO-Antivirus</td>
<td>80.00%</td>
<td>0.01%</td>
<td>3351</td>
<td>2</td>
<td>30850</td>
<td>838</td>
</tr>
<tr>
<td>Antiy-AVL</td>
<td>70.83%</td>
<td>0.10%</td>
<td>2967</td>
<td>31</td>
<td>30821</td>
<td>1222</td>
</tr>
<tr>
<td>Symantec</td>
<td>54.69%</td>
<td>0.01%</td>
<td>2291</td>
<td>2</td>
<td>30850</td>
<td>1898</td>
</tr>
<tr>
<td>ZoneAlarm</td>
<td>53.35%</td>
<td>0.01%</td>
<td>2235</td>
<td>3</td>
<td>30849</td>
<td>1954</td>
</tr>
<tr>
<td>SymantecMobileInsight</td>
<td>46.93%</td>
<td>1.66%</td>
<td>1966</td>
<td>512</td>
<td>30340</td>
<td>2223</td>
</tr>
<tr>
<td>AVG</td>
<td>25.83%</td>
<td>0.03%</td>
<td>1082</td>
<td>9</td>
<td>30843</td>
<td>3107</td>
</tr>
<tr>
<td>Avast</td>
<td>25.81%</td>
<td>0.03%</td>
<td>1081</td>
<td>9</td>
<td>30843</td>
<td>3108</td>
</tr>
<tr>
<td>Alibaba</td>
<td>25.09%</td>
<td>0.01%</td>
<td>1051</td>
<td>2</td>
<td>30850</td>
<td>3138</td>
</tr>
<tr>
<td>MAX</td>
<td>23.56%</td>
<td>0.00%</td>
<td>987</td>
<td>0</td>
<td>30852</td>
<td>3202</td>
</tr>
<tr>
<td>Tencent</td>
<td>22.80%</td>
<td>0.03%</td>
<td>955</td>
<td>9</td>
<td>30843</td>
<td>3234</td>
</tr>
<tr>
<td>Comodo</td>
<td>21.20%</td>
<td>0.04%</td>
<td>888</td>
<td>11</td>
<td>30841</td>
<td>3301</td>
</tr>
<tr>
<td>Zillya</td>
<td>19.69%</td>
<td>0.07%</td>
<td>825</td>
<td>23</td>
<td>30829</td>
<td>3364</td>
</tr>
<tr>
<td>ClamAV</td>
<td>15.80%</td>
<td>0.06%</td>
<td>662</td>
<td>17</td>
<td>30835</td>
<td>3527</td>
</tr>
<tr>
<td>GData</td>
<td>9.95%</td>
<td>0.00%</td>
<td>417</td>
<td>0</td>
<td>30852</td>
<td>3772</td>
</tr>
<tr>
<td>Yandex</td>
<td>8.86%</td>
<td>0.01%</td>
<td>371</td>
<td>4</td>
<td>30848</td>
<td>3818</td>
</tr>
<tr>
<td>Kingsoft</td>
<td>8.04%</td>
<td>0.00%</td>
<td>337</td>
<td>1</td>
<td>30851</td>
<td>3852</td>
</tr>
<tr>
<td>BitDefender</td>
<td>7.50%</td>
<td>0.00%</td>
<td>314</td>
<td>0</td>
<td>30852</td>
<td>3875</td>
</tr>
<tr>
<td>F-Secure</td>
<td>7.47%</td>
<td>0.00%</td>
<td>313</td>
<td>0</td>
<td>30852</td>
<td>3876</td>
</tr>
<tr>
<td>Emsisoft</td>
<td>7.38%</td>
<td>0.00%</td>
<td>309</td>
<td>0</td>
<td>30852</td>
<td>3880</td>
</tr>
<tr>
<td>Jiangmin</td>
<td>6.83%</td>
<td>0.46%</td>
<td>286</td>
<td>142</td>
<td>30710</td>
<td>3903</td>
</tr>
<tr>
<td>MicroWorld-eScan</td>
<td>4.44%</td>
<td>0.00%</td>
<td>186</td>
<td>0</td>
<td>30852</td>
<td>4003</td>
</tr>
<tr>
<td>TrendMicro-HouseCall</td>
<td>4.44%</td>
<td>0.02%</td>
<td>186</td>
<td>7</td>
<td>30845</td>
<td>4003</td>
</tr>
<tr>
<td>TrendMicro</td>
<td>4.30%</td>
<td>0.04%</td>
<td>180</td>
<td>13</td>
<td>30839</td>
<td>4009</td>
</tr>
<tr>
<td>Arcabit</td>
<td>3.72%</td>
<td>0.00%</td>
<td>156</td>
<td>0</td>
<td>30852</td>
<td>4033</td>
</tr>
<tr>
<td>Rising</td>
<td>3.01%</td>
<td>0.01%</td>
<td>126</td>
<td>4</td>
<td>30848</td>
<td>4063</td>
</tr>
<tr>
<td>Ad-Aware</td>
<td>2.48%</td>
<td>0.00%</td>
<td>104</td>
<td>0</td>
<td>30852</td>
<td>4085</td>
</tr>
<tr>
<td>VBA32</td>
<td>2.12%</td>
<td>0.01%</td>
<td>89</td>
<td>3</td>
<td>30849</td>
<td>4100</td>
</tr>
<tr>
<td>Zoner</td>
<td>2.05%</td>
<td>0.00%</td>
<td>86</td>
<td>0</td>
<td>30852</td>
<td>4103</td>
</tr>
<tr>
<td>Qihoo-360</td>
<td>1.69%</td>
<td>0.06%</td>
<td>71</td>
<td>17</td>
<td>30835</td>
<td>4118</td>
</tr>
<tr>
<td>Panda</td>
<td>0.88%</td>
<td>0.00%</td>
<td>37</td>
<td>1</td>
<td>30851</td>
<td>4152</td>
</tr>
<tr>
<td>Baidu</td>
<td>0.29%</td>
<td>0.00%</td>
<td>12</td>
<td>1</td>
<td>30851</td>
<td>4177</td>
</tr>
<tr>
<td>Babable</td>
<td>0.19%</td>
<td>0.01%</td>
<td>8</td>
<td>2</td>
<td>30850</td>
<td>4181</td>
</tr>
<tr>
<td>ViRobot</td>
<td>0.14%</td>
<td>0.00%</td>
<td>6</td>
<td>0</td>
<td>30852</td>
<td>4183</td>
</tr>
<tr>
<td>SentinelOne</td>
<td>0.14%</td>
<td>0.00%</td>
<td>6</td>
<td>0</td>
<td>30852</td>
<td>4183</td>
</tr>
<tr>
<td>VIPRE</td>
<td>0.05%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>30852</td>
<td>4187</td>
</tr>
<tr>
<td>F-Prot</td>
<td>0.05%</td>
<td>0.00%</td>
<td>2</td>
<td>0</td>
<td>30852</td>
<td>4187</td>
</tr>
<tr>
<td>CMC</td>
<td>0.02%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>30852</td>
<td>4188</td>
</tr>
<tr>
<td>SUPERAntiSpyware</td>
<td>0.02%</td>
<td>0.00%</td>
<td>1</td>
<td>0</td>
<td>30852</td>
<td>4188</td>
</tr>
<tr>
<td>Bkav</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>TotalDefense</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>nProtect</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>ALYac</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Malwarebytes</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>CrowdStrike</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>K7AntiVirus</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>TheHacker</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>eScan</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Invincea</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Endgame</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>Webroot</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>AegisLab</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td>AVware</td>
<td>0.00%</td>
<td>0.00%</td>
<td>0</td>
<td>0</td>
<td>30852</td>
<td>4189</td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalGoodware</td>
<td>30852</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalMalware</td>
<td>4189</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
<tr>
<td>TotalSample</td>
<td>35041</td>
<td></td>
<td></td>
<td></td>
<td></td>
<td></td>
</tr>
</tbody>
</table>
<!--kg-card-end: markdown--><p>如有任何疑问, 欢迎随时邮件联系 lxu@trustlook.com. 谢谢.</p>]]></content:encoded></item></channel></rss>