VirusTotal has added a new signal that defenders should pay attention to: daily Internet scanning data tied directly to IP reports. Instead of only seeing reputation, passive DNS, and files that communicated with an address, analysts can now inspect what a host is exposing: open and recently closed ports, service banners, product and version details, protocol fingerprints, SSH and RDP identifiers, and port history.

That sounds like a product update, but the operational lesson is broader. For small businesses, MSPs, and government contractors, exposed-service metadata is becoming part of threat intelligence. An IP address is not just “good” or “bad.” It has a shape: ports, services, versions, certificates, banners, fingerprints, and timelines. That shape can help defenders find related infrastructure before it shows up in traditional reputation feeds.

What VirusTotal changed

In its new write-up, VirusTotal says IP reports now include daily public IPv4 scan results. Each port record can show whether the port is open, closed, or recently closed; when it was first seen; the detected protocol, product, and version; CPE data; raw banners; inferred operating system or device type; SSH/RDP fingerprints; and protocol-specific details such as HTTP headers or mail-server capabilities.

The “recently closed” view is especially useful. Infrastructure often disappears right when analysts start looking. Preserving the last-seen-open history helps answer questions such as when a command-and-control node went dark, whether an operator moved services to a new host, or whether a suspicious panel was briefly exposed during setup.

Why open ports alone are not enough

The article makes an important point: open ports by themselves are noisy. Searching for a default C2 port can return huge volumes of unrelated systems, including hosts that appear to answer on many ports. The useful signal is not simply “port 3389 is open” or “port 8443 is open.” The signal comes from what is behind the port.

Product names, versions, banners, certificates, fingerprints, and port-specific combinations narrow the field. A search for a single port may find millions of systems. A search that combines a web stack on one port, Windows SMB details on another, RDP exposure, and a distinctive page title can reduce that to a small set of candidates worth investigating.

The defender value: pivoting by infrastructure shape

VirusTotal walks through examples where analysts pivot from one suspicious host to others by reusing SSH host-key fingerprints, certificate subjects, service stacks, and port histories. That matters because attackers reuse infrastructure patterns. They clone servers, move panels, recycle certificates, stand up the same web stack, or expose the same remote-access services while changing domains and IPs.

For defenders, this creates a practical investigation path:

  • Start with one known indicator. This could be a suspicious IP, URL, phishing panel, malware callback, or domain.
  • Look at the exposed-service profile. Capture ports, products, versions, banners, certificates, SSH/RDP fingerprints, and first/last-seen dates.
  • Pivot on rare features. Shared SSH keys, unusual certificate subjects, uncommon banners, and port-specific product/version combinations are usually more useful than common ports alone.
  • Check prevalence before acting. A fingerprint shared by two or three hosts may be a lead. A fingerprint shared by a thousand hosts may be a vendor image, default router key, or cloud template.
  • Correlate with behavior. Exposure metadata should support investigation, not replace telemetry, logs, malware analysis, or human review.

Why SMBs and government contractors should care

Many smaller organizations do not run large threat-intelligence programs, but they still need to answer hard questions during incidents: What else belongs to this attacker? Did the infrastructure move? Was this host exposed before the alert? Are there sibling systems using the same panel or fingerprint? Is this just a noisy IP, or part of a managed cluster?

Government contractors also have a compliance and customer-trust angle. Incident response needs evidence. When an investigation involves suspicious remote access, credential theft, C2 callbacks, phishing infrastructure, or supplier compromise, exposed-service history can help reconstruct timelines and justify containment decisions.

This is not only useful against adversary infrastructure. The same mindset applies internally. If your organization exposes VPNs, RDP, SSH, mail gateways, file-transfer services, admin panels, developer systems, or OT gateways, attackers are building the same profile from the outside. Defenders should know their own exposure shape before someone else does.

Practical controls to implement

  • Build an external exposure inventory. Track every public IP, domain, cloud asset, VPN, RDP/SSH service, admin interface, and vendor-managed system tied to the organization.
  • Record service metadata, not just IPs. Store ports, product/version banners, certificate subjects, fingerprints, hosting providers, and first/last-seen dates.
  • Alert on unexpected exposure changes. New RDP, SSH, SMB, database, file-transfer, or admin-panel exposure should be investigated quickly, especially on cloud hosts and temporary project systems.
  • Use port-specific correlation. Do not rely on generic searches for “open 443” or “open 3389.” Correlate service product, version, certificate, banner, OS, and port together.
  • Treat remote-access exposure as high risk. Public RDP, exposed management consoles, unapproved SSH, and forgotten admin panels deserve faster review than ordinary web services.
  • Include exposure snapshots in incident response. When an indicator appears, preserve what the host exposed at that time. The port may close before legal, customer, or insurance review begins.
  • Review third-party and MSP infrastructure. Contractors often inherit exposure through vendors. Ask providers what externally reachable services support your environment and how changes are monitored.

Hunting ideas for defenders

Security teams can use the same approach in day-to-day hunting:

  • Look for suspicious panels on non-standard HTTPS ports paired with RDP or SMB exposure.
  • Pivot from known malicious IPs to hosts sharing rare SSH host keys, certificates, or service stacks.
  • Track recently closed ports after takedowns, incident response actions, or attacker infrastructure movement.
  • Compare known attacker infrastructure against newly registered domains and new cloud-hosted IPs.
  • Monitor whether your own assets expose stale versions, risky banners, or management services that should be behind VPN/ZTNA.

Bulwark Black assessment

The big takeaway is that infrastructure intelligence is moving from reputation-only lookups toward evidence-rich host profiling. That is good for defenders, but only if the data is used carefully. A shared fingerprint is a lead, not a conviction. A common port is noise until it is combined with service details. A “clean” reputation score may simply mean the infrastructure has not been connected to known malware yet.

For SMBs and government contractors, the practical move is simple: start treating exposed-service metadata as part of both threat hunting and asset management. Know what your own public footprint looks like. When investigating external infrastructure, pivot on rare, port-specific traits instead of isolated IPs. And when an incident happens, capture the exposure timeline before it disappears.

Original source: VirusTotal — “Internet Scanning in VirusTotal: hunting infrastructure by what it exposes”.