Retrohunt allows you to scan all the files sent to VirusTotal in the past 12 months with your YARA rules (the 12 months limit applies to users of Hunting Pro, for standard users the limit is 3 months). A Retrohunt job scans a corpus of more than 420M files (~680TB worth of data) in 3-4 hours and reports you the files that matches your rules. However, the matches are limited to 10.000 per job. Also, you can scan a fixed and smaller corpus composed of about 1 million files that are known to be goodware, which is handy when you are testing your YARA rules, as it can help you to spot false-positives. These jobs usually finish in less than a minute.
Creating a Retrohunt job
1. On the homepage, click on the Hunting menu at the top of the screen or the corresponding icon in the toolbar, either option leads you to the same place:
2. Then click on the Retrohunt option on the left side menu, and then in Create your first retrohunt job.
3. A window will be opened with a text editor in which you can write your YARA rules and control its settings. The image below illustrates the usage of this window.
- YARA rules.
- Corpus that is going to be scanned with your rules.
- Notification email.
- Progress indicator.
- Job status: Starting, Running, Aborted or Finished.
- Number of matches found. Click on the number to see the files.
- Button to download list of matches.
- Cancel/Delete job.
- Number of additional matches that you would be able to see with Hunting Pro (i.e. matches on files that have been submitted to VirusTotal more than 3 months ago).