Virustotal
Yeah... no. I'm afraid you didn't realize that Virustotal in this case is more useful to malware authors than the end users; it's what they use to tweak their code until it's undetectable. I've known a group of people who used this over the years to collect literally tens of thousands of accounts from cheaters who would use the given mod/hack.
Virustotal is a good scanner for random files if you just want to check for known/old signatures. It is of absolutely no use for our case here.
Ideally, we could review the exploit's source code, if it's available. The alternative would be to reverse engineer it manually and check for suspicious code, but that can be a challenge in itself.