VirusTotal Favicon

VirusTotal

Industry-leading threat intelligence platform that analyzes files, URLs, and IP addresses using 70+ antivirus engines and threat detection systems.

OSINT Malware Detection Threat Intelligence URL Scanning

Overview

VirusTotal is a leading threat intelligence platform that aggregates the detection capabilities of over 70 antivirus engines, URL scanners, and threat intelligence systems to analyze suspicious files, URLs, IP addresses, and domains. Acquired by Google in 2012, VirusTotal provides a comprehensive service for malware detection, threat hunting, and security analysis. Users can upload files or submit URLs for analysis, receiving detailed reports with detection results from multiple security vendors, behavioral analysis, and community feedback. Key features include file hash lookup, URL scanning, domain intelligence, IP reputation checking, and VirusTotal Graph for visual threat analysis. The platform offers both a free web interface and a powerful API for automated threat intelligence integration, making it essential for SOC teams, incident responders, and security researchers. VirusTotal API v3 is now the default and encouraged way to programmatically interact with the platform, exposing richer data including IoC relationships, sandbox dynamic analysis, YARA Livehunt and Retrohunt management, and crowdsourced detection details. URL Scanning 2.0, launched in August 2026, significantly expands URL analysis capabilities by introducing automated visits with a full browser instance and deeper historical visibility. Instead of relying on static reputation scores alone, reports are enriched with headless browser telemetry including full-page screenshots, DOM trees, web technologies, and network request logs. Historical analysis pivoting allows analysts to track how a page has changed over time. The core enhancements are available to all users for the latest scan, while premium customers gain access to full historical analyses and advanced infrastructure relationships. VirusTotal continues to expand its Crowdsourced AI lineup, adding Knostic's AgentMesh in June 2026 to analyze Visual Studio Code extension (.VSIX) files for supply-chain threats. In February 2026, VirusTotal partnered with OpenClaw to analyze agent skills published on ClawHub, using Code Insight to automatically approve benign skills, warn on suspicious ones, and block malicious ones.

Primary Use Cases

✔ Analyzing suspicious files and hashes against 70+ antivirus engines for malware detection and threat scoring.
✔ Checking URL reputations and detecting phishing or malicious websites using headless browser telemetry and historical analysis.
✔ Investigating IP addresses and domains with historical threat intelligence and reputation data.
✔ Enriching security workflows through API v3 integration with IoC relationships, sandbox analysis, and YARA hunting capabilities.
✔ Analyzing Visual Studio Code extensions and AI agent skills for supply-chain threats using Crowdsourced AI contributors.
✔ Tracking how URLs change over time through historical analysis pivoting to identify evolving phishing campaigns and malicious infrastructure.

Frequently Asked Questions

VirusTotal is a threat intelligence platform acquired by Google that aggregates detection results from over 70 antivirus engines and security vendors to analyze files, URLs, IPs, and domains.

VirusTotal offers a free tier with limited uploads and API calls. Paid subscriptions are available for advanced features, higher rate limits, and enterprise use.

VirusTotal analyzes various file types including executables, documents, archives, and more, using multiple antivirus engines and behavioral analysis.

Yes, VirusTotal provides a powerful REST API for automated threat intelligence integration, file uploads, URL analysis, and IOC lookups.

VirusTotal is used to identify malware, check URL safety, investigate domain/IP reputations, and enrich IOCs with multi-vendor detection results.

Metadata

Official Website Visit Website
Category Info

Open Source Intelligence (OSINT) tools for gathering and analyzing publicly available information from various sources including websites, social media, DNS records, public databases, and other open data sources for security investigations and threat intelligence.

Added On

August 18, 2026

Last Updated

August 18, 2026

OSINT

Free, community-driven platform for sharing Indicators of Compromise (IOCs) related to malware infrastructure, enabling threat intelligence ...

OSINT

Industry-leading graphical link analysis and data visualization tool for OSINT investigations, enabling analysts to uncover hidden relations...

OSINT

Popular service for checking if email addresses or passwords have been exposed in data breaches, providing essential security intelligence.