VirusTotal API v3
SkillFiles & storageVirusTotal API v3 reference. File, IP, domain, and URL analysis endpoints.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the VirusTotal API v3 skill
What this skill tells your AI
The instructions your AI receives, as published by liberty91ltd/cti-skills in skills/virustotal-api/SKILL.md and read by ahel’s review.
Base URL
https://www.virustotal.com/api/v3
Authentication
Header: x-apikey: $VIRUSTOTAL_API_KEY
Check for key: echo $VIRUSTOTAL_API_KEY
If empty, inform the user to run scripts/setup.sh or set the environment variable.
Rate Limits
- Free: 4 requests/minute, 500/day, 15.5K/month
- Premium: 1000 requests/minute
Key Endpoints
File Analysis
# Lookup by hash (MD5, SHA-1, SHA-256)
curl -s "https://www.virustotal.com/api/v3/files/{hash}" \
-H "x-apikey: $VIRUSTOTAL_API_KEY"
Useful response fields:
data.attributes.last_analysis_stats— detection counts (malicious, suspicious, undetected)data.attributes.popular_threat_classification— malware familydata.attributes.names— file namesdata.attributes.type_description— file typedata.attributes.size— file sizedata.attributes.tags— behavioral tagsdata.attributes.sandbox_verdicts— sandbox results
IP Address
curl -s "https://www.virustotal.com/api/v3/ip_addresses/{ip}" \
-H "x-apikey: $VIRUSTOTAL_API_KEY"
Useful fields: last_analysis_stats, as_owner, country, reputation, last_https_certificate
Relationships (communicating files, downloaded files, URLs):
curl -s "https://www.virustotal.com/api/v3/ip_addresses/{ip}/communicating_files?limit=10" \
-H "x-apikey: $VIRUSTOTAL_API_KEY"
Domain
curl -s "https://www.virustotal.com/api/v3/domains/{domain}" \
-H "x-apikey: $VIRUSTOTAL_API_KEY"
Useful fields: last_analysis_stats, registrar, creation_date, last_dns_records, reputation, categories
URL
URLs must be base64-encoded (without trailing =):
URL_ID=$(echo -n "https://example.com/path" | base64 | tr -d '=')
curl -s "https://www.virustotal.com/api/v3/urls/$URL_ID" \
-H "x-apikey: $VIRUSTOTAL_API_KEY"
Common Query Patterns
Quick reputation check (any indicator type)
Return a summary: detection ratio, community score, key context.
File behavior analysis
curl -s "https://www.virustotal.com/api/v3/files/{hash}/behaviours" \
-H "x-apikey: $VIRUSTOTAL_API_KEY"
Search for related indicators
curl -s "https://www.virustotal.com/api/v3/intelligence/search?query={query}" \
-H "x-apikey: $VIRUSTOTAL_API_KEY"
Note: Intelligence search requires premium API.
Response Summary Format
Return results as:
indicator: <value>
type: <ip|domain|hash|url>
detection_ratio: X/Y
community_score: <number>
verdict: malicious|suspicious|clean|unknown
key_findings:
- <finding 1>
- <finding 2>
raw_api_response: <truncated key fields>
Signals
- GitHub stars
- 22
- Forks
- 9
- Last commit
- Aug 2026
Advanced
- Catalog kind
- skill
- Gateway key
virustotal-api- Source
- github.com/liberty91ltd/cti-skills