VirusTotal
Analyze suspicious files, domains, IPs and URLs to detect malware and other breaches, automatically sharing them with the security community.
Analysis Engines
70+
Acquired by Google
2012
Public API Limit
500 requests/day
About VirusTotal
VirusTotal inspects items with over 70 antivirus scanners and URL/domain blacklisting services, in addition to a myriad of tools to extract signals from the studied content. Any user can select a file from their computer or enter a URL and have it analyzed. The platform provides a detailed report, showing results from each scanner. This service is widely used by security researchers, malware analysts, and end-users to verify the safety of files and links. Its powerful API allows developers and enterprises to integrate this threat intelligence directly into their own security products and workflows, automating threat detection. Originally an independent company, VirusTotal was acquired by Google in 2012 and is now part of Google Cloud's security offerings.
Core Analysis Capabilities
File Analysis
Upload and scan files against a vast database of antivirus engines.
Url Analysis
Scan URLs to detect phishing, malware, and other malicious content.
Ip & Domain Search
Investigate domains and IP addresses for malware-related information.
Hash Search
Search for file hashes (MD5, SHA-1, SHA-256) to retrieve existing reports.
API Tiers
Public Api
Free for non-commercial use with basic endpoints and strict rate limits.
Private Api
Paid enterprise-grade service with higher rate limits, premium features, and enriched data.
Access
Public API is self-serve. Private API requires contacting sales.