Get file reportLook up a file by its hash: how many of some seventy security vendors flag it and what they call it, its threat label, names, size and type, and when VirusTotal first saw it. A file VirusTotal has never seen is an answer, not an error: 'found' is false and the verdict unknown.
Get URL reportLook up a URL: how many security vendors flag it as phishing or malware, what they categorise it as, its page title and where it ends up after redirects. A URL VirusTotal has never scanned is an answer, not an error: 'found' is false.
Get domain reportLook up a domain: how many security vendors flag it, what they categorise it as, its registrar and age, and its current DNS records.
Get IP address reportLook up an IP address: how many security vendors flag it, and who runs it (network, autonomous system and country).
Scan fileUpload a file for some seventy antivirus engines to scan, and wait for the verdict. Files up to 650 MB. VirusTotal shares uploaded files with its security community, so don't scan anything confidential.
Scan URLSend a URL for some seventy security vendors to check for phishing and malware, and wait for the verdict. VirusTotal visits the URL and shares what it finds, so don't scan links with private tokens in them.
RescanHave every engine look again, with today's signatures, at a file, URL, domain or IP address VirusTotal already knows, and wait for the fresh verdict.
Get analysisSee where a scan stands, and its verdict once every engine has answered. Use it for a scan that was still running when its step stopped waiting.
SearchLook up a file hash, URL, domain or IP address in one step, each with its verdict, or find comments by tag. VirusTotal's free API searches by file hash only; the rest needs a premium key.
List commentsGet what VirusTotal's community wrote about a file, URL, domain or IP address, newest first.
Add commentPost a comment on a file, URL, domain or IP address for VirusTotal's community to see. Words starting with # become its tags.
Delete commentDelete one of your own comments. A comment that is already gone comes back with 'deleted' false instead of stopping the run.
List votesGet how VirusTotal's community voted on a file, URL, domain or IP address: harmless or malicious, newest first.
Add voteVote a file, URL, domain or IP address harmless or malicious. Voting the same way twice comes back with 'voted' false instead of stopping the run.
Get DNS resolutionsPassive DNS: the IP addresses a domain has pointed to, or the domains that have pointed to an IP address, newest first, with how many vendors flag each.
List subdomainsGet the subdomains VirusTotal has seen under a domain, with each one's verdict.
List communicating filesGet the files that contacted a domain or IP address when VirusTotal's sandboxes ran them, with each file's verdict: the quickest way to tell a malware server from an ordinary one.
Get file behaviourSee what a file did when VirusTotal's sandboxes ran it: the MITRE ATT&CK techniques it showed, the domains it looked up, the addresses and URLs it contacted, the processes and commands it ran, and the files and registry keys it changed. VirusTotal lists sandbox data among its premium features, so a free key may be refused.
Get API quotaSee how many requests the connected VirusTotal account has used today, this hour and this month, and how many it has left, before a run that makes many.