{"id":15008842,"url":"https://github.com/doomedraven/virustotalapi","last_synced_at":"2025-04-08T13:08:32.693Z","repository":{"id":44341055,"uuid":"43681383","full_name":"doomedraven/VirusTotalApi","owner":"doomedraven","description":"VirusTotal Full api","archived":false,"fork":false,"pushed_at":"2023-03-10T07:17:41.000Z","size":629,"stargazers_count":296,"open_issues_count":0,"forks_count":85,"subscribers_count":17,"default_branch":"master","last_synced_at":"2025-04-08T13:08:29.085Z","etag":null,"topics":["intelligence","malware-research","python2","python3","rest-client","virustotal"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/doomedraven.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":null,"funding":null,"license":"LICENSE.md","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null},"funding":{"custom":["https://paypal.me/brukhovetskyy"]}},"created_at":"2015-10-05T11:54:01.000Z","updated_at":"2025-04-07T16:00:21.000Z","dependencies_parsed_at":"2023-09-29T08:55:13.908Z","dependency_job_id":null,"html_url":"https://github.com/doomedraven/VirusTotalApi","commit_stats":{"total_commits":163,"total_committers":13,"mean_commits":"12.538461538461538","dds":0.5276073619631902,"last_synced_commit":"86f8590d80df8e76b6ccac671f25cce3ee00fbec"},"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/doomedraven%2FVirusTotalApi","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/doomedraven%2FVirusTotalApi/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/doomedraven%2FVirusTotalApi/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/doomedraven%2FVirusTotalApi/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/doomedraven","download_url":"https://codeload.github.com/doomedraven/VirusTotalApi/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247847611,"owners_count":21006100,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["intelligence","malware-research","python2","python3","rest-client","virustotal"],"created_at":"2024-09-24T19:20:55.583Z","updated_at":"2025-04-08T13:08:32.669Z","avatar_url":"https://github.com/doomedraven.png","language":"Python","funding_links":["https://paypal.me/brukhovetskyy"],"categories":[],"sub_categories":[],"readme":"VirusTotal public and private APIv2 Full support - VT APIv3\n===================\n\n* __My pypi VT package was transfered to VirusTotal ownership__\n\nBefore using the tool you must set your api key in one of this file or you can start without creating it and you will be prompted to provide the data:\n* Home Directory:\n    * __~.vtapi__, __~vtapi.conf__\n* or current directory where vt script placed\n    * __.vtapi__, __vtapi.conf__\n\n* ~.vtapi file content:\n```python\n[vt]\napikey=your-apikey-here\ntype=public\nintelligence=False\n#coma separated engine list, can be empty\nengines=\ntimeout=60\n# as for weblogin, this only required for rule management\nusername=\npassword=\n```\n* your type of api access, if private: type=private, if public, you can leave it empty, it will be automatically recognized as public\n* if you have access to VT Intelligence, you need set intelligence=True\n\n**Dependencies:**\n *  requests\n *  texttable\n *  python-dateutil\n\nThese can be installed via PIP or a package manager.\nExample of installing all dependencies using pip:\n```python\npip install -r requirements.txt\n```\n\n* Thanks to @kellewic and @urbanski\n* Special thanks to @Seifreed for testing and reporting bugs\n\n### Example of usage as library can be found [here](https://github.com/doomedraven/VirusTotalApi/wiki)\n\n\nFew public API functions taken from Chris Clark script\u003cbr /\u003e\nAnd finally has been added full public and private API support by Andriy Brukhovetskyy (doomedraven)\u003cbr /\u003e\n\n\nSmall manual with examples\nhttp://www.doomedraven.com/2013/11/script-virustotal-public-and-private.html\n\n* ___BEAR IN MIND THIS IS AN OLD EXAMPLE, use -h for current help___\n```\nvt -h\nusage: value [-h] [-fi] [-udb USERDB] [-fs] [-f] [-fr] [-u] [-ur] [-d] [-i]\n             [-w] [-s] [-si] [-et] [-rai] [-itu] [-cw] [-dep] [-eo] [-snr]\n             [-srct] [-tir] [-wir] [-rbgi] [-rbi] [-agi] [-dbc] [-ac] [-gc]\n             [--get-comments-before DATE] [-v] [-j] [--csv] [-rr] [-rj] [-V]\n             [-r] [--delete] [--date DATE] [--period PERIOD] [--repeat REPEAT]\n             [--notify-url NOTIFY_URL] [--notify-changes-only] [-wh] [-wht]\n             [-pdns] [--asn] [-aso] [--country] [--subdomains]\n             [--domain-siblings] [-cat] [-alc] [-alk] [-opi] [--drweb-cat]\n             [-adi] [-wdi] [-tm] [-wt] [-bd] [-wd] [-du] [--pcaps] [--samples]\n             [-dds] [-uds] [-dc] [-uc] [-drs] [-urs] [-pe]\n             [-esa SAVE_ATTACHMENT] [-peo] [-bh] [-bn] [-bp] [-bs] [-dl]\n             [-nm NAME] [-dt DOWNLOAD_THREADS] [--pcap] [--clusters]\n             [--distribution-files] [--distribution-urls] [--before BEFORE]\n             [--after AFTER] [--reports] [--limit LIMIT] [--allinfo] [--rules]\n             [--list] [--create FILE] [--update FILE] [--retro FILE]\n             [--delete_rule DELETE_RULE] [--share]\n             [--update_ruleset UPDATE_RULESET] [--disable DISABLE]\n             [--enable ENABLE]\n             [value [value ...]]\n\nScan/Search/ReScan/JSON parse\n\npositional arguments:\n  value                 Enter the Hash, Path to File(s) or Url(s)\n\noptional arguments:\n  -h, --help            show this help message and exit\n  -fi, --file-info      Get PE file info, all data extracted offline, for work\n                        you need have installed PEUTILS library\n  -udb USERDB, --userdb USERDB\n                        Path to your userdb file, works with --file-info\n                        option only\n  -fs, --file-search    File(s) search, this option, don't upload file to\n                        VirusTotal, just search by hash, support linux name\n                        wildcard, example: /home/user/*malware*, if file was\n                        scanned, you will see scan info, for full scan report\n                        use verbose mode, and dump if you want save already\n                        scanned samples\n  -f, --file-scan       File(s) scan, support linux name wildcard, example:\n                        /home/user/*malware*, if file was scanned, you will\n                        see scan info, for full scan report use verbose mode,\n                        and dump if you want save already scanned samples\n  -fr, --file-scan-recursive\n                        Recursive dir walk, use this instead of --file-scan if\n                        you want recursive\n  -u, --url-scan        Url scan, support space separated list, Max 4 urls (or\n                        25 if you have private api), but you can provide more\n                        urls, for example with public api, 5 url - this will\n                        do 2 requests first with 4 url and other one with only\n                        1, or you can specify file filename with one url per\n                        line\n  -ur, --url-report     Url(s) report, support space separated list, Max 4 (or\n                        25 if you have private api) urls, you can use --url-\n                        report --url-scan options for analyzing url(s) if they\n                        are not in VT data base, read preview description\n                        about more then max limits or file with urls\n  -d, --domain-info     Retrieves a report on a given domain (PRIVATE API\n                        ONLY! including the information recorded by\n                        VirusTotal's Passive DNS infrastructure)\n  -i, --ip-info         A valid IPv4 address in dotted quad notation, for the\n                        time being only IPv4 addresses are supported.\n  -w, --walk            Work with domain-info, will walk through all detected\n                        ips and get information, can be provided ip parameters\n                        to get only specific information\n  -s, --search          A md5/sha1/sha256 hash for which you want to retrieve\n                        the most recent report. You may also specify a scan_id\n                        (sha256-timestamp as returned by the scan API) to\n                        access a specific report. You can also specify a space\n                        separated list made up of a combination of hashes and\n                        scan_ids Public API up to 4 items/Private API up to 25\n                        items, this allows you to perform a batch request with\n                        one single call.\n  -si, --search-intelligence\n                        Search query, help can be found here -\n                        https://www.virustotal.com/intelligence/help/\n  -et, --email-template\n                        Table format template for email\n  -ac, --add-comment    The actual review, you can tag it using the \"#\"\n                        twitter-like syntax (e.g. #disinfection #zbot) and\n                        reference users using the \"@\" syntax (e.g.\n                        @VirusTotalTeam). supported hashes MD5/SHA1/SHA256\n  -gc, --get-comments   Either a md5/sha1/sha256 hash of the file or the URL\n                        itself you want to retrieve\n  --get-comments-before DATE\n                        A datetime token that allows you to iterate over all\n                        comments on a specific item whenever it has been\n                        commented on more than 25 times. Token format\n                        20120725170000 or 2012-07-25 17 00 00 or 2012-07-25\n                        17:00:00\n  -v, --verbose         Turn on verbosity of VT reports\n  -j, --dump            Dumps the full VT report to file (VTDL{md5}.json), if\n                        you (re)scan many files/urls, their json data will be\n                        dumped to separated files\n  --csv                 Dumps the AV's detections to file (VTDL{scan_id}.csv)\n  -rr, --return-raw     Return raw json, in case if used as library and want\n                        parse in other way\n  -rj, --return-json    Return json with parts activated, for example -p for\n                        passive dns, etc\n  -V, --version         Show version and exit\n\nAll information related:\n  -rai, --report-all-info\n                        If specified and set to one, the call will return\n                        additional info, other than the antivirus results, on\n                        the file being queried. This additional info includes\n                        the output of several tools acting on the file (PDFiD,\n                        ExifTool, sigcheck, TrID, etc.), metadata regarding\n                        VirusTotal submissions (number of unique sources that\n                        have sent the file in the past, first seen date, last\n                        seen date, etc.), and the output of in-house\n                        technologies such as a behavioural sandbox.\n  -itu, --ITW-urls      In the wild urls\n  -cw, --compressedview\n                        Contains information about extensions, file_types,\n                        tags, lowest and highest datetime, num children\n                        detected, type, uncompressed_size, vhash, children\n  -dep, --detailed-email-parents\n                        Contains information about emails, as Subject, sender,\n                        receiver(s), full email, and email hash to download it\n  -eo, --email-original\n                        Will retrieve original email and process it\n  -snr, --snort         Get Snort results\n  -srct, --suricata     Get Suricata results\n  -tir, --traffic-inspection\n                        Get Traffic inspection info\n  -wir, --wireshark-info\n                        Get Wireshark info\n  -rbgi, --rombios-generator-info\n                        Get RomBios generator info\n  -rbi, --rombioscheck-info\n                        Get RomBiosCheck info\n  -agi, --androidguard-info\n                        Get AndroidGuard info\n  -dbc, --debcheck-info\n                        Get DebCheck info, also include ios IPA\n\nRescan options:\n  -r, --rescan          Allows you to rescan files in VirusTotal's file store\n                        without having to resubmit them, thus saving\n                        bandwidth, support space separated list, MAX 25\n                        hashes, can be local files, hashes will be generated\n                        on the fly, support linux wildmask\n  --delete              A md5/sha1/sha256 hash for which you want to delete\n                        the scheduled scan\n  --date DATE           A Date in one of this formats (example: 20120725170000\n                        or 2012-07-25 17 00 00 or 2012-07-25 17:00:00) in\n                        which the rescan should be performed. If not specified\n                        the rescan will be performed immediately.\n  --period PERIOD       Period in days in which the file should be rescanned.\n                        If this argument is provided the file will be\n                        rescanned periodically every period days, if not, the\n                        rescan is performed once and not repeated again.\n  --repeat REPEAT       Used in conjunction with period to specify the number\n                        of times the file should be rescanned. If this\n                        argument is provided the file will be rescanned the\n                        given amount of times, if not, the file will be\n                        rescanned indefinitely.\n\nFile scan/Rescan shared options:\n  --notify-url NOTIFY_URL\n                        An URL where a POST notification should be sent when\n                        the scan finishes.\n  --notify-changes-only\n                        Used in conjunction with --notify-url. Indicates if\n                        POST notifications should be sent only if the scan\n                        results differ from the previous one.\n\nDomain/IP shared verbose mode options, by default just show resolved IPs/Passive DNS:\n  -wh, --whois          Whois data\n  -wht, --whois-timestamp\n                        Whois timestamp\n  -pdns, --resolutions  Passive DNS resolves\n  --asn                 ASN number\n  -aso, --as-owner      AS details\n  --country             Country\n  --subdomains          Subdomains\n  --domain-siblings     Domain siblings\n  -cat, --categories    Categories\n  -alc, --alexa-cat     Alexa category\n  -alk, --alexa-rank    Alexa rank\n  -opi, --opera-info    Opera info\n  --drweb-cat           Dr.Web Category\n  -adi, --alexa-domain-info\n                        Just Domain option: Show Alexa domain info\n  -wdi, --wot-domain-info\n                        Just Domain option: Show WOT domain info\n  -tm, --trendmicro     Just Domain option: Show TrendMicro category info\n  -wt, --websense-threatseeker\n                        Just Domain option: Show Websense ThreatSeeker\n                        category\n  -bd, --bitdefender    Just Domain option: Show BitDefender category\n  -wd, --webutation-domain\n                        Just Domain option: Show Webutation domain info\n  -du, --detected-urls  Just Domain option: Show latest detected URLs\n  --pcaps               Just Domain option: Show all pcaps hashes\n  --samples             Will activate -dds -uds -dc -uc -drs -urs\n  -dds, --detected-downloaded-samples\n                        Domain/Ip options: Show latest detected files that\n                        were downloaded from this ip\n  -uds, --undetected-downloaded-samples\n                        Domain/Ip options: Show latest undetected files that\n                        were downloaded from this domain/ip\n  -dc, --detected-communicated\n                        Domain/Ip Show latest detected files that communicate\n                        with this domain/ip\n  -uc, --undetected-communicated\n                        Domain/Ip Show latest undetected files that\n                        communicate with this domain/ip\n  -drs, --detected-referrer-samples\n                        Undetected referrer samples\n  -urs, --undetected-referrer-samples\n                        Undetected referrer samples\n\nProcess emails:\n  -pe, --parse-email    Parse email, can be string or file\n  -esa SAVE_ATTACHMENT, --save-attachment SAVE_ATTACHMENT\n                        Save email attachment, path where to store\n  -peo, --parse-email-outlook\n                        Parse outlook .msg, can be string or file\n\nBehaviour options:\n  -bh, --behaviour      The md5/sha1/sha256 hash of the file whose dynamic\n                        behavioural report you want to retrieve. VirusTotal\n                        runs a distributed setup of Cuckoo sandbox machines\n                        that execute the files we receive. Execution is\n                        attempted only once, upon first submission to\n                        VirusTotal, and only Portable Executables under 10MB\n                        in size are ran. The execution of files is a best\n                        effort process, hence, there are no guarantees about a\n                        report being generated for a given file in our\n                        dataset. a file did indeed produce a behavioural\n                        report, a summary of it can be obtained by using the\n                        file scan lookup call providing the additional HTTP\n                        POST parameter allinfo=1. The summary will appear\n                        under the behaviour-v1 property of the additional_info\n                        field in the JSON report.This API allows you to\n                        retrieve the full JSON report of the files execution\n                        as outputted by the Cuckoo JSON report encoder.\n  -bn, --behavior-network\n                        Show network activity\n  -bp, --behavior-process\n                        Show processes\n  -bs, --behavior-summary\n                        Show summary\n\nDownload options:\n  -dl, --download       The md5/sha1/sha256 hash of the file you want to\n                        download or txt file with .txt extension, with hashes,\n                        or hash and type, one by line, for example: hash,pcap\n                        or only hash. Will save with hash as name, can be\n                        space separated list of hashes to download\n  -nm NAME, --name NAME\n                        Name with which file will saved when download it\n  -dt DOWNLOAD_THREADS, --download-threads DOWNLOAD_THREADS\n                        Number of simultaneous downloaders\n\nAdditional options:\n  --pcap                The md5/sha1/sha256 hash of the file whose network\n                        traffic dump you want to retrieve. Will save as\n                        hash.pcap\n  --clusters            A specific day for which we want to access the\n                        clustering details, example: 2013-09-10\n  --distribution-files  Timestamps are just integer numbers where higher\n                        values mean more recent files. Both before and after\n                        parameters are optional, if they are not provided the\n                        oldest files in the queue are returned in timestamp\n                        ascending order.\n  --distribution-urls   Timestamps are just integer numbers where higher\n                        values mean more recent urls. Both before and after\n                        parameters are optional, if they are not provided the\n                        oldest urls in the queue are returned in timestamp\n                        ascending order.\n\nDistribution options:\n  --before BEFORE       File/Url option. Retrieve files/urls received before\n                        the given timestamp, in timestamp descending order.\n  --after AFTER         File/Url option. Retrieve files/urls received after\n                        the given timestamp, in timestamp ascending order.\n  --reports             Include the files' antivirus results in the response.\n                        Possible values are 'true' or 'false' (default value\n                        is 'false').\n  --limit LIMIT         File/Url option. Retrieve limit file items at most\n                        (default: 1000).\n  --allinfo             will include the results for each particular URL scan\n                        (in exactly the same format as the URL scan retrieving\n                        API). If the parameter is not specified, each item\n                        returned will only contain the scanned URL and its\n                        detection ratio.\n\nRules management options:\n  --rules               Manage VTI hunting rules, REQUIRED for rules management\n  --list                List names/ids of Yara rules stored on VT\n  --create FILE         Add a Yara rule to VT (File Name used as RuleName\n  --update FILE         Update a Yara rule on VT (File Name used as RuleName\n                        and must include RuleName\n  --retro FILE          Submit Yara rule to VT RetroHunt (File Name used as\n                        RuleName and must include RuleName\n  --delete_rule DELETE_RULE\n                        Delete a Yara rule from VT (By Name)\n  --share               Shares rule with user\n  --update_ruleset UPDATE_RULESET\n                        Ruleset name to update\n  --disable DISABLE     Disable a Yara rule from VT (By Name)\n  --enable ENABLE       Enable a Yara rule from VT (By Name)\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdoomedraven%2Fvirustotalapi","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fdoomedraven%2Fvirustotalapi","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fdoomedraven%2Fvirustotalapi/lists"}