Install any skill in seconds. Free to start, no credit card required.
Get Started Free →VirusTotal: check file/URL/domain/IP against 70+ AV engines
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-21 | ✗→✓ | ▲ Improved | 137% | 0% |
| case-01 | ✓→✓ | = Same ✓ | 67% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 11% | 0% |
| case-08 | ✓→✓ | = Same ✓ | 95% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 203% | 0% |
VirusTotal aggregates results from 70+ antivirus engines and threat intelligence feeds. Check file hashes, URLs, domains, and IP addresses for known malware, phishing, and suspicious activity.
Requires: VIRUSTOTAL_API_KEY — free at https://www.virustotal.com/gui/my-apikey (4 req/min on free tier).
powershell$hash = "44d88612fea8a8f36de82e1278abb02f" # EICAR test file $key = $env:VIRUSTOTAL_API_KEY $url = "https://www.virustotal.com/api/v3/files/$hash" $result = Invoke-RestMethod -Uri $url -Headers @{ "x-apikey" = $key } $stats = $result.data.attributes.last_analysis_stats Write-Host "File: $($result.data.attributes.meaningful_name)" Write-Host "Malicious: $($stats.malicious) / $($stats.malicious + $stats.undetected + $stats.harmless)" Write-Host "Suspicious: $($stats.suspicious)" Write-Host "First seen: $($result.data.attributes.first_submission_date)"
powershell$targetUrl = "https://example.com" $key = $env:VIRUSTOTAL_API_KEY # URL id = URL-safe base64 without padding $bytes = [System.Text.Encoding]::UTF8.GetBytes($targetUrl) $b64 = [Convert]::ToBase64String($bytes).Replace('+','-').Replace('/','_').TrimEnd('=') $url = "https://www.virustotal.com/api/v3/urls/$b64" $result = Invoke-RestMethod -Uri $url -Headers @{ "x-apikey" = $key } $stats = $result.data.attributes.last_analysis_stats Write-Host "URL: $targetUrl" Write-Host "Malicious: $($stats.malicious)" Write-Host "Phishing: $($result.data.attributes.categories -join ', ')" Write-Host "Reputation: $($result.data.attributes.reputation)"
powershell$domain = "example.com" $key = $env:VIRUSTOTAL_API_KEY $url = "https://www.virustotal.com/api/v3/domains/$domain" $result = Invoke-RestMethod -Uri $url -Headers @{ "x-apikey" = $key } $attrs = $result.data.attributes Write-Host "Domain: $domain" Write-Host "Reputation: $($attrs.reputation)" Write-Host "Categories: $($attrs.categories.PSObject.Properties.Value -join ', ')" $stats = $attrs.last_analysis_stats Write-Host "Malicious: $($stats.malicious) engines"
powershell$ip = "1.1.1.1" $key = $env:VIRUSTOTAL_API_KEY $url = "https://www.virustotal.com/api/v3/ip_addresses/$ip" $result = Invoke-RestMethod -Uri $url -Headers @{ "x-apikey" = $key } $attrs = $result.data.attributes $stats = $attrs.last_analysis_stats Write-Host "IP: $ip" Write-Host "AS Owner: $($attrs.as_owner)" Write-Host "Country: $($attrs.country)" Write-Host "Reputation: $($attrs.reputation)" Write-Host "Malicious: $($stats.malicious) engines"
"Is hash 44d88612fea8a8f36de82e1278abb02f malware?" → Use the file hash check — malicious count > 0 means confirmed threats.
"Check if https://suspicious-login.com is phishing" → Use the URL check — look at malicious and phishing categories.
"I got an alert for domain evil-c2.net — is it known bad?" → Use the domain check — look at reputation score and malicious engine count.
"This IP keeps hitting our firewall — is it a known attacker?" → Use the IP check — reputation < 0 and high malicious count = treat as threat.
Start-Sleep -Seconds 16 between calls when checking multiple IOCsVIRUSTOTAL_API_KEY — free account at https://www.virustotal.com/gui/join-usOther measured skills in the registry, with their headline benchmark lift.