VirusTotal aggregates the verdicts of many antivirus engines and website scanners into a single picture and is listed in Google Cloud’s security catalog under threat intelligence.
What Is VirusTotal?
VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a myriad of tools that extract signals from the studied content. Any user can select a file from their computer using their browser and send it to VirusTotal.
Google Cloud lists VirusTotal in its official security catalog with the description “Unique visibility into threats” and names static threat indicators, behavior activity and network communications, and in-the-wild information as its characteristics.
Core Features
- Aggregated analysis: Over 70 antivirus engines, website scanners, and file and URL analysis tools, including heuristic engines, known-bad signatures, and metadata extraction
- Multiple submission methods: Web interface, desktop uploaders, browser extensions, and a programmatic API
- Detailed results: Per-engine detection labels rather than a plain yes/no verdict
- Real-time updates: Signatures are updated frequently; as soon as a contributor blocklists a URL, it is immediately reflected in user-facing verdicts
- VirusTotal Community: Users comment on files and URLs, share notes, and vote on whether content is harmful
Typical Use Cases
Check Suspicious Files and URLs
Submit through the web interface, a browser extension, or the API for analysis by the aggregated engines.
Identify False Positives
Per the documentation, VirusTotal is useful both in detecting malicious content and in identifying false positives — normal and harmless items detected as malicious by one or more scanners.
Automated Evaluation
Submissions and queries can be scripted in any programming language using the HTTP-based public API.
Benefits
- Broad coverage: Results from over 70 engines and numerous analysis tools in a single view
- Neutral aggregation: VirusTotal states that it does not distribute or promote any of the third-party engines it works with and simply acts as an aggregator
- Traceable detections: Display of engine-specific detection labels
- Community knowledge: Comments and votes deepen the collective understanding of potentially harmful content
Integration with innFactory
As a certified Google Cloud partner, innFactory supports you with VirusTotal: assessing use cases, connecting the API to your analysis workflows, and placing the results within your security architecture.
Typical Use Cases
Technical Specifications
Frequently Asked Questions
What is VirusTotal?
Per the official documentation, VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a myriad of tools to extract signals from the studied content. Google Cloud's security catalog lists VirusTotal with the description 'Unique visibility into threats'.
How are files and URLs submitted?
VirusTotal offers a number of file submission methods, including the primary public web interface, desktop uploaders, browser extensions, and a programmatic API. The web interface has the highest scanning priority among the publicly available submission methods. Submissions may be scripted in any programming language using the HTTP-based public API. URLs can likewise be submitted via the VirusTotal webpage, browser extensions, and the API.
Is VirusTotal free?
According to the documentation, VirusTotal is free to end users for non-commercial use in accordance with its Terms of Service. Beyond that, VirusTotal offers commercial premium services that provide qualified customers and antivirus partners with tools to perform complex criteria-based searches and access harmful file samples.
How detailed are the results?
VirusTotal not only tells you whether a given antivirus solution detected a submitted file as malicious, but also displays each engine's detection label, for example I-Worm.Allaple.gen. URL scanners mostly discriminate between malware sites, phishing sites, and suspicious sites; some engines additionally state whether a URL belongs to a particular botnet or which brand a phishing site targets.
What happens to submitted content?
Upon submitting a file or URL, basic results are shared with the submitter and also between the examining partners, who use results to improve their own systems. Scanning reports are shared with the public VirusTotal community. The contents of submitted files or pages may also be shared with premium VirusTotal customers.
Note: All product information on this page has been compiled with care, but is provided without guarantee and may be outdated or incomplete. Cloud services evolve rapidly — features, pricing, SLAs, and availability change frequently. Authoritative and up-to-date information can only be found on the official product page of Google Cloud (official documentation). This page does not represent an offer by Google Cloud.
