Threat intelligence · Google
Google VirusTotal
Aggregates verdicts from dozens of antivirus engines and blocklist services on submitted files and URLs, now operated by Google.
VirusTotal takes a file, URL, domain, or IP address a user submits and runs it against dozens of third-party antivirus engines and blocklist services simultaneously, then presents a consolidated verdict showing which vendors flagged it and why. Acquired by Google and operated within Google's security business, it also correlates submissions with metadata, behavioral sandbox reports, and relationship graphs between files, domains, and IPs. A significant, easily overlooked consideration: anything submitted through VirusTotal's standard scanning is shared with the wider security community and antivirus vendors, so it is not a private malware-analysis sandbox. Access ranges from a free Public API with strict rate limits, through Premium and Enterprise API tiers aimed at higher-volume, private, or intelligence-enriched use, all of which are quote-only rather than listed.
At a glance
| Vendor | |
|---|---|
| Pricing model | Free tier + paid plans |
| Free tier | Yes |
| Deployment | Cloud |
| Open source | No |
| Best for | Analysts wanting a fast, multi-engine second opinion on a suspicious file or URL, with the caveat that public submissions are shared with the community. |
Pricing
A free Public API with rate limits is open to anyone; Premium, Enterprise, and Intelligence tiers add higher quotas, private submissions, and enrichment but require a sales quote.
Pricing has not been verified yet — see the vendor's site.
Features
- Multi-engine antivirus and blocklist scanning of files, URLs, domains, and IPs
- Consolidated vendor-by-vendor verdict reports
- Relationship graphing between files, domains, and IPs
- Behavioral sandbox execution reports
- Free Public API with rate limits
- Premium/Enterprise API for higher-volume and private use
Profile last reviewed September 21, 2026