GDE-025 |
VirusTotal OSINT | |||||||
Digital infrastructure | ||||||||
August 2026 | ||||||||
GDE-025 |
VirusTotal OSINT | |||||||
Digital infrastructure | ||||||||
September 2026 | ||||||||
VirusTotal aggregates verdicts from more than 70 antivirus and security engines alongside community votes, passive DNS history and WHOIS data, all queryable through one interface. Owned by Google, it has become the default first stop for checking a suspicious file, link or piece of infrastructure before deciding whether it warrants further investigation.
The workflow pairs naturally with domain and infrastructure investigation: a malicious IP or domain surfaced through VirusTotal becomes a pivot point into related infrastructure via passive DNS, the same expansion technique used in WHOIS and Shodan-based investigations.
|
When to use this guide
|
02
How do you use VirusTotal for OSINT investigations?
This section covers the tools and sequence for checking indicators and reading the results correctly.
Four tools cover VirusTotal OSINT from a single hash lookup through to full sandbox detonation, free tools first.
VirusTotal: Free web lookup, no login for a single search; free API (500 requests a day, 4 a minute) requires a free account, and the unlimited Premium API is paid. Aggregates 70-plus antivirus engines plus community votes, passive DNS, WHOIS and relationship data for files, URLs, domains and IPs.
urlscan.io: Free, no login for a public scan. Renders the destination page in a sandbox and returns a screenshot, DOM snapshot and the full list of contacted domains and IPs, useful when a link is too new for VirusTotal's engines to have a verdict yet. Public scans are visible to other users; a paid tier adds private scanning.
AbuseIPDB: Free web check, no login required. The API needs a free account and allows 1,000 requests a day. Crowd-sourced abuse reports and a confidence score for a specific IP address, a useful independent cross-check against VirusTotal's own reputation data.
Hybrid Analysis: Free web submissions with a standard account; API access and sample downloads require completing Hybrid Analysis's separate vetting process. CrowdStrike's Falcon Sandbox detonates a file in an isolated environment and reports its actual runtime behaviour, complementing VirusTotal's static, signature-based verdicts with dynamic analysis. CrowdStrike reengineered the platform in late August 2026 (new default QuickScan Pro engine, unified sample view), so expect a different interface to the one in older screenshots.
|
Before you begin Stop at the login. AbuseIPDB needs a free account for its API; Hybrid Analysis needs a free account to submit at all, and a separate vetting process only for API access or sample downloads. VirusTotal and urlscan.io let you run a single check without one. The account requirement is the smaller decision here. The one that matters is whether you query a hash or upload the file itself, covered below. Legal considerations. Uploading a full file to VirusTotal's public service shares it with the contributing antivirus vendors and, per VirusTotal's own privacy policy, makes it available to verified security researchers and premium customers as part of its threat-sharing mission. Never upload a file containing personal data, client material or anything confidential; query its SHA-256 hash instead. urlscan.io's public scans are similarly visible to other users by default. |
Compute the file's SHA-256 hash locally and search it directly in VirusTotal. A match returns the full multi-engine verdict with nothing uploaded. If there is no match, weigh how sensitive the file is before deciding whether a full upload is warranted.
A 2-of-70 detection from low-reputation engines is a weak signal; 20 or more from established vendors is a strong one. Check the Details tab for which specific engines flagged the file and what they named it.
VirusTotal's URL scan checks the link against blocklists and engine verdicts. urlscan.io actually loads the page in a sandbox and returns a screenshot and the full list of domains and scripts it contacts, useful when the URL is too new for engines to have caught up.
On a domain or IP's VirusTotal report, the Relations tab surfaces historical resolutions, communicating files and subdomains. This is the fastest way to expand from one confirmed indicator to a wider set worth checking.
Query the same IP address in AbuseIPDB and compare its confidence score and report categories against VirusTotal's community and vendor data. Agreement between independent sources is stronger evidence than either alone.
Submit the file to Hybrid Analysis, which runs it in an isolated environment and reports network connections, file writes and process activity. Useful for samples that evade signature detection but still behave maliciously.
|
03
What VirusTotal OSINT gets wrong
A low or zero detection count is read as a clean bill of health far more often than the evidence supports.
Zero detections treated as proof of safety: New or custom malware, and legitimate but rarely-seen files, both produce low detection counts for the same reason: few engines have encountered them before. Verifying check: for an unfamiliar file with zero or near-zero detections, corroborate with behavioural analysis rather than treating the score alone as clearance.
A single flagging engine treated as confirmation: Some antivirus engines are known for aggressive heuristic false positives on legitimate but unusual software, particularly packers, installers and penetration-testing tools. Verifying check: check which specific engine flagged the file and what detection name it used; a single generic heuristic label carries far less weight than a specific named-family detection from multiple established vendors.
Shared hosting infrastructure read as shared ownership: A malicious domain and an unrelated legitimate domain can resolve to the same IP address on shared hosting, cloud or CDN infrastructure. Verifying check: before attributing two domains to the same actor from a shared IP, confirm the hosting provider is not a large shared platform where thousands of unrelated domains coexist.
A stale report assumed current: A URL or domain's reputation can change substantially after its last scan, particularly for compromised legitimate sites that get cleaned up or newly weaponised infrastructure. Verifying check: check the last analysis date on the report and resubmit for a fresh scan if the existing one is more than a few days old and the finding is material.
Disagreement between sources dismissed rather than investigated: VirusTotal and AbuseIPDB draw on different reporting communities and can genuinely disagree on a borderline IP. Verifying check: treat a disagreement as a prompt to examine the underlying reports and detection names on both platforms rather than defaulting to whichever score fits the expected conclusion.
Chain of custody: detection ratios and reputation scores shift as engines update their signatures and communities file new reports, so a finding is only as strong as the record of when and how it was captured.
Record the exact hash queried and the date of the query
Screenshot the full detection list, not just the summary ratio, including engine names and detection labels
Export urlscan.io scan results, including the screenshot and request list, if a page is likely to change or be taken down
Note whether a finding came from a hash lookup or a full upload, since the two carry different disclosure implications
Retain AbuseIPDB and Hybrid Analysis reports separately, since cross-source corroboration only holds if each source's finding is independently preserved
04
Go deeper
A reference card for practitioners who want to build on this guide's infrastructure workflow.
CARD · DIG-001
WHOIS investigation: domain name to attribution chain.
ViewDNS, SecurityTrails and crt.sh. Registrant email pivots that map infrastructure and hosting networks.
CARD · DIG-002 · SIGNAL TIER
IP infrastructure: geolocation to attribution.
IPinfo, Shodan and BGP.tools. ASN mapping and passive DNS pivots from a single IP to a documented case file.
Evidentiary standard
Signal & Shadow operates to the LST-001 evidentiary standard. All claims are graded against the LST-001 v1.0.3 confidence tiers (Confirmed, Corroborated, Reported, Alleged) per the canonical voice and structural specification.
About Signal & Shadow
Signal & Shadow is an independent forensic investigation and methodology practice publishing tutorials, reference cards, and forensic dossiers for working practitioners. Founded by Derek Bowler.




