VirusTotal is a free online malware scanning service: submit a file, URL, domain or IP address, and it runs the item through more than 70 antivirus engines and URL blocklists at once, then aggregates the verdicts into a single, publicly searchable report. Compared with relying on one antivirus product, its value is a second opinion from dozens of security vendors in a single check — useful both for catching threats a single engine missed and for spotting false positives (harmless items flagged by one or two engines). The service was created in June 2004 by the Spanish security company Hispasec Sistemas, acquired by Google in September 2012, and now sits within Google's security operations business (Google Security Operations). (Sources: How it works, Wikipedia: VirusTotal, checked 2026-09-02)

The VirusTotal home page: file, URL and search tabs, with a notice that submissions are shared with the security community

The screenshot above shows the VirusTotal home page: a search bar at the top accepts URLs, IPs, domains or file hashes, and the main area offers three tabs — FILE (upload a file), URL (submit a link) and SEARCH (look up existing reports). Note the fine print under the upload button: by submitting, you agree to the Terms of Service and Privacy Notice and to the sharing of your sample with the security community, and the page explicitly asks you not to submit any personal information. This is the single most important rule to understand before using the service; the "Privacy: uploads are shared" section below explains it in detail.

At a glance

  • URL: https://www.virustotal.com/
  • Type: multi-engine file/URL malware scanner and threat-intelligence aggregation platform
  • Cost: the public web scanner is free (for non-commercial use); advanced services such as Intelligence, Hunting and Private Scanning are paid enterprise products with undisclosed pricing (contact sales)
  • Registration: not required for scanning or viewing public reports; a free community account unlocks comments, votes and a public API key
  • Interface languages: available in many languages, including Chinese (source: Wikipedia infobox)
  • Launched: June 2004
  • Operator: Google (acquired 2012; folded into Chronicle in 2018, then Google Cloud's security business)

Background

VirusTotal was launched in June 2004 by Hispasec Sistemas, a security company based in Málaga, Spain, co-founded by Bernardo Quintero and others. PC World named it one of the best 100 products of 2007. Google announced its acquisition in September 2012, promising at the time to keep it running independently and to expand partnerships with antivirus vendors. In January 2018 VirusTotal moved under Chronicle, Alphabet's cybersecurity company; when Chronicle merged into Google Cloud in June 2019, VirusTotal's enterprise offerings were gradually absorbed into what is now Google Threat Intelligence, while the free public scanner remained open to everyone. (Sources: Wikipedia: VirusTotal, TechCrunch, VT→Google TI migration guide)

This "acquired but still free" trajectory gives the site a dual identity: for everyday users it is a quick way to check a suspicious file; for the security industry it is a sharing hub where antivirus vendors — and, since November 2018, a unit of U.S. Cyber Command — exchange samples and verdicts as "contributors."

Core capability: one submission, dozens of verdicts

As of 2026-09-02, VirusTotal's documentation says it aggregates more than 70 antivirus scanners and URL/domain blocklisting services, plus 10+ dynamic-analysis sandboxes. There are four main ways to use it:

  • File scanning: upload directly in the browser, up to 650MB (the API accepts direct uploads up to 32MB; larger files require a special upload URL, also capped at 650MB). If you only have a hash, you can query the existing report without uploading anything. (Sources: Upload a file, Wikipedia)
  • URL scanning: submit a suspicious link; engines distinguish malware sites, phishing sites, suspicious sites and so on.
  • Domain / IP lookups: detection history, WHOIS data, related samples and other context for an infrastructure item.
  • Search: look up historical reports by hash, URL, domain, IP or keyword. Basic search is free; advanced search modifiers and bulk export are paid features.

The public report for the EICAR test file: 65 of 67 engines flag it, each with its own detection name

The screenshot above shows the public report for the EICAR standard test file — a harmless 68-byte string designed to verify that antivirus software works. At capture time, 65 of 67 engines flagged it (the red ring shows 65/67), and the report lists each vendor's detection name side by side: AhnLab calls it Virus/EICAR_Test_File, ClamAV Eicar-Test-Signature, BitDefender EICAR-Test-File (not a virus). A "Code insights" panel at the top automatically explains that EICAR is not a real virus. This side-by-side layout is the essence of VirusTotal: it does not decide for you — it shows you what every engine decided.

The public dataset and the community

Every sample and report submitted through the public interface enters VirusTotal's public dataset, which anyone can search without an account. With a free community account you can also comment on files and URLs (disinfection advice, reverse-engineering notes, in-the-wild sightings) and vote on whether items are harmful; comments and votes feed into a community reputation score. (Sources: How it works, Join Community)

The domain report for wikipedia.org: all 91 vendors rate it Clean, with a community score of 88

The screenshot above is the domain report for wikipedia.org: all 91 security vendors on the Detection tab rate it "Clean," the community score on the left is 88, and the domain carries a "top-1K" popularity label. The banner at the top adds useful nuance — "at least 9 detected files communicating with this domain" — showing that even a clean overall verdict can hide interesting relationships. The DETECTION, DETAILS, RELATIONS and COMMUNITY tabs correspond to engine verdicts, metadata, related samples and community discussion.

Accounts and developer access

  • Public API (free): registering a community account entitles you to an API key in your settings. The limits are 500 requests per day and 4 requests per minute; the API must not be used in commercial products or services, must not serve as a substitute for antivirus products, and registering multiple accounts to bypass the limits is prohibited (checked 2026-09-02).
  • Premium API and enterprise services: VirusTotal Intelligence (advanced search, sample downloads), Hunting (live YARA rule matching and retrohunts), Graph (relationship visualization) and Private Scanning are paid features with undisclosed pricing. Enterprise customers are being migrated to the Google Threat Intelligence product family. (Sources: Public vs Premium API, migration guide)
  • Companion tools: the site footer links to desktop uploaders, browser extensions, a mobile app and YARA tooling; files can also be submitted through the browser extensions.

Privacy: uploads are shared

This is the one thing to understand before using VirusTotal: items submitted through the public interface are not scanned privately. The data flow works roughly like this:

  1. A submitted sample is immediately distributed to VirusTotal's security partners for analysis, and the resulting report joins the public dataset, searchable by anyone.
  2. The official documentation states plainly that the contents of submitted files may also be shared with premium VirusTotal customers — paying security professionals can search for and download samples for research.
  3. The notice under the home-page upload button says that submitting means agreeing to share your sample with the security community, and asks you not to submit any personal information.

The 2021 edition of the site's terms (now archived as the historic Terms of Service) put it even more bluntly: users should only upload samples they wish to publicly share, must not knowingly submit samples containing confidential, commercially sensitive or personal data without lawful permission, and "if you do not want to publicly share a sample in the manner set out in these terms... do not send it to the service." The terms link on the site now points to the Google Cloud Terms of Service and the SecOps Privacy Notice (effective February 6, 2025).

An incident in June 2023 illustrates how far this sharing reaches: an employee accidentally uploaded a CSV containing premium customers' company names, group names and administrator email addresses to VirusTotal itself. The file was visible to all paying partners and was flagged within an hour by several customers' own YARA monitoring rules. In its official apology, the company said information belonging to roughly 5,600 customers was exposed, reiterating that files uploaded to VirusTotal being visible to paid security analysts is exactly how the platform is designed to work. (The 5,600 figure per The Register, cited via Wikipedia.)

If you genuinely need to analyze sensitive files, the company sells Private Scanning: files are not distributed to third parties, are deleted after a short retention period (about 24 hours by default), and reports are visible only within your organization. The trade-off is that private reports contain no antivirus verdicts — only sandbox and static-analysis results. For most people the practical rule is simpler: suspicious installers and documents are fine to upload; anything containing personal photos, IDs, work documents or other private content is not.

When it is useful

  • Cross-checking a downloaded program with dozens of engines before running it
  • Looking up a suspicious link or attachment hash before opening it
  • Judging whether your own antivirus alert is a false positive (if only one or two engines flag the file, community comments help you dig deeper)
  • Threat research: pivoting across malware families, related domains and attacker infrastructure (advanced features are paid)

Limitations

  • A clean result is not a guarantee of safety: brand-new malware may not yet be recognized by any engine, and a single flag is not necessarily a false positive either. VirusTotal stresses that it is an aggregator and does not draw conclusions for you.
  • Not a replacement for antivirus software: the terms explicitly prohibit using it as a substitute for antivirus products, and it provides no real-time protection.
  • No antivirus benchmarking: the 2021 terms prohibit using the service to test or compare antivirus/URL-scanning products, or in any way that could harm the antivirus industry.
  • Privacy boundary: anything submitted publicly — including the file itself — is shared with the security community and premium customers, as detailed above.
  • Tight free API quota: 500 requests/day and 4 requests/minute; bulk workflows need a paid plan.
  • Age requirement: the 2021 terms require users to be at least 18 years old.

Alternatives

  • Hybrid Analysis: a free sandbox-report platform run by CrowdStrike; submissions are likewise shared publicly.
  • ANY.RUN: an interactive online sandbox that lets you watch malware execute live in the browser.
  • urlscan.io: focused on URL scanning and recording web-page behavior, with free public reports.

References