Providers

VirusTotal

The v3 domain URL relationship of VirusTotal. Needs VIRUSTOTAL_API_KEY. Cursor pages up to 50.
IDvirustotal06 / 7www.virustotal.com
Source

VirusTotal

  • provider: "virustotal"
  • www.virustotal.com

URLs VirusTotal has seen for the domain. No key, no answer.

Format
JSON v3 pages
Paging
cursor, at most 50 pages
Dates
none, from and to skip nothing
Key
required

Access

Loadawait create("virustotal")
CLIurls discover example.com -p virustotal
KeyVIRUSTOTAL_API_KEY, required, or apiKey in create()
Endpointhttps://www.virustotal.com/api/v3/domains/{domain}/urls

What it knows

URLs VirusTotal has seen for the domain, mostly ones somebody wanted checked. It skews toward the suspicious, which is sometimes exactly the point. No dates come back.

How it asks

GET /api/v3/domains/{domain}/urls with the key in the x-apikey header, never in the URL. Then links.next page by page, 50 pages at most.

Traps

  • No key, no answer. create("virustotal") without VIRUSTOTAL_API_KEY or apiKey fails with AuthError, and the automatic pick moves on to the next source.
  • With a key set, the automatic pick tries VirusTotal first. That's the one source that jumps the queue.
  • A links.next that points off www.virustotal.com isn't followed. The page then ends with truncated, since VirusTotal advertised more.
  • The legacy v2 domain/report endpoint is dead, it answers 403 HTML. This provider speaks v3 only.