performing-malware-hash-enrichment-with-virustotal - Enrich malware hashes with VirusTotal
Enrich malware file hashes through the VirusTotal API with detection rates, sandbox behavior, YARA matches, network indicators, and contextual intelligence.
Tags
Updated: 2026-09-28Capabilities
Typical Inputs
What this skill does
- Query VirusTotal hash reports
- Extract detection statistics
- Retrieve sandbox behavior
- Extract network indicators
- Identify YARA matches
- Classify threat levels
- Export enrichment results
Inputs
- VirusTotal API key
- File hashes
- Hash input file
- Output CSV path
Outputs
- Hash enrichment reports
- Sandbox behavior data
- Network IOC lists
- CSV results file
- Console status messages
Requirements
- Python 3.9 or later
- vt-py or requests
- VirusTotal API access
