Skip to content

Latest commit

 

History

29 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

VirusTotal Malicious IP and URL Check

Overview

This Python tool is designed for Threat Intelligence (CTI) Analysts to automate the detection of malicious IPs and URLs using the VirusTotal API. It supports checking multiple IPs and URLs, and outputs the results, allowing teams to monitor potential threats effectively.

Features:

  • Automated Malicious IP and URL Detection: Queries the VirusTotal API to check for malicious reports.
  • API Key Cycling: Automatically rotates through multiple VirusTotal API keys to avoid hitting rate limits.
  • Malicious Report Logging: Saves malicious IPs and URLs to a malicious.txt file for tracking and analysis.
  • Supports both IPs and URLs: Checks both types of indicators in threat intelligence workflows.

Requirements:

  • Python 3.x
  • requests library for making HTTP requests.
  • virustotal-python Python client library.
  • VirusTotal API key(s).

Installation and Setup:

  1. Clone the repository:

    git clone https://github.com/rodanmaharjan/virus-total-threat-intel.git
    cd virus-total-threat-intel
  2. Install dependencies:

    pip install -r requirements.txt
  3. Obtain a VirusTotal API Key:

    • Sign up for a VirusTotal account here.
    • Copy your API key from your account settings.
  4. Prepare the input files:

    • input.txt: List of IPs and URLs to check (one per line).
    • api_keys.txt: List of your VirusTotal API keys (one per line).
  5. Run the script:

    python malicious_check.py

Usage:

  1. Add your IP addresses and URLs to input.txt.
  2. Add your VirusTotal API keys to api_keys.txt.
  3. Run the script, and the results will be saved to malicious.txt.

Example output:

Making request for IP: 192.168.0.1 Using API key: your-api-key Response for IP 192.168.0.1: Malicious Number of malicious reports: 3

Malicious IP addresses and URLs saved to malicious.txt

About

A Python-based threat intelligence tool to detect malicious IPs, Domains and URLs using VirusTotal's API. Ideal for CTI analysts to automate IP and URL reputation checks and track potential threats.

Resources

Stars

3 stars

Watchers

1 watching

Forks

Releases

Packages

Used by

Contributors

Languages