This Python tool is designed for Threat Intelligence (CTI) Analysts to automate the detection of malicious IPs and URLs using the VirusTotal API. It supports checking multiple IPs and URLs, and outputs the results, allowing teams to monitor potential threats effectively.
- Automated Malicious IP and URL Detection: Queries the VirusTotal API to check for malicious reports.
- API Key Cycling: Automatically rotates through multiple VirusTotal API keys to avoid hitting rate limits.
- Malicious Report Logging: Saves malicious IPs and URLs to a
malicious.txtfile for tracking and analysis. - Supports both IPs and URLs: Checks both types of indicators in threat intelligence workflows.
- Python 3.x
requestslibrary for making HTTP requests.virustotal-pythonPython client library.- VirusTotal API key(s).
-
Clone the repository:
git clone https://github.com/rodanmaharjan/virus-total-threat-intel.git cd virus-total-threat-intel -
Install dependencies:
pip install -r requirements.txt
-
Obtain a VirusTotal API Key:
- Sign up for a VirusTotal account here.
- Copy your API key from your account settings.
-
Prepare the input files:
input.txt: List of IPs and URLs to check (one per line).api_keys.txt: List of your VirusTotal API keys (one per line).
-
Run the script:
python malicious_check.py
- Add your IP addresses and URLs to
input.txt. - Add your VirusTotal API keys to
api_keys.txt. - Run the script, and the results will be saved to
malicious.txt.
Example output:
Making request for IP: 192.168.0.1 Using API key: your-api-key Response for IP 192.168.0.1: Malicious Number of malicious reports: 3
Malicious IP addresses and URLs saved to malicious.txt