Enriching Data with VirusTotal v2

VirusTotal analyzes files and URLs for viruses, worms, trojans, and other malicious content. When activated, the VirusTotal enrichment enables you to pivot on domains, IP addresses (v4 only), and hashes. Enrichment data is also displayed on observable details pages.

You can leverage VirusTotal data on Explore after activation.

Enrichment data can also be accessed from observable details pages under Enrichments.

Where data is available, the VirusTotal enrichment returns the following information for each observable type:

Observable Type Enrichment Data
Domain Categories, Communicating Files, Downloaded Files, Observed Subdomains, Passive DNS Replication, URLs
Hash Basic Properties, Community Score (displayed as Safe/Unsafe), Detections, Detection Ratio, History, Last Analysis, Related Hashes
IP Autonomous System, Communicating Files, Country, Domain Replication, Downloaded Files, Passive DNS Replication, URLs
URL Detections, Detection Ratio, Last Analysis

Activating the VirusTotal Enrichment

The VirusTotal enrichment can be activated using a free public API key or a subscription based premium API key.

If you activate the VirusTotal enrichment using a public API key, you can execute a subset of the transforms listed above. If you attempt to execute a transform which is not available through the public API, you will see the following error message:

If you activate the VirusTotal enrichment using a premium API key, you can execute all of the transforms listed above.

To obtain a public VirusTotal API key:

  1. Visit the VirusTotal registration page, enter the required information, and click Join Us. After completing this step, VirusTotal sends you an activation email.
  2. Locate the VirusTotal activation email in your inbox and complete the enclosed steps required to activate your account.
  3. Login to your VirusTotal account.
  4. Click API key in the VirusTotal menu at the top right of the screen.

  5. Copy your API key, available under the API Key heading.

    You will use your API key to activate the enrichment on the ThreatStream user interface.

To request a premium VirusTotal API key:

  1. On the VirusTotal user interface, click API key in the menu at the top right of the screen.

  2. Click Request premium API Key.
  3. Fill out the request form and click Send. VirusTotal will contact you with further information on obtaining a premium API key.
To read more about the premium VirusTotal API, see https://www.virustotal.com/en/documentation/private-api/

To activate the VirusTotal enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.
  2. Click Get Access in the VirusTotal box.
  3. Click I have credentials.
  4. Enter your VirusTotal API Key. You can enter a public or premium API key.
  5. Click Activate.

The VirusTotal enrichment is now active.