Enriching Data with VirusTotal v3

VirusTotal analyzes files and URLs for viruses, worms, trojans, and other malicious content. When activated, the VirusTotal enrichment enables you to pivot on domains, IP addresses (v4 only), and hashes. Enrichment data is also displayed in the Enrichments section on observable details pages.

The information in this article pertains to activating and using the ThreatStream integration with VirusTotal that leverages the VirusTotal v3 API. For information on the legacy VirusTotal v2 API integration, see Enriching Data with VirusTotal v2.

You can leverage VirusTotal data on Explore after activation.

Enrichment data can also be accessed from observable details pages under Enrichments.

Where data is available, the VirusTotal enrichment returns the following information for each observable type:

Observable Type Enrichment Data
Domain

Categories, Communicating Files, Downloaded Files, Observed Subdomains, Passive DNS Replication, URLs

Downloaded Files information is available only to users with premium VirusTotal API keys.
Hash Basic Properties, Community Score (displayed as Safe/Unsafe), Detections, Detection Ratio, History, Last Analysis, Other Hashes
IP

Autonomous System, Communicating Files, Country, Domain Replication, Downloaded Files, Passive DNS Replication, URLs

Downloaded Files information is available only to users with premium VirusTotal API keys.
URL Last Analysis Time, Last Analysis Stats, Last Analysis Results

Activating the VirusTotal v3 Enrichment

The VirusTotal v3 enrichment can be activated using a free public API key or a subscription based premium API key.

If you activate the VirusTotal v3 enrichment using a public API key, you can execute a subset of the transforms listed above. If you attempt to execute a transform which is not available through the public API, you will see the following error message:

If you activate the VirusTotal enrichment using a premium API key, you can execute all of the transforms listed above.

To obtain a public VirusTotal API key:

  1. Visit the VirusTotal registration page, enter the required information, and click Join Us. After completing this step, VirusTotal sends you an activation email.
  2. Locate the VirusTotal activation email in your inbox and complete the enclosed steps required to activate your account.
  3. Login to your VirusTotal account.
  4. Click API key in the VirusTotal menu at the top right of the screen.

  5. Copy your API key, available under the API Key heading.

    You will use your API key to activate the enrichment on the ThreatStream user interface.

To request a premium VirusTotal API key:

  1. On the VirusTotal user interface, click API key in the menu at the top right of the screen.

  2. Click Request premium API Key.
  3. Fill out the request form and click Send. VirusTotal will contact you with further information on obtaining a premium API key.
To read more about the premium VirusTotal API, see https://developers.virustotal.com/v3.0/reference#public-vs-premium-api

To activate the VirusTotal v3 enrichment:

  1. Navigate to ThreatStream > APP STORE > APP Store.
  2. Click Get Access on the VirusTotal v3 tile.
  3. Click I have credentials.
  4. In the Limit field, enter a maximum number of entities that you want to be returned per a transform request.
  5. Enter your VirusTotal API Key. You can enter a public or premium API key.
  6. Click Activate.

The VirusTotal v3 enrichment is now active.