Is this file, link, domain or IP known-malicious?
Checks VirusTotal’s existing scan results via VTAI, VirusTotal’s free API for AI agents — no API key, no account. This retrieves an existing result; it never triggers a new scan. A URL check sends the complete URL (including anything after ? or #) to VirusTotal — use the domain check instead if the link might carry a token or private data.
How this works
This tool proxies your lookup through PlayCISO’s own registration with VirusTotal’s VTAI API — you never need your own account or key. Lookups are rate-limited per visitor to stay well within VTAI’s shared free quota, so it stays free for everyone. Want the full picture on what VTAI is and the governance considerations before wiring it into your own AI agents? Read the explainer and the rollout checklist.
Frequently asked questions
Is this tool free?
Yes, no signup or API key needed. It proxies your lookup through PlayCISO’s own registration with VirusTotal’s free VTAI API for AI agents, rate-limited per visitor to stay within VTAI’s shared free quota.
Does this start a new scan?
No. It only retrieves an existing scan result already on file at VirusTotal. If nothing has scanned that file, URL, domain or IP before, you’ll see "no existing scan result" rather than a fresh analysis.
Is my file uploaded when I check a hash?
No. A hash check only ever sends the hash itself, never the file. If you want a file actually scanned rather than just checked against prior results, you’d need to submit it directly to VirusTotal.
What data does a URL check send?
The complete URL, including everything after a ? or #. If the link might contain a session token, API key, or other private data in its query string, check the domain instead.
What does "no existing scan result" mean?
It means VirusTotal hasn’t seen that specific hash, URL, domain or IP before — not that it’s confirmed safe. A brand-new or rarely-seen artifact can be malicious and still show no detections simply because nothing has scanned it yet.