{"uid":"cap_AW5DArPUHLqInbZ6zbo9o","slug":"virustotal-file-report-via-locus-x402-c0580045","name":"VirusTotal File Report via Locus x402","description":"Threat intelligence platform — scan files by hash, URLs, domains, and IPs against 70+ antivirus engines and security tools.","url":"https://virustotal.x402.paywithlocus.com/virustotal/file-report","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"hash":{"type":"string"}}},"responseSchema":{"type":"json","example":{"data":{},"payment":{"scheme":"exact","settledUsdc":"0.001000","authorizedMaxUsdc":"0.001000"},"request":{"id":"00000000-0000-4000-8000-000000000000","statusUrl":"/requests/00000000-0000-4000-8000-000000000000"},"success":true}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.055","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.055/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.055","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.055","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_e_gUZwc9KMO4u4Z6Fl6fu","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.055","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves a threat intelligence report for a file identified by its hash (MD5, SHA-1, or SHA-256) from VirusTotal, scanning against 70+ antivirus engines.","exampleAgentPrompt":"Can you check VirusTotal to see if this file hash is malicious — SHA-256: 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f?","exampleUseCases":[{"title":"Malware triage for suspicious download","prompt":"I just downloaded a file and I'm not sure if it's safe — can you check this SHA-256 hash on VirusTotal to see how many antivirus engines flag it as malicious? Hash: e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"},{"title":"Security incident file verification","prompt":"We found a suspicious executable on one of our servers during an incident response — can you pull its VirusTotal report using this MD5 hash: d41d8cd98f00b204e9800998ecf8427e and tell me if any AV engines are detecting it as a threat?"},{"title":"Automated threat feed enrichment","prompt":"I have a SHA-1 hash from our SIEM alert — da39a3ee5e6b4b0d3255bfef95601890afd80709 — can you look it up on VirusTotal and tell me the malware family and how many engines detected it?"}],"resultDescription":"Returns a JSON object containing VirusTotal's full file report data including per-engine detection verdicts, malware names, detection counts, file metadata, and threat categories across 70+ antivirus engines and security tools. Also includes payment confirmation with settled USDC amount and a request tracking ID.","failureModes":["Hash not found in VirusTotal database — file may never have been submitted for analysis","Invalid hash format (not a valid MD5, SHA-1, or SHA-256) returns an error","Payment failure or insufficient USDC balance prevents the request from completing","Rate limiting if too many requests are made in quick succession","Network timeout if VirusTotal backend is slow to respond"],"whenToPreferThis":"Use this endpoint when you need to check whether a specific file is malicious using its hash and want results from 70+ antivirus engines simultaneously without uploading the actual file. Ideal for security pipelines, incident response triage, SIEM enrichment, or any workflow where you already have a file hash and need a quick threat verdict. Prefer over direct VirusTotal API access when you want pay-per-call micropayment billing via x402 with no API key management.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:43:41.747Z","isFirstParty":false}