{"uid":"cap_L83iJyax_4sMEhlV_s1O9","slug":"virustotal-file-behaviours-via-locus-x402-e79793e2","name":"VirusTotal File Behaviours via Locus x402","description":"Threat intelligence platform — scan files by hash, URLs, domains, and IPs against 70+ antivirus engines and security tools.","url":"https://virustotal.x402.paywithlocus.com/virustotal/file-behaviours","method":"POST","headers":{},"bodySchema":{"type":"object","properties":{"hash":{"type":"string"},"limit":{"type":"number"}}},"responseSchema":{"type":"json","example":{"data":{},"payment":{"scheme":"exact","settledUsdc":"0.001000","authorizedMaxUsdc":"0.001000"},"request":{"id":"00000000-0000-4000-8000-000000000000","statusUrl":"/requests/00000000-0000-4000-8000-000000000000"},"success":true}},"example":null,"exampleRequest":null,"tags":["x402"],"displayCostAmount":"0.055","displayCostAsset":"USDC","priceDynamic":false,"priceHint":null,"priceStatus":"priced","priceSource":"probe","requiresHandshake":false,"reviewCount":0,"rating":{"score":"0.00","successRate":"0.00","reviews":0,"stars":null,"state":"unrated"},"availabilityStatus":"unknown","priceObserved":null,"sessionDeposit":null,"pricing":{"kind":"static","summary":"$0.055/call","primary":{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.055","per":"call","confidence":"exact"},"accepted":[{"kind":"static","protocol":"x402","network":"base","amountUsd":"0.055","per":"call","confidence":"exact"}]},"paymentMethods":[{"uid":"pm_-_KqpFn-eKUiKKyqyVNuq","protocol":"x402","methodType":"crypto","chain":"base","mode":"charge","costAmount":"0.055","costPer":"request","priority":0,"asset":"0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913","unit":"request","depositMicros":null,"planRef":null}],"brandName":null,"brandSlug":null,"brandBaseUrl":null,"brandDocsUrl":null,"whatItDoes":"Retrieves sandbox behavior reports for a file identified by its hash, showing dynamic analysis results from VirusTotal's sandbox environments.","exampleAgentPrompt":"Can you pull up the sandbox behavior reports for the file with SHA-256 hash 275a021bbfb6489e54d471899f7db9d1663fc695ec2fe2a2c4538aabf651fd0f — show me up to 5 reports so I can see what it does when it runs?","exampleUseCases":[{"title":"Malware triage during incident response","prompt":"We found a suspicious file on an endpoint — its MD5 hash is 44d88612fea8a8f36de82e1278abb02f. Can you fetch its VirusTotal behavior reports so I can see what processes it spawns, what network calls it makes, and whether it drops any files?"},{"title":"SOC analyst vetting a phishing attachment","prompt":"A user forwarded a sketchy email attachment and I have its SHA-1 hash: aaf4c61ddcc5e8a2dabede0f3b482cd9aea9434d. Pull the first 3 sandbox behavior reports from VirusTotal so I can understand what it actually does before opening it."},{"title":"Threat hunting for known malware family behavior","prompt":"I'm hunting for lateral movement indicators — can you grab the sandbox behavior reports for the SHA-256 hash e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855 and return up to 10 reports so I can check for credential-dumping or network scanning activity?"}],"resultDescription":"Returns a JSON object containing dynamic sandbox behavior reports for the queried file hash, including details such as processes created, network connections, file system changes, registry modifications, and other runtime behavioral indicators observed during sandbox execution. The response also includes payment confirmation metadata and a request ID for status tracking.","failureModes":["Unknown or unanalyzed hash returns empty data array","Invalid hash format (not SHA-256/SHA-1/MD5) causes request failure","Rate limiting or payment failure returns non-success response","Hash exists in VirusTotal but no sandbox reports available yields empty results","Network timeout on large behavior report sets"],"whenToPreferThis":"Choose this endpoint when you need dynamic/behavioral analysis of a file rather than static detection results. It is specifically suited for understanding what a file does at runtime — process trees, network connections, file drops — as opposed to just whether antivirus engines flag it. Prefer this over static scan endpoints when investigating malware behavior, performing incident response triage, or threat hunting for specific behavioral TTPs. Ideal when you already have a file hash and need sandbox execution context.","instructions":null,"reviewSummary":null,"reviewSummaryHighlights":null,"reviewSummaryConcerns":null,"reviewSummaryGeneratedAt":null,"activationCount":0,"lastUsedAt":null,"lastSuccessfullyRanAt":null,"lastHealthCheckAt":"2026-09-14T18:33:20.670Z","isFirstParty":false}