MYTHOSAI

Tool tutorials / PRACTICAL GUIDE

Use VirusTotal without uploading confidential files

Search an existing file hash first and interpret detections as evidence, not a verdict.

Before you start

A browser and a locally calculated SHA-256 digest; no paid API is required.

Understand the sharing model

Public analysis services can share submissions and results with security partners and other users according to their terms. Do not upload customer records, contracts, source code, password databases or business documents merely to check whether they are safe.

A hash lookup avoids sending the actual file contents in that lookup, though the hash and your network request still reach the external service.

Calculate a digest locally

On Windows:

powershell
Get-FileHash -Algorithm SHA256 -LiteralPath 'C:\Mina\Downloads\sample.exe'

On Linux:

bash
sha256sum -- ./sample.exe

Use the actual existing file. Neither command runs it. Do not rename and open the file to inspect its contents.

Search before considering any upload

  1. Open the genuine VirusTotal website.
  2. Search for the digest, not a password or confidential text.
  3. If a report exists, compare file type, size, names and analysis date with your context.
  4. Review the nature of detections and other behaviour indicators, not only the number of engines.

An unknown digest means no report was found in the available search, not that the file is clean. If an upload would disclose confidential material, stop and use your approved local or private investigation process instead.

Interpret a result cautiously

One detection can be a false positive; zero can reflect a new threat or a file engines cannot fully inspect. Different names from vendors do not necessarily mean different malware families. Old analysis may not represent current detection coverage.

For URLs, do not submit private document links, password-reset tokens or authenticated portal URLs. A scanner may visit a submitted URL and change its exposure. Public reputation checking should not become accidental disclosure of access tokens.

Verify your decision with context

Check the publisher, digital signature, expected source and your endpoint alerts. For an incident, preserve the digest and report time. A clean reputation result does not authorise executing an unexpected attachment.

Common mistakes

Treating a detection count as a mathematical probability of malware is misleading. Uploading a confidential file cannot be undone simply by closing the tab. Automating repeated checks through a public API has quota and licence constraints; this tutorial uses the free manual lookup and does not promise unlimited access.

Official references

Consult the current vendor documentation if your version or screen differs.

Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.