ActionVirusTotalUpdated September 2026

How do I look up an existing VirusTotal URL report?

Short answer: You can get url report in VirusTotal by hand from its own interface, but it won’t repeat itself. On TinyCommand, add the VirusTotal Get URL Report action to a workflow, map its 1 input from any upstream app, and it runs automatically every time the trigger fires. No code, and a free tier to start.

Get URL Report in VirusTotal — start free
Inputs

The fields this action accepts.

Every field can be mapped from an upstream trigger, AI step, table row, or hard-coded literal.

FieldTypeRequiredDescription
Analysis ID
analysisId
stringRequiredFrom the scan submission response
Sample request
{
"analysisId": "{{trigger.analysisId}}"
}
Returns
{
"data": {
"attributes": {
"stats": {
"harmless": 70,
"malicious": 0,
"suspicious": 0,
"undetected": 15
},
"status": "completed",
"results": {}
}
}
}

Use these fields in downstream nodes for routing, logging, or error handling.

Triggered by

Apps that pair well as the trigger for Get URL Report.

Any of these apps can fire this action as part of a workflow.

FAQ

Questions about Get URL Report.

What does the Get URL Report action do in VirusTotal?
Returns the existing VirusTotal analysis for a URL, including engine-by-engine verdicts and an aggregate threat score. Cheaper and faster than Scan URL when the URL has been analyzed before.
What inputs does Get URL Report require?
Required: Analysis ID. Every input accepts a static value or a variable from any upstream node in your workflow.
Can I use dynamic inputs from earlier workflow nodes?
Yes. Any field on this action can pull values from upstream nodes, whether that's a form response, a trigger payload, an AI output, or a lookup result.
What happens if VirusTotal returns an error?
The run history shows the failed step with its input and the error message VirusTotal returned, so you can fix the input and run the workflow again. Automatic retries are built into HTTP steps only, where you can also set your own retry count and delay.
Does Get URL Report support batch operations?
Run Get URL Report inside a loop to process each item in an array. TinyCommand does not throttle calls for you, so for large arrays add a Delay step if you need to stay within VirusTotal's rate limits.
More actions

Other VirusTotal actions.

Get URL Report in VirusTotal — start free