IN PROGRESS
Technical summary
NEXUS plugin that checks the reputation of hashes, IPs, domains and URLs on the VirusTotal v3 API, feeding the Intelligence Hub with severity signals. Supports multiple keys with circular rotation and rate-limit failover, local TTL cache and manual scanning of task attachments.
Executed scope
- Registration:
plugin.jsonv1.0.0, lucideshield-alerticon,icon_bg #f8fafc, customicon.png(brand logo) andicon.svg; noregisterTab— the UI lives in the Intelligence Hub (no loose tab/sidebar);registerDoc('virustotal','VirusTotal','shield-alert',doc.md)andregisterModal('virustotal-modals',modals.php); nocronjob.json(on-demand plugin). - Configuration: multiple API keys in
DB::setConfig('plugin.virustotal.keys'); circular rotation with persistedlast_key_indexand automatic failover on 429/401/403 (tries the next key until exhausted). - v3 API via cURL:
virustotal_indicator_endpoint()mapsfiles/{hash},ip_addresses/{ip},domains/{domain}andurls/{base64url id};x-apikeyheader, 12s timeout andSSL_VERIFYconfigurable via a Core constant. - Classification:
maliciouswhenmalicious > 0orsuspicious > 1;cleanotherwise;unknownfor 404 (not found in the database) — withmalicious/suspicious/totalcounts and last analysis date. - Local TTL cache:
vt_c_<md5>(hash) andvt_<type>_<md5>keys viaDB::setConfig; 24h TTL for results and 12h forunknown(may be submitted later). - Manual task scan:
virustotal_scan_tasksweeps physical attachments (task and comments, SHA-256 viahash_file) and hashes quoted in text (MD5/SHA-1/SHA-256);forcebypasses the cache; fallback to expired cache when the API fails. - Intelligence Hub enricher:
nx_intel_register_enricher('virustotal', ['hash','ip','domain','url'], 'virustotal_intel_enrich', 53)— signals withok/needs_key/error/skippedstatus; without a key the signal isneeds_key("API Key necessária") without altering markdown; budgetslice ≤ min(6, max_live_lookups); severitymin(100, 60 + malicious × 3)for malicious and8for clean. - Fast Responses:
/virustotal <value>(required argument) →virustotal_lookupwith auto type detection (MD5/SHA-1/SHA-256 → hash; IP; URL; otherwise domain). - API with 5 actions:
virustotal_get_config(masked keys),virustotal_save_config,virustotal_test_key(validates with a known clean hash; 200/404 OK, 401/403 denied, 429 limit),virustotal_scan_taskandvirustotal_lookup. - Config modal: masked key list (
xxxx••••••••xxxx), per-key test with states (zap → spinner → check/x), add with dedup and remove. - Details modal (click a VT signal in the hub): Status cards (Dirty/Clean/Unknown), Detections (
X / total) and Hash Type (SHA-256/SHA-1/MD5); contextual threat description; full hash with copy button; query metadata; external "View on VirusTotal" link (gui/file/<hash>). - CORS:
cors.phpregisters thevirustotal.comandapi.virustotal.comorigins for scanning lookups. - Persistence without MySQL tables: everything via
system_settings(DB::getConfig/DB::setConfig);assets/virustotal.jsis empty legacy (UI moved to the hub).
Stack and tools
- PHP 8 backend (no framework) + cURL (VirusTotal API v3)
- Alpine.js + Tailwind CSS (config and details modals)
- Internal Plugin API (actions + enricher +
fastr.json+cors.php+system_settings)
Tags
VirusTotal, Threat Intel, Hash, Reputation, OSINT, Intelligence Hub, NEXUS Plugin
Operational result
- One-click reputation: hashes, IPs, domains and URLs from tasks/comments become Intelligence Hub signals with computed severity.
- Key rotation: multiple free keys rotated automatically bypass the free-tier rate limit.
- TTL cache: repeated lookups answer from the local cache (24h/12h) without spending quota.
- Physical attachment scanning: SHA-256 of files attached to tasks and comments checked without automatic submission.
- No key? No noise: the hub signals "API Key necessária" without breaking the task flow.
- External verification: modal with a direct link to the VirusTotal
gui/file.
GitHub progress (issues)
Real-time panel with latest repository issues.
live feed
open issues on GitHubcarregando andamento...
não foi possivel carregar as issues agora. abra no github pelo link acima.
Real results
NEXUS plugin that checks the reputation of hashes, IPs, domains and URLs on the VirusTotal v3 API, feeding the Intelligence Hub with severity signals. Supports multiple keys with circular rotation and rate-limit failover, local TTL cache and manual scanning of task attachments.
Architecture and organization
- PHP 8
- cURL
- VirusTotal API v3
- Alpine.js
- Tailwind CSS
- Plugin NEXUS
Execution and operations
The project follows reproducible execution flow with technical validation in production-like environments.
Screenshots
Talk about this project
Apply this implementation pattern in your environment and accelerate delivery with technical consistency.