Cover image for project: NEXUS VirusTotal IN PROGRESS

Technical summary

NEXUS plugin that checks the reputation of hashes, IPs, domains and URLs on the VirusTotal v3 API, feeding the Intelligence Hub with severity signals. Supports multiple keys with circular rotation and rate-limit failover, local TTL cache and manual scanning of task attachments.

Executed scope

  • Registration: plugin.json v1.0.0, lucide shield-alert icon, icon_bg #f8fafc, custom icon.png (brand logo) and icon.svg; no registerTab — the UI lives in the Intelligence Hub (no loose tab/sidebar); registerDoc('virustotal','VirusTotal','shield-alert',doc.md) and registerModal('virustotal-modals',modals.php); no cronjob.json (on-demand plugin).
  • Configuration: multiple API keys in DB::setConfig('plugin.virustotal.keys'); circular rotation with persisted last_key_index and automatic failover on 429/401/403 (tries the next key until exhausted).
  • v3 API via cURL: virustotal_indicator_endpoint() maps files/{hash}, ip_addresses/{ip}, domains/{domain} and urls/{base64url id}; x-apikey header, 12s timeout and SSL_VERIFY configurable via a Core constant.
  • Classification: malicious when malicious > 0 or suspicious > 1; clean otherwise; unknown for 404 (not found in the database) — with malicious/suspicious/total counts and last analysis date.
  • Local TTL cache: vt_c_<md5> (hash) and vt_<type>_<md5> keys via DB::setConfig; 24h TTL for results and 12h for unknown (may be submitted later).
  • Manual task scan: virustotal_scan_task sweeps physical attachments (task and comments, SHA-256 via hash_file) and hashes quoted in text (MD5/SHA-1/SHA-256); force bypasses the cache; fallback to expired cache when the API fails.
  • Intelligence Hub enricher: nx_intel_register_enricher('virustotal', ['hash','ip','domain','url'], 'virustotal_intel_enrich', 53) — signals with ok/needs_key/error/skipped status; without a key the signal is needs_key ("API Key necessária") without altering markdown; budget slice ≤ min(6, max_live_lookups); severity min(100, 60 + malicious × 3) for malicious and 8 for clean.
  • Fast Responses: /virustotal <value> (required argument) → virustotal_lookup with auto type detection (MD5/SHA-1/SHA-256 → hash; IP; URL; otherwise domain).
  • API with 5 actions: virustotal_get_config (masked keys), virustotal_save_config, virustotal_test_key (validates with a known clean hash; 200/404 OK, 401/403 denied, 429 limit), virustotal_scan_task and virustotal_lookup.
  • Config modal: masked key list (xxxx••••••••xxxx), per-key test with states (zap → spinner → check/x), add with dedup and remove.
  • Details modal (click a VT signal in the hub): Status cards (Dirty/Clean/Unknown), Detections (X / total) and Hash Type (SHA-256/SHA-1/MD5); contextual threat description; full hash with copy button; query metadata; external "View on VirusTotal" link (gui/file/<hash>).
  • CORS: cors.php registers the virustotal.com and api.virustotal.com origins for scanning lookups.
  • Persistence without MySQL tables: everything via system_settings (DB::getConfig/DB::setConfig); assets/virustotal.js is empty legacy (UI moved to the hub).

Stack and tools

  • PHP 8 backend (no framework) + cURL (VirusTotal API v3)
  • Alpine.js + Tailwind CSS (config and details modals)
  • Internal Plugin API (actions + enricher + fastr.json + cors.php + system_settings)

Tags

VirusTotal, Threat Intel, Hash, Reputation, OSINT, Intelligence Hub, NEXUS Plugin

Operational result

  • One-click reputation: hashes, IPs, domains and URLs from tasks/comments become Intelligence Hub signals with computed severity.
  • Key rotation: multiple free keys rotated automatically bypass the free-tier rate limit.
  • TTL cache: repeated lookups answer from the local cache (24h/12h) without spending quota.
  • Physical attachment scanning: SHA-256 of files attached to tasks and comments checked without automatic submission.
  • No key? No noise: the hub signals "API Key necessária" without breaking the task flow.
  • External verification: modal with a direct link to the VirusTotal gui/file.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

NEXUS plugin that checks the reputation of hashes, IPs, domains and URLs on the VirusTotal v3 API, feeding the Intelligence Hub with severity signals. Supports multiple keys with circular rotation and rate-limit failover, local TTL cache and manual scanning of task attachments.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.