VirusTotal IoC Feeds - Domain intelligence feed API

IoC Feeds - Domain intelligence feed

Business capability
Threat Detection & Response Management BC-620.30

Operations 2

GET /feeds/domains/hourly/{time} VirusTotal Get an Hourly Domain Feed Batch #
GET /feeds/domains/{time} VirusTotal Get a Minutely Domain Feed Batch #

Work with this as data

Every API here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for apis

7 MCP tools reach this
  • find_apisBrowse and filter every API in the catalog.
  • get_api_artifactsOne API's artifacts, grouped by type.
  • get_openapiThe primary OpenAPI for this API.
  • find_similar_apisAPIs that look like this one.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This API
curl "https://apis.io/api/v1/apis/virustotal-ioc-feeds-domain-intelligence-feed-api"
All apis
curl "https://apis.io/api/v1/apis?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.

OpenAPI Specification

virustotal-ioc-feeds-domain-intelligence-feed-api-openapi.yml Raw ↑
openapi: 3.2.0
info:
  title: VirusTotal API v3 - IoC Feeds IoC Feeds - Domain…
  version: '3.0'
  description: Per-minute and hourly intelligence feed batches for files, URLs, domains, IP addresses, and sandbox analyses. Premium tier required.
  contact:
    name: VirusTotal / Google Threat Intelligence
    url: https://docs.virustotal.com/reference/overview
  license:
    name: VirusTotal Terms of Service
    url: https://www.virustotal.com/gui/terms-of-service
  x-generated-from: https://storage.googleapis.com/gtidocresources/guides/GTI_API_v3_openapi_spec_10022025.json
  x-last-validated: '2026-05-29'
servers:
- url: https://www.virustotal.com/api/v3
  description: VirusTotal / GTI API v3 production.
security:
- VTApiKey: []
tags:
- name: IoC Feeds - Domain intelligence feed
  description: IoC Feeds - Domain intelligence feed
paths:
  /feeds/domains/hourly/{time}:
    get:
      tags:
      - IoC Feeds - Domain intelligence feed
      deprecated: false
      description: '> 🚧 Special privileges required

        >

        > Domain feeds endpoints are only available to users with a Domain feeds license. Contact us for more information.


        This endpoint returns a single package containing all minutely packages returned in `/feeds/domains/{time}` endpoint for a given hour. The returned file is a .tar.bz2 file which contains the 60 minutely feeds for that hour.


        The provided time argument must be in `YYYYMMDDhh` format. For example, time `2021012211` returns the batches correspoding to January 21st 2021 11:00 - 11:59 UTC. You can download batches up to 7 days old, and the most recent batch has always a 2 hours lag with respect with to the current time. This means that if the current time in UTC is T you can download batch T-2h but any more recent.


        Successful calls to this endpoint will return a `302` redirect response to a URL from which the final batch file will be downloaded.'
      operationId: feedsdomainshourly2time
      parameters:
      - description: A string in format YYYYMMDDhh
        in: path
        name: time
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get an Hourly Domain Feed Batch
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
  /feeds/domains/{time}:
    get:
      tags:
      - IoC Feeds - Domain intelligence feed
      deprecated: false
      description: '> 🚧 Special privileges required

        >

        > Domain feeds endpoints are only available to users with a Domain feeds license. Contact us for more information.


        With this endpoint you can download an individual one-minute batch by providing a time consisting of a string with format `YYYYMMDDhhmm`. Time `201912010802` will return the batch corresponding to December 1st, 2019 08:02 UTC. You can download batches up to 7 days old, and the most recent batch has always a 60 minutes lag with respect with to the current time. This means that if the current time in UTC is `T` you can download batch `T-60m` but not `T-59m` or any more recent.


        Successful calls to this endpoint will return a `302` redirect response to a URL from which the final batch file will be downloaded.


        > 🚧 Missing batches

        >

        > Missing batches are rare, but still can happen occasionally. This doesn''t mean that you are losing any Domains in the feed, it just means that no batches were generated on a specific minute. The client code should be ready to accept a `404` error while retrieving a batch and proceed with the following one. However, receiving multiple `404` errors in a row for consecutive batches shouldn''t happen and should be treated as an error condition.


        The downloaded file is a bzip2 compressed UTF-8 text file contains one JSON structure per line, where the structure represents a URL object as returned by the GET /domains/{domain} endpoint.'
      operationId: feedsdomains2time
      parameters:
      - description: A string in format YYYYMMDDhhmm
        in: path
        name: time
        required: true
        schema:
          type: string
      responses:
        '200':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '200'
        '400':
          content:
            application/json:
              examples:
                Result:
                  value: '{}'
              schema:
                properties: {}
                type: object
          description: '400'
      security:
      - VTApiKey: []
      summary: VirusTotal Get a Minutely Domain Feed Batch
      x-microcks-operation:
        delay: 0
        dispatcher: FALLBACK
components:
  securitySchemes:
    VTApiKey:
      type: apiKey
      in: header
      name: x-apikey
      description: Personal VirusTotal / GTI API key. Found in the user menu of your VirusTotal account.