Virustotal Url Object Structure
A URL analysed by VirusTotal — identified by base64url of the URL.
UrlObject is a JSON Structure definition published by VirusTotal, describing 5 properties, of which 3 are required. It conforms to the https://json-structure.org/meta/core/v0/# meta-schema.
Properties
Meta-schema: https://json-structure.org/meta/core/v0/#
JSON Structure
{
"$schema": "https://json-structure.org/meta/core/v0/#",
"$id": "https://raw.githubusercontent.com/api-evangelist/virustotal/refs/heads/main/json-structure/virustotal-url-object-structure.json",
"name": "UrlObject",
"description": "A URL analysed by VirusTotal \u2014 identified by base64url of the URL.",
"type": "object",
"properties": {
"id": {
"type": "string",
"description": "Object identifier."
},
"type": {
"type": "string",
"description": "Object type discriminator."
},
"links": {
"type": "object",
"description": "Hypermedia links.",
"properties": {
"self": {
"type": "uri"
}
}
},
"attributes": {
"type": "object",
"description": "Type-specific attributes for UrlObject.",
"properties": {
"url": {
"type": "uri",
"description": "Submitted URL.",
"example": "https://example.com/path"
},
"final_url": {
"type": "uri",
"description": "Final URL after redirects."
},
"name": {
"type": "string",
"description": "HTML <title> of the URL when fetched."
},
"first_submission_date": {
"type": "int32",
"description": "Unix epoch of first submission."
},
"last_submission_date": {
"type": "int32",
"description": "Unix epoch of most recent submission."
},
"last_analysis_date": {
"type": "int32",
"description": "Unix epoch of last analysis."
},
"last_http_response_code": {
"type": "int32",
"description": "HTTP status from the last fetch.",
"example": 200
},
"last_http_response_content_length": {
"type": "int32"
},
"last_http_response_content_sha256": {
"type": "string"
},
"last_http_response_headers": {
"type": "object",
"additionalProperties": {
"type": "string"
}
},
"last_http_response_cookies": {
"type": "object",
"additionalProperties": {
"type": "string"
}
},
"reputation": {
"type": "int32"
},
"total_votes": {
"type": "object",
"properties": {
"harmless": {
"type": "int32"
},
"malicious": {
"type": "int32"
}
}
},
"last_analysis_stats": {
"type": "object",
"properties": {
"harmless": {
"type": "int32"
},
"malicious": {
"type": "int32"
},
"suspicious": {
"type": "int32"
},
"undetected": {
"type": "int32"
},
"timeout": {
"type": "int32"
}
}
},
"last_analysis_results": {
"type": "object",
"additionalProperties": {
"type": "object",
"properties": {
"category": {
"type": "string"
},
"engine_name": {
"type": "string"
},
"method": {
"type": "string"
},
"result": {
"type": [
"string",
"null"
]
}
}
}
},
"categories": {
"type": "object",
"description": "Category assignments per categorisation engine.",
"additionalProperties": {
"type": "string"
}
},
"tags": {
"type": "array",
"items": {
"type": "string"
},
"description": "Community / engine tags."
}
}
},
"relationships": {
"type": "object",
"description": "Pre-expanded relationships, keyed by relationship name.",
"additionalProperties": true
}
},
"required": [
"id",
"type",
"attributes"
]
}
Work with this as data
Every JSON Structure here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for json structure
4 MCP tools reach this
find_json_structuresBrowse and filter every JSON Structure in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/json-structures/virustotal-url-object-structure"
curl "https://apis.io/api/v1/json-structures?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.