Rust CLI that scans every file in a folder against VirusTotal using SHA-256 hashes.
Repository: https://github.com/Sam97300/VT-scan
For each file it:
- Computes the SHA-256 hash
- Looks up that hash on the VirusTotal API
- Prints a table with status, engine detections, and malware names
API requests run concurrently but are rate-limited to 4 requests per minute (VirusTotal free tier).
git clone https://github.com/Sam97300/VT-scan.git
cd VT-scan
cargo build --releaseBinary: target/release/vt-scan (or vt-scan.exe on Windows).
Install globally:
cargo install --path . --force# API key via environment variable (recommended)
set VT_API_KEY=your_key_here # Windows cmd
$env:VT_API_KEY="your_key_here" # PowerShell
export VT_API_KEY=your_key_here # bash
vt-scan path/to/folder
# Or pass the key on the command line
vt-scan path/to/folder --api-key your_key_here
# Only top-level files (no subdirectories)
vt-scan path/to/folder --no-recursive
# Tune concurrent hashing/tasks (API is still limited to 4/min)
vt-scan path/to/folder --concurrency 4┌──────────────┬─────────┬─────────────────┬────────────────────────────┐
│ Filename │ Status │ Engines flagged │ Malware names │
├──────────────┼─────────┼─────────────────┼────────────────────────────┤
│ app.exe │ clean │ 0 │ — │
│ sample.bin │ flagged │ 12 │ Trojan.Generic, … │
│ brand_new.dat│ unknown │ — │ — │
└──────────────┴─────────┴─────────────────┴────────────────────────────┘
Summary: 3 file(s) — 1 clean, 1 flagged, 1 unknown (not in VT), 0 error(s)
| Status | Meaning |
|---|---|
| clean | Present in VT; no malicious/suspicious detections |
| flagged | One or more engines marked it malicious/suspicious |
| unknown | Hash not found on VirusTotal |
| error | Hash or API failure |
Exit code 2 if any file is flagged (useful in scripts).
Do not commit API keys. Prefer VT_API_KEY. If a key was shared or committed to git, revoke/regenerate it in your VirusTotal account.