Launch Offer: 80% off on kAIPTA certification voucher

Recon with VirusTotal That Actually Pays Bounty

Hello, Hope everyone is doing great. Today I'm gonna share a secret method that helps me to get more than 5000$ in bounties. Lets start.

Virustotal - It Analyse suspicious files, domains, IPs and URLs to detect malware and other breaches, automatically share them with the security community.

Virustotal is a gold mine for bug bounty hunters. This can reveal sensitive endpoint, live password reset tokens, active jwt tokens, invoice links, private docs etc etc.

How we can do this??

-> https://www.virustotal.com/vtapi/v2/domain/report?apikey=YOU_API_KEY&domain=SUB_DOMAIN

2026-01-28_21-52.png

Here you can see I've got some live fresh email verification links which leads to ATO and users invoice link which contains users PII information.

This bug was accepted by a private company which I cant disclose. Everyday I do virustotal dorking and see if there is anything new.

2026-01-28_22-00.png

You can automate this using various scripts available on internet.

-> https://github.com/orwagodfather/virustotalx

this tool is very nice by -> https://x.com/GodfatherOrwa

But I will suggest to do this manually

Saif Abdullah Khan Mahi

Networking & Offensive Security Specialist

Saif is a founding member of the Knight Squad community with a background in network engineering, hands-on web security testing, CTFs, and security research. He focuses on responsible vulnerability discovery and practical, real-world bug hunting workflows. Since 2023, he has been involved with the Yogosha Strike Force and has responsibly reported security findings to major organizations including Apple and Microsoft. He also contributes to the community by creating CTF challenges for competitions such as KnightCTF and BDSec CTF.