> For the complete documentation index, see [llms.txt](https://docs.hex-rays.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/multi-service-checker.md).

# Multi-Service Checker

Before you start your own analysis, find out what is already known about the sample. The multi-service checker asks external services, such as VirusTotal, VMRay, and MalwareBazaar, if they know the sample. If a service knows it, you can quickly open its results and collect the existing analysis and background context.

The checker searches each service by the SHA-256 hash of the input file, so you get results before auto-analysis completes. If a service does not know the sample, you can upload it. By default, the checker asks for confirmation before each upload.

To open the panel, select **Malware Analysis > Services Checker > Open panel...** or press `Shift-U`. The checker keeps the results in the IDB, so the next time you open the panel, it searches only the services that have no result yet. To search all services again, select **Reanalyse**.

## Configuration

To change the settings, select **Malware Analysis > Services Checker > Configure...**, or use HCLI:

```bash
hcli extension config ida-multiservice-checker set vt_api_key <KEY>
```

Restart IDA after you change a setting.

| Setting             | Default                      | Description                                                                                                                                                                              |
| ------------------- | ---------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `vt_api_key`        | empty                        | VirusTotal API key. If empty, the VirusTotal row shows "Not configured" and the checker does not search VirusTotal.                                                                      |
| `vmray_api_key`     | empty                        | VMRay API key. If empty, the VMRay row shows "Not configured".                                                                                                                           |
| `vmray_host`        | `https://eu.cloud.vmray.com` | URL of the VMRay server, including the scheme. Change this for a different VMRay cloud region or an on-premises server.                                                                  |
| `mb_api_key`        | empty                        | MalwareBazaar authentication key, from [abuse.ch](https://auth.abuse.ch/). MalwareBazaar needs the key for searches and uploads. If empty, the MalwareBazaar row shows "Not configured". |
| `mb_anonymous`      | `false`                      | If `true`, uploads to MalwareBazaar are anonymous. This setting has no effect on searches.                                                                                               |
| `run_at_startup`    | `false`                      | If `true`, the panel opens automatically the first time you open a database.                                                                                                             |
| `ask_before_upload` | `true`                       | If `true`, the checker asks for confirmation before each upload. If `false`, an upload starts immediately when you click **Upload**.                                                     |
| `network_timeout`   | `60`                         | Timeout in seconds for each search and upload request.                                                                                                                                   |

{% hint style="info" %}
The automated unpacker has its own `vt_api_key`, `vmray_api_key`, and `vmray_host` settings. To use VirusTotal and VMRay in both components, set the keys in both.
{% endhint %}


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.hex-rays.com/ida-9.5/add-ons/malware/concepts/multi-service-checker.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
