Python调用VirusTotal API遇ReadTimeout异常求助
requests访问VirusTotal API触发ReadTimeout异常的排查与解决建议
问题现象
使用Python的requests库调用VirusTotal API时,触发ReadTimeout异常,报错回溯如下:
Traceback (most recent call last): ... requests.exceptions.ReadTimeout: HTTPSConnectionPool(host='www.virustotal.com', port=443): Read timed out. (read timeout=None)
异常情况:Chrome浏览器可正常访问VirusTotal,但Edge浏览器会显示ERR_TIMED_OUT错误。
相关代码
简化复现代码
import requests def get_ip_report_vt(ip): url = f"https://www.virustotal.com/api/v3/ip_addresses/{ip}" headers = { "x-apikey": "YOUR_API_KEY" } response = requests.get(url, headers=headers) return response.json() # Process IP list def process_ip_list(input_csv_file, output_csv_file): ip = "8.8.8.8" # Example IP vt_score, vt_country, vt_organization = get_ip_report_vt(ip) # Further processing... process_ip_list("input.csv", "output.csv")
完整脚本
import requests import csv import time # API keys for VirusTotal and AbuseIPDB VIRUSTOTAL_API_KEYS = [ 'YOUR_VIRUSTOTAL_API_KEY' # Replace with your actual API key ] ABUSEIPDB_API_KEYS = [ 'YOUR_ABUSEIPDB_API_KEY' # Replace with your actual API key ] # Round-robin index counters vt_key_index = 0 abuseipdb_key_index = 0 # Function to get the next API key def get_next_api_key(api_keys, index): key = api_keys[index % len(api_keys)] index += 1 return key, index # Function to query VirusTotal for IP report def get_ip_report_vt(ip): global vt_key_index api_key, vt_key_index = get_next_api_key(VIRUSTOTAL_API_KEYS, vt_key_index) url = f"https://www.virustotal.com/api/v3/ip_addresses/{ip}" headers = {"x-apikey": api_key} try: response = requests.get(url, headers=headers) response.raise_for_status() # Raises an error for HTTP codes 4xx/5xx data = response.json() return data['data']['attributes']['reputation'], data['data']['attributes']['country'] except requests.exceptions.RequestException as e: print(f"VirusTotal Error for IP {ip}: {e}") return None, None # Function to query AbuseIPDB for IP report def get_ip_report_abuseipdb(ip): global abuseipdb_key_index api_key, abuseipdb_key_index = get_next_api_key(ABUSEIPDB_API_KEYS, abuseipdb_key_index) url = "https://api.abuseipdb.com/api/v2/check" headers = {'Key': api_key, 'Accept': 'application/json'} params = {'ipAddress': ip} try: response = requests.get(url, headers=headers, params=params) response.raise_for_status() data = response.json() return data['data']['abuseConfidenceScore'], data['data']['countryCode'] except requests.exceptions.RequestException as e: print(f"AbuseIPDB Error for IP {ip}: {e}") return None, None # Main function to process IPs def process_ip_list(input_csv, output_csv): with open(input_csv, 'r') as infile, open(output_csv, 'w', newline='') as outfile: reader = csv.reader(infile) writer = csv.writer(outfile) writer.writerow(['IP', 'VT Score', 'VT Country', 'AbuseIPDB Score', 'AbuseIPDB Country']) next(reader) # Skip header for row in reader: ip = row[0] vt_score, vt_country = get_ip_report_vt(ip) abuse_score, abuse_country = get_ip_report_abuseipdb(ip) writer.writerow([ip, vt_score, vt_country, abuse_score, abuse_country]) time.sleep(1) # Respect rate limits # Example usage process_ip_list('ip_list.csv', 'ip_report_list.csv')
已完成的排查步骤
- 验证API密钥:确认密钥有效且处于激活状态
- 网络排查:
- 多浏览器测试:Chrome可正常访问VirusTotal,Edge报
ERR_TIMED_OUT - ping测试
www.virustotal.com结果为"Request timed out" - 切换为Google DNS(8.8.8.8/8.8.4.4)后Edge可访问,但代码仍超时
- 多浏览器测试:Chrome可正常访问VirusTotal,Edge报
- 防火墙/代理检查:关闭防火墙和代理后问题依旧
额外背景
- 脚本此前偶尔能正常运行,现在完全无法调用VirusTotal API
- 单独调用AbuseIPDB API可正常工作
- 之前处理100个IP后首次报错,后续偶尔恢复,更换新API密钥后仍无效
请求建议
请提供解决该网络问题或进一步排查的方向。
内容的提问来源于stack exchange,提问作者Shatha
相关产品推荐
相关产品推荐

