malware-intel
ANY.RUN
An interactive online malware sandbox whose public report feed makes a large corpus of analyses freely browsable. You search and read public reports on the website; the API is limited to paid plans. Reach for it when you want to see how a suspicious file behaves when run, without executing it yourself.
No programmatic check, opens the archive’s own search.
Why it’s useful & how it works
ANY.RUN is an interactive sandbox, meaning you can watch a file execute in a browser-based virtual machine in real time and interact with it as it runs. Its community feeds a large public corpus of analyses, which you can browse and search freely on the website without an account: look up a known hash or browse recent public submissions to find existing reports on a sample. Submitting your own files for analysis and accessing the full API require a paid plan, but reading public reports is free.
What’s inside
ANY.RUN's community ran 6.8 million sandbox sessions in 2025 alone, a 72 percent increase over 2024, and the platform has collected roughly 3.8 billion indicators of compromise cumulatively. The public report archive covers a wide variety of Windows, Linux and web-based threats.
API access
https://api.any.run/v1/ (API-Key; paid plans only)
An API key is required (usually free); see the endpoints above for where to get one.
What we measured
Our own probes, not the archive’s own claims. Re-run periodically; every reading below is dated.
Reachability
- Direct request
- Responded HTTP 200 456 ms
- Through a datacenter proxy
- Responded HTTP 200 1.4 s
- API, direct
- Not found HTTP 404 161 ms
- API, through a proxy
- Not found HTTP 404 878 ms
Reachability measured 2026-08-22.
Access
Freely reachable, no key, login, or captcha.