file-by-hash
VirusShare
An invite-only repository of tens of millions of malware samples, with hash lookup and sample download for members. Getting in means emailing the operator for an account; the API likewise needs the member key. Researchers turn to it when they need the actual sample behind a known hash and the open repositories do not have it.
Keine programmatische Prüfung, öffnet die eigene Suche des Archivs.
Warum es nützlich ist & wie es funktioniert
VirusShare is a high-barrier, invite-only repository aimed at researchers who need access to a very large collection of raw malware samples, including many not found in open repositories. To gain access you email the operator and request an account; once approved, the API key unlocks hash lookups and sample downloads. It is worth the extra step when you have a hash that simpler services cannot resolve, or when you specifically need the file itself rather than a report about it.
Was drinsteckt
VirusShare holds over 114 million malware samples, making it one of the largest privately held repositories accessible to vetted researchers. The collection spans well over a decade of continuous acquisition and covers an exceptionally wide range of malware families and file types.
API-Zugang
https://virusshare.com/apiv2/file?apikey= <KEY>&hash=<h>
Ein API-Schlüssel ist erforderlich (meist kostenlos); siehe die Endpunkte oben, wo du einen bekommst.
Zugang
May require solving a captcha before it responds.