file-by-hash
VirusShare
An invite-only repository of tens of millions of malware samples, with hash lookup and sample download for members. Getting in means emailing the operator for an account; the API likewise needs the member key. Researchers turn to it when they need the actual sample behind a known hash and the open repositories do not have it.
Sin comprobación programática; abre la propia búsqueda del archivo.
Por qué es útil y cómo funciona
VirusShare is a high-barrier, invite-only repository aimed at researchers who need access to a very large collection of raw malware samples, including many not found in open repositories. To gain access you email the operator and request an account; once approved, the API key unlocks hash lookups and sample downloads. It is worth the extra step when you have a hash that simpler services cannot resolve, or when you specifically need the file itself rather than a report about it.
Qué contiene
VirusShare holds over 114 million malware samples, making it one of the largest privately held repositories accessible to vetted researchers. The collection spans well over a decade of continuous acquisition and covers an exceptionally wide range of malware families and file types.
Acceso por API
https://virusshare.com/apiv2/file?apikey= <KEY>&hash=<h>
Se requiere una clave de API (normalmente gratuita); consulta los endpoints anteriores para saber dónde obtenerla.
Acceso
May require solving a captcha before it responds.