Skip to content




VirusShare is a repository of malware samples to provide security researchers, incident responders, forensic analysts, and the morbidly curious access to samples of live malicious code.

The analyzer enables local searching for md5 hashes in hash list.


  • Download the VirusShare hashlists. For convenience the script is provided
  • In the analyzer parameters configure the path of downloaded hashlists folder.


Author: Nils Kuhnert, CERT-Bund
License: AGPL-V3
Version: 2.0
Supported observables types:
- hash
- file
Registration required: False
Subscription required: False
Free subscription: False
Third party service:


Search for MD5 hashes in hash list


path Define the path to the stored data
Default value if not configured N/A
Type of the configuration item string
The configuration item can contain multiple values False
Is required False

Templates samples for TheHive#

VirusShare: long report

Last update: November 15, 2021 06:39:13