> For the complete documentation index, see [llms.txt](https://tools.osintnewsletter.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://tools.osintnewsletter.com/osint-tools/scanmalware.md).

# ScanMalware

Tool Description : An online URL and website security-analysis platform for investigating potentially malicious or suspicious websites.

| **Tool name**    | **Quick Overview**                                                                                                                                                                                        |
| ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| URL              | <https://scanmalware.com/>                                                                                                                                                                                |
| What it does     | Scans URLs/websites for malware, phishing, suspicious scripts, redirects, malicious indicators and other security threats                                                                                 |
| How to use it    | Enter a URL into the scanner, select the appropriate visibility option (public, unlisted, private), submit and review the resulting security report.                                                      |
| Cost             | Free.                                                                                                                                                                                                     |
| Account required | No for ordinary public URL scanning. Authentication is required for private scans.                                                                                                                        |
| Cookies          | Cloudflare security cookies and a Matomo analytics identifier.                                                                                                                                            |
| Ownership        | Triop AB, based in Funäsdalen, Sweden, founded by Jonas Legion.                                                                                                                                           |
| Use in Reporting | Useful for documenting the security characteristics of suspicious URLs, including risk scores, detected indicators, redirects, scripts, forms, contacted infrastructure and other technical observations. |

### What does ScanMalware do?

ScanMalware opens a URL inside a sandboxed, instrumented browser so you do not have to touch it yourself, and records what the page actually did: the screenshot, every host and IP contacted, the ASNs behind them, the TLS certificate served, the JavaScript loaded, the technologies detected, and any YARA rules that matched.

The part that separates it from a plain scanner is that every scan stays searchable. The archive holds over 551,000 scans and can be pivoted by domain, IP, ASN, JARM fingerprint, favicon hash, screenshot hash, TLSH or ssdeep fuzzy hash, OCR text from the rendered page, and JavaScript fingerprint. So a single suspicious link becomes a way into the rest of the infrastructure behind it, rather than a single verdict.

**The lowdown:** It’s a free sandboxed browser for suspicious links, with a public scan archive you can pivot through, and no account or API key needed for any of it.

### How to Use:

**1. Copy the suspicious URL you want to investigate and enter it into the ScanMalware URL scanner. Select the appropriate visibility option (public, unlisted, private).**

<img src="https://2429831402-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3YeRsjw1gI6xxIP4cuOd%2Fuploads%2FQGdP78Iv0krJjMNLK5XH%2Funknown.png?alt=media&amp;token=1a0da1b0-fafd-4066-9bb8-c75c1afe25dc" alt="" height="221" width="602">

**2. Submit the URL and allow ScanMalware to perform its browser-based analysis.**&#x20;

Read the Summary and Screenshot first. The screenshot tells you what a visitor would actually have seen, which is often enough on its own for a phishing or scam page. The summary carries the verdict and the headline findings.

<img src="https://2429831402-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3YeRsjw1gI6xxIP4cuOd%2Fuploads%2Fb5YOL1VcqPew9yaF10E1%2Funknown.png?alt=media&amp;token=0001a84c-09c6-48c2-9df2-9cd6ed9ef784" alt="" height="429" width="602">

**3. Work through the detail tabs. HTTP shows every request the page made, TLS shows the certificate served, JavaScript shows what code loaded and how it was fingerprinted, Technologies shows what the site is built on, and IOC shows any threat-intelligence matches.**

<img src="https://2429831402-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3YeRsjw1gI6xxIP4cuOd%2Fuploads%2FArNPErKR9QJWcRgqevwa%2Funknown.png?alt=media&amp;token=71415273-96ce-4b71-a020-cb08b6bbb9c1" alt="" height="303" width="602">

**4. Pivot, which is the step most people skip. Take an artefact from the result, the JARM fingerprint, the favicon hash, an IP or the certificate, and search the archive for everything else that matches. This is what turns one suspicious link into the cluster of sites behind the same operation.**

**5. Share the result URL. Every scan has a permanent public link that needs no account to open, so it can go straight into a report or a ticket.**

**Top tip:** Search the archive before you scan. If the domain has been seen already you get its history for free, and you avoid touching the target at all.

### Cost

* [x] Free
* [ ] Partially Free
* [ ] Paid

## Data Processing

### Account Required:

* [ ] Yes
* [x] No

No for ordinary public URL scanning. Authentication is required for private scans.

### Cookies:&#x20;

ScanMalware uses Cloudflare security cookies such as cf\_clearance to support anti-bot/security controls. The site also sets \_pk\_id.1.6111, a Matomo analytics identifier used to distinguish returning visitors. Cookie behaviour may vary depending on consent and site configuration.

### Use in Reporting

ScanMalware can be used to:

* Assess whether a website or URL exhibits indicators associated with malware, phishing or other malicious activity.
* Examine suspicious websites and webpages encountered during an OSINT investigation.
* Identify redirects associated with a suspicious URL.
* Examine domains and IP addresses contacted by a webpage.
* Investigate hosting, ASN and network infrastructure associated with a website.
* Examine JavaScript and other scripts loaded by a webpage.
* Identify forms that may be used to collect credentials or payment information.
* Examine cookies, HTTP requests and other webpage/network characteristics.
* Identify technologies, frameworks and services used by a website.
* Examine TLS certificates and JARM fingerprints associated with web infrastructure.
* Obtain screenshots and visual information about a suspicious webpage.
* Compare technical indicators against threat-intelligence and malware/phishing detection sources.
* Generate investigative leads concerning phishing sites, scam websites, malware distribution infrastructure, domains, IP addresses and associated technical infrastructure.&#x20;

| **Capabilities**                                                                                                                                          | **Limitations**                                                                                                        |
| --------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- |
| Sandboxed rendering of any URL, with screenshot and full technical record.                                                                                | Public scans are visible to everyone, so it is the wrong tool for sensitive URLs unless you use an unlisted scan.      |
| Public archive of 551,000+ scans, searchable and permanently linkable.                                                                                    | Some sites block automated scanners or serve different content to them, so a clean result is not proof a site is safe. |
| Pivots that most scanners do not expose: JARM, favicon hash, screenshot perceptual hash, TLSH and ssdeep fuzzy hashes, OCR text, JavaScript fingerprints. | The target may see the scan, as with any remote scanner.                                                               |
| YARA rule matches, TLS certificate and Certificate Transparency data, RDAP records, detected technologies, and clipboard-hijack / pastejacking detection. | Subdomain and certificate history covers a recent window rather than the full history of a domain.                     |
| <p>Full REST API with no key required, plus an MCP server for use from AI tooling.</p><p><br></p>                                                         | Smaller archive than the longest-established scanners, so a quiet domain may have no history.                          |

### Summary

ScanMalware is a free sandboxed URL scanner whose real strength is the archive behind it. It is most useful in the analysis and pivoting stages of an investigation: scan or look up a suspicious link, confirm what the page actually does, then use the fingerprints to find the rest of the same operation. That it needs no account and no API key makes it practical to share results with colleagues, and easy to reach for during triage.

### Ownership

Triop AB, based in Funäsdalen, Sweden, founded by [Jonas Lejon.](https://x.com/jonasl?lang=en)

### Ethical Considerations

* Only scan URLs you are authorised to investigate.
* Remember that public scans are published. Do not submit links containing session tokens, password-reset URLs, personal data or anything else you would not put on a public page. Use an unlisted scan when in doubt.
* The target site may detect the scan, so it is not a covert technique.
* Do not use the archive to compile information about private individuals
* Follow your organisation's own rules and applicable law.

### Related Tools:

* VirusTotal
* [URLscan.io](/osint-tools/urlscan.md)

#### Sources

<https://scanmalware.com/>&#x20;

<https://x.com/jonasl?lang=en>&#x20;

<https://scanmalware.com/api-docs>

<https://github.com/scanmalware/mcp-server>

<https://triop.se>

<https://github.com/jivoi/awesome-osint>

<https://github.com/The-Art-of-Hacking/h4cker>  <https://github.com/mesquidar/ForensicsTools>

<https://github.com/soxoj/awesome-osint-mcp-servers><br>

*With thanks to* [*Jonas Lejon*](https://x.com/jonasl?lang=en) *for submitting this tool to the OSINT Tool Library.*&#x20;
