Skip to content

Add ScanMalware to URL and Phishing Kit Analysis - #17

Open
jonaslejon wants to merge 1 commit into
K2SOsint:mainfrom
jonaslejon:add-scanmalware
Open

Add ScanMalware to URL and Phishing Kit Analysis#17
jonaslejon wants to merge 1 commit into
K2SOsint:mainfrom
jonaslejon:add-scanmalware

Conversation

@jonaslejon

@jonaslejon jonaslejon commented Aug 6, 2026

Copy link
Copy Markdown

I run ScanMalware (it's built by Triop AB in Sweden), so I want to be upfront about that rather than submit it as a neutral third party. Happy to close this if you'd prefer to be asked first — CONTRIBUTING says to contact you, and a PR is the easier thing to merge, but it's your call.

ScanMalware is a free URL scanner: submit any URL and it renders the page in a sandboxed browser, then reports phishing and malware verdicts, network requests, form analysis, TLS/JARM fingerprints and screenshots. No account is needed to scan or to browse the public scan feed, and the REST API allows 600 requests/minute anonymously (docs). There's also a public hunt roster tracking active campaigns, and a CLI.

I put it next to urlscan.io and URLquery since that's the closest functional group. One line, one file:

- [ScanMalware](https://scanmalware.com/) — Renders submitted URLs in a sandboxed browser and reports phishing, malware, network requests, and screenshots

Checked it isn't already listed anywhere in docs/. The lychee run on this PR needs your approval to start, but I verified separately that the URL answers 200 to both HEAD and GET with a lychee user-agent, so it shouldn't add noise to the daily check.

Unrelated, in case it's useful: the scheduled link check on main has been failing daily for at least the last four runs (Aug 3–6), so that job is already red before this change.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant