Malware analysis and URL scanning
MalwareAnalyzer by Cyble is a public malware analysis and threat intelligence platform. Submit a file, a URL, or a hash and get a verdict backed by multi-engine static scanning, real sandbox detonation, extracted indicators, and a threat graph you can pivot through. Public analysis is free and unlimited.
Platform activity
- 89,836 public analysis reports
- 50 detection engines on a recent analysis
- 0 analyses completed in the last hour
What runs on every submission
- Multi-engine static analysis. Antivirus, YARA rule packs and hash reputation engines run over every sample, alongside parsers for PE, ELF, Mach-O, Android packages, Office documents, PDFs and email carriers. Every engine is named on the report with its own result, including the engines that found nothing.
- Real sandbox detonation. Windows and Linux samples execute in instrumented full-system sandboxes with controlled network egress, recording the process tree, API activity, dropped files, memory artefacts and captured traffic. Behaviour is never simulated, and a run that captured nothing is labelled as incomplete rather than presented as clean.
- Interactive live VM. Drive a sample yourself in a live desktop session when a payload needs a click or a decision an automated run cannot make.
- URL and phishing analysis. Pages are fetched through an egress-locked scanner and rendered in an isolated browser, capturing requests, cookies, scripts and a screenshot, with brand impersonation, homograph names, phishing kits and credential-harvesting forms called out.
- Threat graph and pivots. Move from a sample to its infrastructure, its family, the URLs it contacts and the samples that resemble it.
- Built to integrate. A documented REST API and OpenAPI specification, STIX 2.1 and CSV feeds, a TAXII endpoint, SIEM and SOAR connectors, and downloadable PDF or Word reports.
How an analysis runs
- Submit a file, a URL, or a hash. Files are hashed in the browser first, so a sample already in the corpus returns its existing report immediately.
- The static engine roster scans the bytes while parsers extract structure, strings, imports, certificates and embedded indicators.
- Executable types are queued to a sandbox guest and run for real. A submission waits for a genuine slot rather than degrading to a lesser analysis.
- Read the fused verdict with every contributing signal, pivot through the indicators, and export the result as a document, a STIX bundle, or an API response.
Malware families in this corpus
ATT&CK techniques observed
- T1566.002
- T1112
- T1105
- T1543.003
- T1071.001
- T1057
- T1547.001
- T1056.001
- T1055
- T1059.001
- T1059.004
- T1003
- T1555
- T1486
- T1571
- T1497
- T1071.004
- T1218.005
- T1053.005
- T1562.001
- T1016
- T1033
- T1082
- T1003.001
Common questions
- What is MalwareAnalyzer?
- MalwareAnalyzer is a public malware analysis and threat intelligence platform. You submit a file, a URL, or a hash, and it returns a verdict backed by multi-engine static scanning, real sandbox execution, extracted indicators, and a threat graph you can pivot through.
- Is it free to use?
- Yes. Submitting files and URLs for public analysis is unlimited and free, including the full report. Dataset lookups are capped per day, and premium compute such as private analysis, deep URL scans and the AI assistant spends credits. Every account starts with a free credit grant.
- Do you actually execute the file, or only scan it?
- Both. Every submission runs through a static tier of antivirus, YARA and hash reputation engines, and executable file types are then detonated in an instrumented full-system sandbox that records the process tree, API activity, files written and network traffic. Behaviour is never simulated or inferred: if a sandbox did not capture a trace, the report says so.
- Which operating systems can you detonate on?
- Windows and Linux samples run in full-system sandboxes with controlled network egress, and Office documents and PDFs are opened in real reader applications on both. Android packages are analysed statically and detonated when the Android tier is attached. There is no macOS sandbox, so Mach-O samples receive static analysis and lightweight emulation only, which the report states plainly.
- Can I scan a website instead of a file?
- Yes. A URL scan fetches the page through an egress-locked scanner, records the redirect chain, certificate, headers and page structure, then renders it in an isolated browser to capture requests, cookies, scripts and a screenshot. The same detection engines that scan files are run over the page content and over any file the page serves.
- Is my submission public?
- Anonymous submissions are public, which is how the community corpus stays useful. Signed-in users can submit privately, and a private sample is never published, never indexed and never shown in the public feeds. URLs containing credentials or tokens are redacted automatically and forced private.
- How is the verdict decided?
- Signals from every tier are fused into one weighted score, and each report lists every signal that contributed with its weight, so a verdict can be audited rather than taken on trust. Engines that did not run are reported as not run, because an absent detection tier is not evidence that a file is safe.
- Can I use it from my own tools?
- Yes. There is a documented REST API with an OpenAPI specification, a Model Context Protocol server for AI assistants, STIX 2.1 and CSV threat feeds, a TAXII endpoint, and push connectors for common SIEM and SOAR platforms. Reports can also be downloaded as PDF or Word documents.
- What does it mean when a report says analysis was degraded?
- It means a tier that should have run did not complete, so its section is incomplete. The platform marks these runs rather than presenting reduced coverage as a clean result, and a degraded sample is eligible for automatic re-analysis. A report with no findings and no degradation notice is a real negative result.
- Who runs MalwareAnalyzer?
- MalwareAnalyzer is a product from Cyble, a US-headquartered threat intelligence company and a Y Combinator W21 company.