Malware analysis and URL scanning

MalwareAnalyzer by Cyble is a public malware analysis and threat intelligence platform. Submit a file, a URL, or a hash and get a verdict backed by multi-engine static scanning, real sandbox detonation, extracted indicators, and a threat graph you can pivot through. Public analysis is free and unlimited.

Platform activity

What runs on every submission

How an analysis runs

  1. Submit a file, a URL, or a hash. Files are hashed in the browser first, so a sample already in the corpus returns its existing report immediately.
  2. The static engine roster scans the bytes while parsers extract structure, strings, imports, certificates and embedded indicators.
  3. Executable types are queued to a sandbox guest and run for real. A submission waits for a genuine slot rather than degrading to a lesser analysis.
  4. Read the fused verdict with every contributing signal, pivot through the indicators, and export the result as a document, a STIX bundle, or an API response.

Malware families in this corpus

ATT&CK techniques observed

Common questions

What is MalwareAnalyzer?
MalwareAnalyzer is a public malware analysis and threat intelligence platform. You submit a file, a URL, or a hash, and it returns a verdict backed by multi-engine static scanning, real sandbox execution, extracted indicators, and a threat graph you can pivot through.
Is it free to use?
Yes. Submitting files and URLs for public analysis is unlimited and free, including the full report. Dataset lookups are capped per day, and premium compute such as private analysis, deep URL scans and the AI assistant spends credits. Every account starts with a free credit grant.
Do you actually execute the file, or only scan it?
Both. Every submission runs through a static tier of antivirus, YARA and hash reputation engines, and executable file types are then detonated in an instrumented full-system sandbox that records the process tree, API activity, files written and network traffic. Behaviour is never simulated or inferred: if a sandbox did not capture a trace, the report says so.
Which operating systems can you detonate on?
Windows and Linux samples run in full-system sandboxes with controlled network egress, and Office documents and PDFs are opened in real reader applications on both. Android packages are analysed statically and detonated when the Android tier is attached. There is no macOS sandbox, so Mach-O samples receive static analysis and lightweight emulation only, which the report states plainly.
Can I scan a website instead of a file?
Yes. A URL scan fetches the page through an egress-locked scanner, records the redirect chain, certificate, headers and page structure, then renders it in an isolated browser to capture requests, cookies, scripts and a screenshot. The same detection engines that scan files are run over the page content and over any file the page serves.
Is my submission public?
Anonymous submissions are public, which is how the community corpus stays useful. Signed-in users can submit privately, and a private sample is never published, never indexed and never shown in the public feeds. URLs containing credentials or tokens are redacted automatically and forced private.
How is the verdict decided?
Signals from every tier are fused into one weighted score, and each report lists every signal that contributed with its weight, so a verdict can be audited rather than taken on trust. Engines that did not run are reported as not run, because an absent detection tier is not evidence that a file is safe.
Can I use it from my own tools?
Yes. There is a documented REST API with an OpenAPI specification, a Model Context Protocol server for AI assistants, STIX 2.1 and CSV threat feeds, a TAXII endpoint, and push connectors for common SIEM and SOAR platforms. Reports can also be downloaded as PDF or Word documents.
What does it mean when a report says analysis was degraded?
It means a tier that should have run did not complete, so its section is incomplete. The platform marks these runs rather than presenting reduced coverage as a clean result, and a degraded sample is eligible for automatic re-analysis. A report with no findings and no degradation notice is a real negative result.
Who runs MalwareAnalyzer?
MalwareAnalyzer is a product from Cyble, a US-headquartered threat intelligence company and a Y Combinator W21 company.

Explore