Skip to main content
POST
Malware Scan
Malware Scan returns one safety verdict for a URL, QR code, barcode, image, or file. POST /api/lookup/malware/scan Requires an Encrata API key in the Authorization header.

Request

All five scan types use the same endpoint. Set kind to select the input and scanner.
string
required
One of url, qr, bar, image, or file.
string
URL to inspect. Required when kind is url.
string
Base64-encoded bytes. Required for qr, bar, and image. For file, send either this field or source_url.
string
Short-lived download URL for a file. Available only when kind is file. The downloaded file can be up to 100 MiB.
string
Original file name. Send it with uploaded images and files so extension checks and file scanners have the expected context.
boolean
default:"false"
Include a STIX 2.1 bundle in result.stix.

Examples

Response

Every scan returns the {success, result, message} envelope. Start with result.verdict, then inspect signals and the fields for the selected kind.

Common fields

boolean
Whether the scan completed.
string
Malicious content detected., This item looks suspicious - review the signals., No threats found., or Scan complete..
object
The scan verdict and kind-specific analysis.

URL fields

Page analysis is static. Encrata does not execute scripts from the scanned URL.

QR code and barcode fields

Each codes item can contain format, payload_type, redacted raw content, final_url, verdict, score, signals, error_correction, pixel position, structured-append sequence, parsed payload, and url_scans. The parsed payload can describe URLs, Wi-Fi configuration without the password, payment details, phone numbers, email messages, SMS messages, coordinates, contacts, one-time password metadata without the secret, device links, FIDO data, app-install links, scripts, or text.

Image fields

File fields

A file result uses the common fields plus sha256, file_type, and a SHA-256 indicator in iocs. The signals array contains malware and rule matches.

Errors

Errors use {"success": false, "result": {"code": "..."}, "message": "..."}.

Credits

Each successful scan costs 1 credit. Repeating the same kind with the same content does not charge your account twice. See Credits.