Easily Report Phishing and Malware

This is how you can strike back at criminals sending phishing spam - by getting their webpages on blacklists. Blocking their sites helps protect other people and helps researchers trying to stop this. Sites can be blocked within 15 minutes of your report, but you may not immediately see it. [Page last updated 2017-04-06]

Report phishing website:

Right-click the link in the phishing email, and copy the hyperlink. Do not click the link, which is less useful to security companies.

  1. urlscan.io - (Optional) Quickly get a screenshot and redirects
  2. VirusTotal - Send to computer security companies
  3. UrlQuery.net - Get screenshot, analyze for known risks, create public record (don't need to wait)
  4. Google SafeBrowsing - Block in Chrome, Firefox, Android, iPhone, and Google
  5. NetCraft - Send to computer security companies
  6. ESET
  7. Kaspersky
  8. Symantec - Submit to Norton and Blue Coat
  9. McAfee - Select real-time, click Check, and click Submit at the bottom
  10. Websense/Forcepoint
  11. Cisco PhishTank - Very effective, but requires registration
  12. Webroot BrightCloud - Provides data to PaloAlto firewalls, many others

    Report phishing/file hosting abuse directly:

    Extra-credit phishing reporting:

    Via Twitter:
    If you have a Twitter account, message these people the link (add a space somewhere so clicking it doesn't work). They are high-powered researchers with lots of connections who track down clues and shut down entire constellations of fraud. Like computer Batman.

    Other malware tools:

    Report malware:

    1. VirusTotal.com (Shares reports publicly, shares files with Premium subscribers)
    2. Hybrid-Analysis.com (Shares reports and files publicly, uses Payload Security's VxStream sandbox)
    3. Malwr.com (Shares reports and files publicly)
    4. Microsoft (Select 'Home User')
    5. Webroot (Detections and threat intelligence go to multiple other products)
    6. Kaspersky
    7. ClamAV (Especially for files that came through email, used in many spam filters)
    8. Emsisoft
    9. Fortiguard (leave name and email blank and hit scan)
    10. OPSWAT Metadefender (EXE only)

    Report phishing/spam text (SMS) message:

    Copy the contents of the spam SMS and paste it into a message to this four-digit number. This reports it to your phone company so they can search for who sent it and block them. Don't click the link, it could be dangerous!

        7 7 2 6  ( S - P - A - M )

    On iPhone: Hold your finger on the message, tap "More...", tap the Forward icon in the bottom right of the screen.

    Report unsolicited calls and SMS

    Use the form on SpamResponse.

    Report abuse to website hosts:

    Find who hosts the website with WhoIsHostingThis and search Google for "webhost + abuse" to find their complaint contact information.

    Investigate suspicious websites:

    You can always get here by typing GotPhish.com