amsi.fail favicon

amsi.fail

Category: Technology

Scanned: Aug 27, 2026, 09:56 PM UTC · First seen: Aug 27, 2026 · Threat Engines: 0 / 91 · Times Scanned: 1
90 / 100 Trust Score Based on scan findings at the time of analysis
No Threats Found
0 - High Risk50 - Moderate100 - No Threats
Not scanned has not been scanned yet. Hit Scan Now to check it.

Scans can take up to 5 minutes to complete. Please keep this tab open - we'll redirect you to the report when it's ready.

Failed
Scan unavailable
Scan failed
Screenshot of amsi.fail Captured Aug 27, 2026
https://amsi.fail
Screenshot of amsi.fail
6 years
Not Ranked - This website does not appear in the Tranco top list
Not listed (91 checked)
✓ Valid (TLS)
Cloudflare, Inc.
Toronto, Canada
cloudflare
Unknown
104.21.43.86
Domain & WHOIS Information
Registrar Cloudflare, Inc.
Registered August 22, 2020
Expires August 22, 2027
Name Servers emerie.ns.cloudflare.com
DNSSEC Unsigned
Hosting Cloudflare, Inc.
Reputation & Threat Check 91 security engines checked
File Scan Summary Powered by Quttera Engine
3 files scanned
No threats
0
Low Risk
0
Medium Risk
3
High Risk
0
No threats Low Risk Medium Risk High Risk
amsi.fail/index.html 23.4 KB Flagged: medium risk
amsi.fail/# 23.4 KB Flagged: medium risk
amsi.fail/js/amsi-engine.js 31.7 KB Flagged: medium risk
Quttera flagged medium risk files - is this your website?
Investigate and remove potential threats with Quttera
Remove Malware

Quttera Web Malware Removal is a paid subscription service. Pricing, plans, and trial availability are set by Quttera. Quttera is operated by Quttera Ltd, an independent third-party company unrelated to RCS LT. PCrisk.com may earn a referral commission when users sign up through this link.

External Links & Domains
15
External Links
1 Flagged
0
Iframes
Clean
7
Referenced Domains
1 Flagged
2
Flagged Resources
Detected
rastamouse.meFlagged: Generic Suspicious Object
https://rastamouse.me/memory-patching-amsi-bypass/Flagged: Generic Suspicious Object
https://rastamouse.me/memory-patching-amsi-bypass/Flagged: Generic Suspicious Object
http://amsi.fail/index.htmlNot flagged
http://amsi.fail/js/amsi-engine.jsNot flagged
https://fonts.googleapis.comNot flagged
https://fonts.googleapis.com/css2?family%3DJetBrains+Mono:wght@400%3B500%3B700&family%3DIBM+Plex+Sans:wght@300%3B400%3B500%3B600&display%3DswapNot flagged
https://fonts.gstatic.comNot flagged
https://github.com/CCob/SharpBlockNot flagged
https://github.com/FlangvikNot flagged
https://github.com/Flangvik/AMSI.failNot flagged
https://github.com/MartinIngesenNot flagged
https://github.com/S3cur3Th1sSh1t/Amsi-Bypass-PowershellNot flagged
https://github.com/rasta-mouseNot flagged
https://twitter.com/mattifestationNot flagged
https://twitter.com/mattifestation/status/735261120487772160Not flagged
https://www.mdsec.co.uk/2018/06/exploring-powershell-amsi-and-logging-evasion/Not flagged
rastamouse.meFlagged: Generic Suspicious Object
amsi.failNot flagged
fonts.googleapis.comNot flagged
fonts.gstatic.comNot flagged
github.comNot flagged
twitter.comNot flagged
www.mdsec.co.ukNot flagged
amsi.fail Overview

Description of amsi.fail

amsi.fail appears to be a niche cybersecurity tool website focused on Microsoft Windows AMSI, the Antimalware Scan Interface. Based on the page title, metadata, and visible interface, the site provides a generator for obfuscated PowerShell snippets intended to break or disable AMSI within the current process, along with explanatory material and links to related research and code repositories.

The site appears to be operated as a technical project rather than a commercial service. Its homepage references developer-oriented resources such as code hosting profiles, security research articles, and social posts from known infosec sources, which suggests the audience is likely security researchers, red-team practitioners, penetration testers, or advanced administrators studying AMSI behavior and bypass techniques.

Although the content appears educational or tooling-oriented, the subject matter is dual-use. Tools that disable or evade security controls may be used in legitimate testing environments, but they may also be misused outside authorized contexts.

Safety Assessment for amsi.fail

At the time of this scan, no detections were reported by 0 out of 91 security engines, and the domain was not listed by the checked content-malice and phishing blacklist databases. The domain is also several years old, which can be a stabilizing signal when considered alongside clean multi-engine and blacklist results.

One malware scanner did label the page and several related resources as suspicious, and it also flagged a linked research article and referenced domain with a generic suspicious classification. Based on the available details, this appears to be a low-confidence heuristic result tied to the site's AMSI-bypass content rather than broad consensus from multiple security engines. Because the website explicitly offers PowerShell code intended to disable or evade an antimalware interface, some scanners may treat the content as potentially risky or offensive-security related even when no direct malware payload is detected.

In practical terms, the main concern here appears to be the nature of the content rather than evidence of active phishing, malware hosting, or blacklist activity. Visitors should still use caution, especially in managed enterprise environments, because generated bypass code may violate policy or trigger endpoint defenses. Based on available scan data, no significant threats were detected at the time of this scan.

Technical Description

The domain uses a valid SSL/TLS certificate issued by a mainstream certificate authority, with expiry shown as 2026-11-24. It is hosted behind Cloudflare infrastructure on IP address 104.21.43.86, with Cloudflare nameservers and a web server response identified as Cloudflare. The domain has been registered for about six years and is currently set to expire in 2027.

DNSSEC appears to be unsigned, which is not uncommon but means DNS responses do not benefit from that additional integrity layer. No major infrastructure-level warning signs were provided in the scan data, and the blacklist checks were clean at the time of review. The primary technical caution is content-related: the site distributes AMSI-bypass generation logic, which may be treated as suspicious by some defensive tools.

HTTP Redirect Chain
No redirects detected - direct connection to destination
Website Insights
Not Ranked
Tranco Rank
Not in Top 1M
Visitors Unknown
Category: Technology
Rank History (30 days)
No rank data available
No cookies data available
Dispute This Score For website owners
Believe this score is inaccurate?
If you are the website owner and believe the scan results contain errors or false positives, you can submit a dispute for manual review. Our team typically responds within 1-2 business days.
You will be asked to verify your email before the dispute can be processed.
By submitting this form, you confirm that the information provided is accurate. Disputes are reviewed manually and results may take up to 48 hours to update.
One more step…
To submit your dispute for amsi.fail, please click the verification link we just emailed you. Once verified, we'll review it within 1-2 business days.
This report was generated automatically and is provided for informational purposes only. Results are based on a point-in-time scan and may contain false positives or incomplete data. This does not constitute a security audit or certification. No vendor in the market can guarantee a 100% detection rate. If you believe this report is inaccurate, please submit a dispute.

Share your experience with this website. Was it safe? Did you encounter any issues?