What Gridinsoft observed on Url.sg
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
- Reviewed
- by Gridinsoft Threat Analyst
- Analyst finding
- URL Shortening Service โ Destination-Specific Review Required
- Evidence basis
- First-party site analysis External vendor intelligence: Context only โ not used for this decision
The reviewed root site and public service pages did not show behavior supporting the prior domain-wide Distributes Malware or Unwanted File Download classification, and no specific malware file, payload, URL, or hash was found there. However, url.sg is a user-controlled URL-shortening namespace whose individual short codes can redirect to destinations that were not enumerated or reviewed. The service root appears operational, but the safety of the whole domain is inconclusive and each suspicious short link requires destination-specific review.
Analyst findings
Substantive URL-shortening service
The reviewed public pages consistently described and implemented the same URL-shortening, QR-code, bio-page, analytics, and API service, including same-origin account and support routes.
Prior malware-download classification not supported in reviewed scope
The direct first-party review did not identify an automatic or suspicious download, a malware payload, credential forwarding to an unrelated host, conditional external navigation, or other current behavior supporting a domain-wide malware-distribution classification.
Public short-link abuse reporting is available
The service exposed a dedicated same-origin report form for spam, fraud, malicious, and phishing short links, providing a public route for destination-specific abuse reports.
User-controlled short-link destinations require separate review
The service accepts user-selected destinations and issues redirecting short codes. The clean reviewed root and public service pages do not establish that every existing or future short code is safe, so the whole url.sg redirect namespace cannot receive a domain-wide Safe verdict from this scope.
Privacy and terms documentation needs correction
The privacy-policy link was unavailable and the Terms and Conditions page contained placeholder text. These gaps reduce transparency but did not demonstrate malware delivery in the reviewed scope.
Review 6 documented observations View evidence
The reviewed public site presented a coherent URL-shortening and link-management service with substantive pricing, developer API, QR-code, bio-page, contact, account, and abuse-reporting interfaces.
-
Page element
The homepage described URL shortening, analytics, targeting, QR codes, link management, branded domains, and an authenticated developer API as parts of the same service. -
Page element
Pricing, Developer API, QR Codes, Bio Pages, Contact, registration, and login pages consistently used the url.sg service identity and same-origin navigation. -
Page element
The public Report Link page accepted reports for spam, fraudulent, malicious, or phishing short links through the same-origin /report/send endpoint.
Repeated direct requests to the root and reviewed public pages returned the expected same-site content without an unrelated redirect, conditional external destination, or automatic download.
-
HTTP status
200 -
Final URL
https://url.sg/ -
Analyst observation
Browser-like, curl, Googlebot, and Bingbot client profiles all received HTTP 200 at the same https://url.sg/ destination with the same URL-shortener page title and purpose. -
Analyst observation
The reviewed pricing, developer, QR-code, bio-page, contact, report, registration, and login routes each returned HTTP 200 at their expected url.sg destination.
The reviewed public forms and client code used same-origin endpoints for shortening, authentication, contact, and abuse reporting; no credential forwarding to an unrelated host was identified in the reviewed public code.
-
Page element
The public shortening form posted a user-supplied destination to the same-origin /shorten endpoint and requested a Google reCAPTCHA token before submission. -
Page element
Registration and login forms submitted to the same-origin /user/register/validate and /user/login/auth endpoints. -
Page element
Contact and short-link abuse reports submitted to the same-origin /contact/send and /report/send endpoints. -
Analyst observation
The public shortening workflow was not submitted because doing so would create a new public short link; the reviewed client code displayed the returned short URL and QR-code controls without initiating navigation or a download automatically.
The reviewed public scripts implemented ordinary interface, form, QR-code, and link-management behavior. No specific executable, malware payload, suspicious automatic download, or unrelated script-delivery mechanism was identified.
-
File SHA-256
fc981871b8271bea9270a3af4f77bb50d37101e555dd6801fe7ecf9e26a9b12b -
File SHA-256
866fd618922d2dd69c88e27a3e7fb6c5b45663b37c07f7ef9e51186c38bc6bdc -
File SHA-256
63a9648e7ea1a3ac0bca8de86590edb953812f39d73fa222a397942dcf63c112 -
Analyst observation
QR-code PNG, PDF, and SVG download routes were attached to explicit user controls after a link is created; the reviewed code did not trigger them automatically. -
Analyst observation
No specific malicious file, payload, URL, or hash was identified in the reviewed public scope.
The active hostname resolved through its published DNS and presented a currently valid HTTPS certificate and several response-security headers.
-
DNS fact
A records: 104.21.87.35 and 172.67.140.117; authoritative name servers: angela.ns.cloudflare.com and tom.ns.cloudflare.com. -
Certificate fact
Google Trust Services WE1 certificate for url.sg and *.url.sg, valid from 2026-07-31 through 2026-10-29. -
Certificate fact
The reviewed HTTPS response included X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Origin-Agent-Cluster, and cross-domain-policy restrictions.
The reviewed policy presentation was incomplete: the privacy-policy link returned a not-found page and the Terms and Conditions page contained placeholder text.
-
HTTP status
404 -
Page element
The Terms and Conditions page displayed the placeholder sentence: Please edit me when you can. I am very important. -
Analyst observation
These are transparency and documentation weaknesses; they were not evidence of malware delivery in the reviewed site behavior or code.
Scope and limitations
- The review covered the root domain and listed public unauthenticated pages; no account was created, no credentials were submitted, and private dashboard, billing, administrative, and authenticated API flows were not accessed.
- The public shortening form was not submitted because that would create a new public short link. The form and its client-side behavior were reviewed without creating content on the service.
- A URL-shortening platform can redirect individual short codes to user-selected third-party destinations. This domain-level result does not certify every existing or future short code; a specific suspicious short link requires destination-specific review.
- The result applies to the site content, code, infrastructure, and behavior reviewed at the recorded time and does not predict future changes.
Help protect others by sharing this page on social media! The more people who know about url.sg, the fewer chances they have to deceive someone else. Help others evaluate url.sg by sharing this page on social media!