Envoy
Below is a recent sample of public scans on ScanMalware.com where Envoy was detected as part of the site's technology stack. Use this as a jumping-off point for investigating how Envoy is deployed across the web — including on potentially malicious or compromised hosts.
Recent scans where Envoy was detected
How ScanMalware detects Envoy
Each public scan on ScanMalware.com is analysed for the technologies that make up the site's stack — web servers, frameworks, CDNs, analytics, and security middleware. When Envoy is observed (via response headers, fingerprintable URLs, JavaScript globals, or known asset patterns), the scan is tagged accordingly. This page lists scans where Envoy was identified as part of the underlying stack.
Want to dig deeper? You can pivot from any scan into related signals — JARM TLS fingerprints, ASN ownership, BGP routing, or co-resident technologies — to map how Envoy is being used across the public web.