About ScanMalware Security Scanner
A URL security scanner that visits a site the way a browser does, records what it actually loads and runs, and turns that into an evidence-backed verdict.
Detection Scale
Every scan is checked against the full detection set below. These figures are refreshed daily from our own systems — last updated 2026-09-08.
What We Do
Security Analysis
Detect malware, phishing pages, scams and suspicious scripts, and explain the reasoning behind each verdict with the evidence it rests on.
Technology Detection
Identify the frameworks, libraries and services a site is built on, and correlate detected versions against known vulnerabilities.
Visual Analysis
Capture screenshots and compare them against everything scanned before, to surface fake sign-in pages, cloned layouts and deceptive content.
Network Monitoring
Record every request a page makes while loading, and flag connections to known malicious domains, addresses and infrastructure.
Analysis Modules
AI-Powered Security Analysis
AI models review the collected scan evidence and produce a security assessment alongside the rule-based verdict, classifying phishing, scams and malware delivery with the findings that support the rating.
Multi-Layer Threat Intelligence
Domains, addresses, URLs and file hashes seen during a scan are matched against a large aggregated indicator set, combined with Google Safe Browsing and Cisco Umbrella domain rankings. Each match names the source and where it was seen.
Malware & Phishing Kit Rule Matching
Page content, scripts and downloaded files are matched against YARA rules and antivirus signatures to identify malware families, known phishing kits and the infrastructure behind them.
Credential & Form Analysis
Deep inspection of web forms to detect credential harvesting, payment card skimming and other suspicious data collection, including where a form actually sends what a visitor types.
JavaScript Obfuscation & Behaviour Analysis
Rates how heavily a page's JavaScript is obfuscated, counts dynamic code execution, and surfaces the highest-risk findings together with the code that triggered them — both per script and across the whole page.
Visual Similarity & Text Extraction
Perceptual hashing matches a screenshot against visually similar pages across every scan on record, and multi-language OCR extracts on-page text from images so lures and phishing wording are analysed even when rendered as graphics.
Content & Code Similarity
Fuzzy hashing with TLSH, ssdeep and sdhash detects malware variants and content clones despite minor edits, while machine-learning code embeddings find scripts that behave alike even when the source has been rewritten.
Brand Impersonation Detection
Identifies pages presenting themselves as a brand they do not belong to, using page content, favicons, layout and domain signals rather than the site's own claims about its identity.
Tracker & Privacy Analysis
Identifies analytics, advertising and tracking services embedded in a page, including fingerprinting scripts and other privacy-invasive technologies.
Technology Stack Detection
Fingerprinting identifies the technologies, frameworks and CMS platforms behind a site, with CPE enumeration for correlation against CVE databases.
Bot Protection & Anti-Analysis Detection
Detects when a site is behind a bot-protection or challenge service, and when a page behaves differently for visitors it believes are being analysed.
Certificate Transparency Intelligence
Certificate Transparency log monitoring surfaces lookalike domains, typosquatting attempts and wildcard certificates, helping identify phishing infrastructure and domain impersonation as it is set up.
RDAP/WHOIS Domain Intelligence
RDAP with WHOIS fallback for domain registration data, including domain age for risk assessment and dedicated handling of newly registered domains, which are heavily used in phishing campaigns. Includes network information from the Regional Internet Registries.
Network Intrusion Detection
Captured network traffic is analysed for malicious activity patterns, exploit attempts and suspicious communications, using intrusion-detection rules applied to the recorded PCAP data.
Research Tools
Threat Hunts
Write a query against everything we have scanned and keep it running, so new matches surface as they appear rather than only when you go looking.
Cross-Scan Search
Pivot across the whole corpus by domain, URL, screenshot, file or script hash, script behaviour, technology, network or tracking identifier.
Brand Pages
Browse impersonation activity by the brand being targeted, and follow it through to the individual scans behind it.
API, MCP Server & CLI
Submit scans and read results programmatically over the public API, from the command line, or directly from an AI assistant via our MCP server.
Algorithms & Techniques
Machine Learning & AI
- • AI security assessment models
- • Code embeddings for script similarity
- • Multi-language OCR engine
- • Automated language detection
- • Content classification
Security Algorithms
- • TLSH fuzzy hashing
- • ssdeep similarity detection
- • sdhash content matching
- • Perceptual image hashing
- • JARM TLS fingerprinting
- • SHA256 & MD5 hashing
Analysis Techniques
- • DOM tree analysis
- • JavaScript behaviour monitoring
- • Network traffic inspection
- • Form field pattern matching
- • Redirect chain reconstruction
- • Certificate Transparency monitoring
- • RPKI BGP origin validation
- • Domain age risk scoring
Use Cases
Security Research
Analyze suspicious URLs, investigate phishing campaigns, and research malware distribution networks.
Threat Intelligence
Gather intelligence on emerging threats, monitor malicious infrastructure, and track threat actor activities.
Website Analysis
Perform technical analysis of websites, identify technologies used, and assess security posture.
Educational Purposes
Learn about web security, understand how malicious websites work, and practice security analysis skills.
Important Notice
This tool is intended for educational and defensive security purposes only. Use it responsibly and only scan websites you own or have explicit permission to analyze. Do not use this service for malicious purposes or to scan websites without proper authorization.