About ScanMalware Security Scanner

A URL security scanner that visits a site the way a browser does, records what it actually loads and runs, and turns that into an evidence-backed verdict.

Detection Scale

Every scan is checked against the full detection set below. These figures are refreshed daily from our own systems — last updated 2026-09-08.

21,903,297
Threat intelligence indicators
85,760
Malware detection rules
3,642,754
Virus signatures
25,631,811
Detection signatures in total

What We Do

Security Analysis

Detect malware, phishing pages, scams and suspicious scripts, and explain the reasoning behind each verdict with the evidence it rests on.

Technology Detection

Identify the frameworks, libraries and services a site is built on, and correlate detected versions against known vulnerabilities.

Visual Analysis

Capture screenshots and compare them against everything scanned before, to surface fake sign-in pages, cloned layouts and deceptive content.

Network Monitoring

Record every request a page makes while loading, and flag connections to known malicious domains, addresses and infrastructure.

Analysis Modules

AI-Powered Security Analysis

AI models review the collected scan evidence and produce a security assessment alongside the rule-based verdict, classifying phishing, scams and malware delivery with the findings that support the rating.

Multi-Layer Threat Intelligence

Domains, addresses, URLs and file hashes seen during a scan are matched against a large aggregated indicator set, combined with Google Safe Browsing and Cisco Umbrella domain rankings. Each match names the source and where it was seen.

Malware & Phishing Kit Rule Matching

Page content, scripts and downloaded files are matched against YARA rules and antivirus signatures to identify malware families, known phishing kits and the infrastructure behind them.

Credential & Form Analysis

Deep inspection of web forms to detect credential harvesting, payment card skimming and other suspicious data collection, including where a form actually sends what a visitor types.

JavaScript Obfuscation & Behaviour Analysis

Rates how heavily a page's JavaScript is obfuscated, counts dynamic code execution, and surfaces the highest-risk findings together with the code that triggered them — both per script and across the whole page.

Visual Similarity & Text Extraction

Perceptual hashing matches a screenshot against visually similar pages across every scan on record, and multi-language OCR extracts on-page text from images so lures and phishing wording are analysed even when rendered as graphics.

Content & Code Similarity

Fuzzy hashing with TLSH, ssdeep and sdhash detects malware variants and content clones despite minor edits, while machine-learning code embeddings find scripts that behave alike even when the source has been rewritten.

Brand Impersonation Detection

Identifies pages presenting themselves as a brand they do not belong to, using page content, favicons, layout and domain signals rather than the site's own claims about its identity.

Tracker & Privacy Analysis

Identifies analytics, advertising and tracking services embedded in a page, including fingerprinting scripts and other privacy-invasive technologies.

Technology Stack Detection

Fingerprinting identifies the technologies, frameworks and CMS platforms behind a site, with CPE enumeration for correlation against CVE databases.

Bot Protection & Anti-Analysis Detection

Detects when a site is behind a bot-protection or challenge service, and when a page behaves differently for visitors it believes are being analysed.

Certificate Transparency Intelligence

Certificate Transparency log monitoring surfaces lookalike domains, typosquatting attempts and wildcard certificates, helping identify phishing infrastructure and domain impersonation as it is set up.

RDAP/WHOIS Domain Intelligence

RDAP with WHOIS fallback for domain registration data, including domain age for risk assessment and dedicated handling of newly registered domains, which are heavily used in phishing campaigns. Includes network information from the Regional Internet Registries.

Network Intrusion Detection

Captured network traffic is analysed for malicious activity patterns, exploit attempts and suspicious communications, using intrusion-detection rules applied to the recorded PCAP data.

Research Tools

Threat Hunts

Write a query against everything we have scanned and keep it running, so new matches surface as they appear rather than only when you go looking.

Cross-Scan Search

Pivot across the whole corpus by domain, URL, screenshot, file or script hash, script behaviour, technology, network or tracking identifier.

Brand Pages

Browse impersonation activity by the brand being targeted, and follow it through to the individual scans behind it.

API, MCP Server & CLI

Submit scans and read results programmatically over the public API, from the command line, or directly from an AI assistant via our MCP server.

Algorithms & Techniques

Machine Learning & AI

  • • AI security assessment models
  • • Code embeddings for script similarity
  • • Multi-language OCR engine
  • • Automated language detection
  • • Content classification

Security Algorithms

  • • TLSH fuzzy hashing
  • • ssdeep similarity detection
  • • sdhash content matching
  • • Perceptual image hashing
  • • JARM TLS fingerprinting
  • • SHA256 & MD5 hashing

Analysis Techniques

  • • DOM tree analysis
  • • JavaScript behaviour monitoring
  • • Network traffic inspection
  • • Form field pattern matching
  • • Redirect chain reconstruction
  • • Certificate Transparency monitoring
  • • RPKI BGP origin validation
  • • Domain age risk scoring

Use Cases

Security Research

Analyze suspicious URLs, investigate phishing campaigns, and research malware distribution networks.

Threat Intelligence

Gather intelligence on emerging threats, monitor malicious infrastructure, and track threat actor activities.

Website Analysis

Perform technical analysis of websites, identify technologies used, and assess security posture.

Educational Purposes

Learn about web security, understand how malicious websites work, and practice security analysis skills.

Important Notice

This tool is intended for educational and defensive security purposes only. Use it responsibly and only scan websites you own or have explicit permission to analyze. Do not use this service for malicious purposes or to scan websites without proper authorization.