Changelog

Recent changes and improvements to ScanMalware.com

Loading...
Scans now examine the domain lookups and encrypted-connection details a page performs, not just the web requests it makes. That brings a large body of network threat-detection rules into play, covering malware and command-and-control activity that is only visible in that part of a site's traffic - see the Security tab on any report
Loading...
Scan reports now show a JA4X structural fingerprint for a site's TLS certificate: a summary of how the certificate is assembled rather than what it claims, so it stays the same even when the operator changes every name and value inside it. Where that structure is uncommon the report says so and links to the other sites whose certificates are built the same way, which can connect sites that otherwise look unrelated - see the Security tab on any report
Loading...
The certificate and DNS lookup API now says when an answer is incomplete because the service was busy, instead of returning an empty result that reads as a definitive 'nothing found'. Tools built on it can retry rather than recording a blank, so automated lookups during busy periods are no longer quietly under-reported - see /api-docs
Loading...
The Brands catalog now covers 676 brands and shows a logo for 417 of them, up from 62 — logos are fetched from each brand's own site and served by ScanMalware, so browsing still involves no third-party requests. Brands are also recognised under far more of their real-world names, including local and legal ones, so a page impersonating "DHL Express" or "Crédit Suisse" is now filed under the brand you would expect. Nordic and regional banks, telecoms and postal services are among the newly covered brands - Browse /brands
Loading...
The AI Security Verdict now runs on a stronger analysis engine, chosen after an independent blind review of hundreds of real scans where the old and new analyses disagreed. Verdicts more often reflect what a page actually is, and the wording and evidence shown on a report are unchanged.
Loading...
Brand pages now include sites whose page is identical to one already confirmed as impersonating that brand, even when the copy itself names nothing. Where a listing was matched this way it says so, labelled "Identical page", so you can still see exactly what the claim rests on rather than taking it on trust - Browse /brands
Loading...
Not Found pages no longer send you to the homepage on their own — a mistyped or out-of-date link now stays on screen long enough to read and correct.
Loading...
Scan results show the analysed page more accurately. On sites that answer an automated visit differently from a browser, the title and captured content on a report now describe the page that was actually examined.
Loading...
Scans now finish in roughly a third of the time. A typical scan completes in about 30 seconds instead of a minute and a half, so results and verdicts appear sooner after you submit a URL, and large or slow sites are far less likely to run out of time before they finish.
Loading...
The Brands catalog and brand pages have been rebuilt. The catalog opens on the brands we have findings for, can be sorted and filtered, and loads in under half the data it used to; each brand page lists every site we can substantiate rather than a recent sample, shows what each entry was matched on so you can judge it yourself, offers the full list as CSV, and lets any entry be reported as incorrect. Brand logos are served directly by ScanMalware, so browsing involves no third-party requests.
Loading...
Pages that could not be read are no longer recorded as clean. When a site refuses the scanner or returns a server error, the verdict is now stored as "Not Assessed" rather than as a safe result — the report page already said so, but the record behind search and the API did not. 28,371 earlier scans have been corrected to match.
Loading...
Detection of lookalike pages is no longer defeated by trademark symbols or damaged characters in a page title, so a product name written with a symbol between the words is now matched the same as plain text.
Loading...
A page whose title is the full product name of a major brand, published on free hosting that brand does not control, is now treated as a likely impersonation on that basis alone.
Loading...
A web address that misspells the brand shown on the page is now treated as a deliberate lookalike, so near-miss domains built to be misread at a glance are rated accordingly.
Loading...
Sites are no longer flagged for impersonating a brand that is legitimately their own — a sign-in page on the brand's own domain, or the placeholder page a registrar serves on a newly registered domain.
Loading...
Improved the reliability of site icon capture on scan results — the icon shown beside a scanned site now appears consistently whenever that site provides one.
Loading...
Network (ASN) pages now show current BGP routing data, including prefix counts and transit providers, and load in about a tenth of a second.
Loading...
Script analysis has been expanded across scan results and script analysis pages. Scan results list more of the JavaScript a page actually loads, including code served by widely used third-party providers, and report function call counts for modern bundles. Script analysis pages name the bundler identified and how confident that identification is, list the code segments found in inline scripts, and show full segment totals. Searching for code by its fingerprint surfaces more of where the same code appears across scanned sites.
Loading...
The About page now lists the third-party security tools that include ScanMalware as a built-in source. OpenCTI, MISP, subfinder and subfaster can each query the scan archive directly, so if you already use one of them, ScanMalware is available to it without adding a separate plugin.
Loading...
Search is faster and more complete. Result pages load about twice as fast, repeat searches return instantly, and searches differing only in capitalisation are recognised as the same search. Domains whose names begin with digits — 163.com, 365364.xyz — now return their full set of matching scans; this shape is common in short-lived phishing and malware hosting. A scan finished within the last ten minutes may take that long to appear in search results; individual scan report pages are unaffected and always show the latest data.
Loading...
The detection-coverage figure shown on the About page and beneath each scan result counts every threat-intelligence feed in active use during a scan, and reads 21.9 million indicators. This affects the reported figure only — the feeds themselves were already in use, so nothing about how sites are scanned has changed.
Loading...
Script analysis pages show author details only when a script actually names an author, distinguishing that from the licence wording many scripts share. Existing pages have been updated to match.
Loading...
Library identification on scan results is more accurate: a script is named as a library only when there is evidence specific to that library, rather than on wording that many libraries share. Existing results have been updated to match, so a script is attributed only to a library it actually contains.
Loading...
Detection rules that can influence a scan verdict are now reviewed automatically as the rule set updates, so an over-broad new rule is surfaced for review rather than quietly affecting results.
Loading...
Scan result pages are more reliable: pages display correctly across a wider range of scans, and completed scans always record when they finished so they appear correctly in recent activity.
Loading...
The Library Composition breakdown on scan results now names each library consistently, collapses long lists behind a show-more control, and is left out when too little of a page was identified for a share of it to mean anything.
Loading...
Malware scanning now runs on the latest engine release, broadening detection coverage for the files encountered during a scan.
Loading...
Scan results and search draw on a fuller record of which hosts a page loaded its scripts from, and the trusted marker now covers more of the code a page actually loads.
Loading...
The script analysis on scan results now shows a complete Library Composition breakdown, with each detected library sized by its share of the identified code.
Loading...
Improved reliability at peak traffic — scan result pages load without intermittent errors during busy periods.
Loading...
Sharing a scan link now shows a correct preview for every scan, including sites that could not be reached.
Loading...
Faster and more complete certificate and DNS history on scan results — fuller subdomain listings for every type of domain name, related domains that share an IP address, and the time period each lookup covers.
Loading...
Improved brand impersonation accuracy in scan results, with brand names shown consistently across scan results and brand pages, and each listed host linking directly to its scan report.
Loading...
Search links now fall back to searching all fields when they carry a filter the site does not recognise.
Loading...
Improved AI Security Verdict accuracy on parked and expired domains — placeholder notices are now recognised as such.
Loading...
Technology and JavaScript statistics load substantially faster, and report more accurate counts.
Loading...
Advanced search handles unusual or malformed queries more gracefully, with a clear message rather than an error.
Loading...
When a site cannot be reached, scan reports now show "Not Assessed" rather than a risk rating — a site we could not load is not a site we found safe.
Loading...
Every page was being loaded twice, doubling the work behind each visit and slowing reports down. Pages now load once.
Loading...
Improved Security Verdict accuracy in both directions — better detection of pages built to impersonate well-known companies, and fewer legitimate sites incorrectly flagged.
Loading...
Scan results are clearer when a page could not be loaded — the report now describes what was and was not observed instead of stating a cause.
Loading...
API documentation examples now match live responses, and several documented endpoints that returned errors have been fixed - Visit /api-docs
Loading...
Rebuilt the About page around current detection coverage - Visit /about
Loading...
Script pages now list known security vulnerabilities affecting the library version a script matches, with the severity of each and the release it is fixed in.
Loading...
Improved the accuracy of script obfuscation ratings.
Loading...
Similar Scripts results are limited to genuine structural matches, and each result links through to its own script page.
Loading...
Script pages show how widely a script's exact content is seen across scans, with first and last sighting, and load faster.
Loading...
API: domain endpoints now publish a response schema and reject values that are not domains, so a client can tell invalid input apart from a domain we hold no data on.
Loading...
Domain lookups ignore capitalisation and a trailing dot, so a domain searched in any of those forms returns the same results.
Loading...
Screenshot hash search finds visually similar screenshots across every scan on record, not only identical ones, with an adjustable similarity range.
Loading...
Hash search returns results quickly for every supported hash type.
Loading...
Improved Security Verdict accuracy — fake sign-in pages are more reliably flagged as dangerous, while legitimate company sign-in portals are less likely to be flagged.
Loading...
Scan results show more complete network detail, listing more of the addresses and networks a site contacted while loading.
Loading...
Improved AI Security Verdict accuracy. Legitimate sites — including ones that forward visitors to a company's main website — are less likely to receive an elevated risk rating.
Loading...
Certificate and DNS history on a scan result loads substantially faster, especially for domains with many subdomains.
Loading...
Scan result pages load faster. They now request only the sections that have something to show, so a result opens with less waiting and less data transferred.
Loading...
Hash search returns results faster, including for hashes that match nothing.
Loading...
Previews of scan results shared on other sites now load much faster and use a fraction of the data, and the preview image is sized correctly.
Loading...
Improved Security Verdict and AI Security Verdict accuracy. Legitimate sign-in pages are less likely to be rated as risky, and pages impersonating a sign-in service are more reliably identified.
Loading...
Improved AI Security Verdict accuracy for business software. Administrative dashboards and monitoring consoles are less likely to receive an elevated risk rating.
Loading...
Improved Security Verdict and AI Security Verdict accuracy for well-established organisations. Their sign-in and account pages are less likely to be rated as risky.
Loading...
Improved Security Verdict accuracy. Harmful sites are less likely to be given a low risk rating, and legitimate sites are less likely to be rated as risky.
Loading...
Scan results reliably include both the Security Verdict and the AI Security Verdict.
Loading...
Scan results include a page screenshot far more often, which also means the visual similarity and image analysis sections are populated for more results.
Loading...
JavaScript analysis on scan results completes for large, script-heavy sites, with the Obfuscation tab and the script sections including the full breakdown.
Loading...
The progress bar shown while a scan runs follows the scan for its whole duration: it keeps moving until the scan finishes, names the stage currently in progress, and never moves backwards.
Loading...
Scan results pick up analysis that finishes after the scan itself, so the Obfuscation tab and the AI Security Verdict appear on a results page left open on screen without a manual refresh. A scan that failed shows its state directly rather than placeholder content.
Loading...
Improved AI Security Verdict accuracy. Legitimate sites — particularly sign-in pages belonging to established organisations — are less likely to receive an elevated risk rating.
Loading...
Behavioural similarity search results now show how closely each match resembles the script you searched for, along with the per-component breakdown behind that score.
Loading...
Scan results have a new Obfuscation tab summarising obfuscated JavaScript across the whole page — an overall rating, counts of dynamic code execution, and the highest-risk findings with the code that triggered them. Per-script details were already available under Scripts; this adds the page-level view. The tab appears only for scans where the analysis ran.
Loading...
Detected JavaScript libraries on scan results show how confident the detection is, in both the script list and the expanded script details.
Loading...
Scan results populate several additional panels. The embedded-frames panel counts the frames actually flagged and lists why each was flagged, and page statistics, browser console counts and the declared-versus-detected language notice are all shown.
Loading...
Threat intelligence matches on scan results now say where each indicator was found. A match listed only the indicator, its threat type and its source for around a third of matches; those now also name the location it was seen in and the related domain, host or file hash.
Loading...
The Bot Protection section on scan results now shows the evidence behind each detection. Detected services were listed with a confidence score, but the evidence rows underneath were blank; each row now names where on the page the signal came from, how much it contributed to the score, and what was matched.
Loading...
A site already blocked by its own hosting or security provider is rated as dangerous by both the Security Verdict and the AI Security Verdict, across the range of reasons a provider may give for the block.
Loading...
The AI Security Verdict summary now agrees with the rating above it. A page raised to high risk by a confirmed threat could still be described as low risk in the sentence underneath; that summary now states the finding behind the rating, unless it already described the threat more specifically.
Loading...
Searching scans by domain is dramatically faster: results typically return in well under a second, including searches for domains we have never scanned, and hold up under heavy load.
Loading...
Improved AI Security Verdict accuracy for small-business websites whose contact forms are delivered through a third-party form service. When such a form demonstrably delivers to the site's own organisation, that is recognised and reflected in the rating. Sites that ask for passwords or payment details, or that show any other threat signal, are unaffected.
Loading...
Advanced Search (SMQL) now supports Certificate Transparency filters: ct_domain, ct_san, ct_hash, ct_log and ct_issued let you find scans of domains through their certificate history — for example "ct_domain:*paypa1* AND ct_issued:last30d" surfaces scans of look-alike domains that received a certificate in the last 30 days. Also improved: the certificate-transparency history shown on scan results includes wildcard certificates, and the "domains on this IP" certificate lookup returns reliably - Visit /search-advanced
Loading...
The API now has published rate limits, which keep heavy automated traffic from affecting scanner performance for everyone else. Normal browsing and everyday API use are unaffected. If you do hit the limit you will get a clear page explaining it, and a free API key — created on your account page and sent with your requests — raises your limit substantially. The limits are listed in the API documentation.
Loading...
Improved AI Security Verdict accuracy for malicious sites that are already hidden behind a security provider's warning page — these are now consistently rated as dangerous.
Loading...
New detection for adversary-in-the-middle (AiTM) phishing — "Evilginx"-style attacks that present Microsoft's real sign-in page from a look-alike, non-Microsoft web address to steal both your password and your multi-factor (MFA) session, even when the page looks and behaves exactly like the genuine one. Scanned pages that serve the Microsoft sign-in flow from a non-Microsoft address are now flagged as dangerous. Genuine Microsoft sign-in — including government (sovereign cloud) and Azure AD B2C / Entra business sign-in — is unaffected.
Loading...
Improved detection of cryptocurrency scam apps that appear blank to automated scanners but load a fake investment or "earn money" app in a real browser. These are now flagged as dangerous and tracked as they reappear on new web addresses. Reputable services are unaffected.
Loading...
Improved the JavaScript analysis pages — the Security tab reliably lists the malware and obfuscation patterns detected in each script, and the Similar Scripts tab shows full details and working links.
Loading...
Further reduced Security Verdict false positives on legitimate sites — content-delivery and shared-hosting infrastructure addresses that merely contain a well-known brand name, and sign-in pages on new or lesser-known domains, are flagged as brand impersonation only with concrete evidence of credential theft. Genuine phishing and brand-impersonation pages continue to be flagged.
Loading...
Improved detection of a stealthy phishing technique that shows security scanners a blank page and only assembles its fake Microsoft sign-in and "device code" authorisation prompt inside the visitor's browser from encrypted content. These pages are now recognised by their structure and flagged as a known malicious kit on the scan result.
Loading...
New detection for "ClickFix" scams — fake CAPTCHA or error pages that try to trick you into copying and pasting a command into your computer to run malware. When a scanned page attempts this clipboard trick, it is now captured and flagged as dangerous.
Loading...
Improved detection of cryptocurrency scams — pages that try to steal wallet recovery ("seed") phrases or trick you into connecting a wallet so it can be drained are now more reliably flagged, and scans are checked against an additional continuously-updated list of known crypto-phishing and wallet-drainer sites.
Loading...
Community reports now help flag threats — when visitors mark a scanned page as malicious, those reports contribute to the Security Verdict and trigger a fresh analysis, so threats reported by the community surface faster. A flood of false reports will not flag a page on its own.
Loading...
Improved detection of phishing pages that hide their trap — including multi-step "sign in with [brand]" lures that only reveal the credential form after a fake verification or CAPTCHA step, and pages that serve scanners a harmless decoy while showing their real content to ordinary visitors.
Loading...
Reduced Security Verdict false positives on many kinds of legitimate sites — self-hosted software dashboards and their sign-in pages on your own domain, corporate single sign-on and identity providers, cloud-platform default and error pages, official sites that simply link to a well-known brand, and country-specific domains are flagged as phishing only with concrete evidence of credential theft. Genuine phishing and brand impersonation continue to be flagged.
Loading...
Faster "Known malicious kit" warnings on scan results — when a scanned site matches one of the phishing or malware kits tracked in our hunt catalog, the warning banner appears on the result page automatically within moments of the analysis finishing, without needing a reload. Hunt pages pick up newly matching scans just as quickly - Visit /hunts
Loading...
New Page Load Speed rating on scan results — the HTTP tab now shows how a site's page-load time compares with every other site we've scanned, as a simple Very Fast / Fast / Medium / Slow rating along with the percentage of scanned sites it loaded faster than.
Loading...
Improved Security Verdict accuracy on Microsoft phishing-simulation test pages — links from Microsoft's Attack Simulation Training (the harmless phishing-awareness tests organisations send their own staff) are identified as Microsoft-operated test domains and treated as benign, while genuine Microsoft-impersonation phishing continues to be flagged.
Loading...
Security Verdict reliability — the brand-impersonation and network-level threat checks are now applied consistently on every scan, so a dangerous page is flagged the first time it is scanned rather than only on a later re-analysis.
Loading...
Improved detection of brand-impersonation phishing — the Security Verdict now more reliably flags pages that impersonate a well-known brand's sign-in flow (including "device code" login scams that try to trick you into authorising an attacker's access) and pages that display a trusted brand's logo on a look-alike domain. Threat alerts raised at the network level during a scan are now reflected in the Security Verdict as well.
Loading...
Improved AI Security Verdict accuracy on legitimate sign-in pages — a high-risk verdict for government, municipal, university and other official login portals requires concrete evidence of credential theft rather than the presence of a login form on a low-traffic or unfamiliar domain, while genuine phishing and brand-impersonation pages continue to be flagged.
Loading...
Improved detection of fake login pages hosted on cloud storage and app-hosting platforms — credential-harvesting pages placed on free file-storage and hosting services are now more reliably flagged as dangerous in the Security Verdict, including ones that don't impersonate a well-known brand.
Loading...
Reduced Security Verdict false positives from overly-broad threat data — a website is flagged as dangerous on corroborated evidence rather than on sharing a server address with many unrelated sites or on an entry from a discontinued threat list. Genuine, corroborated threats are unaffected.
Loading...
Improved AI Security Verdict accuracy on new and lesser-known websites — an elevated verdict requires concrete evidence of malicious behaviour rather than a recently-registered domain or a lack of established reputation, reducing false positives on legitimate new sites.
Loading...
New account dashboard — logged-in users now have an account page showing their submitted scans, recent logins, and API keys. API keys can be created with scopes and expiration dates, revoked at any time (individually or all at once), and used to submit scans and read results programmatically via the X-API-Key header — see the API documentation. Private scans are now available: results are visible only to you when logged in or using your API key.
Loading...
The perceptual image hashes shown on scan results reflect the captured screenshot, so visual similarity searches between scans work as expected.
Loading...
Improved phishing detection for sites that hide from automated scanners — pages that show security tools a harmless decoy while serving their real content to ordinary visitors are now more reliably flagged as dangerous.
Loading...
Improved scan submission reliability — resolved an intermittent issue that caused some recent scans to time out without producing a result. Affected scans can be re-submitted.
Loading...
Newly-reported threats now appear in scan results faster.
Loading...
Improved AI Security Verdict accuracy on niche and regional sites — fewer false positives where a login form alone was triggering a high-risk verdict.
Loading...
Improved AI Security Verdict accuracy on sites hosted on common developer platforms and on sites that use in-browser file handling — these are assessed on their own behaviour rather than treated as inherently suspicious.
Loading...
Improved AI Security Verdict accuracy — better-corroborated threat reports are weighted more heavily, reducing false positives on widely-used third-party services.
Loading...
Made the search loading indicator more noticeable — the progress bar shown while results load is now more prominent and stays on screen long enough to see, even on fast searches.
Loading...
Search results now show a clear loading state when you change the search type — a progress bar at the top of the page and a placeholder table appear while the new results load, instead of the page appearing to pause with no feedback.
Loading...
Expanded threat-intelligence coverage — scanned URLs are now matched against an additional continuously-updated database of known malware-hosting and phishing URLs, refreshed throughout the day so newly reported threats are caught quickly.
Loading...
Improved the accuracy of network threat alerts on scan results — the alerts shown reflect genuine findings, with a class of technical false positives filtered out.
Loading...
Corrected the JavaScript analysis statistics on scan results — the script count, number of static analyses and code-entropy figures were overstated on some scans and now report accurately.
Loading...
Improved malware-pattern coverage on JavaScript code-analysis pages — script-detail pages now show their full set of pattern matches.
Loading...
Improved JavaScript fingerprinting — per-function code segments that drive cross-scan code-similarity, library detection, and pattern matching are now recorded for every new scan.
Loading...
Improved Certificate Transparency and reverse DNS lookup reliability — the certificate history, similar-domain, and rDNS endpoints under /api/v1/ct/ are serving normally.
Loading...
Search and scan-result pages are now noticeably faster after migrating the search backend onto faster storage — full-cluster searches drop from seconds to under 100 ms, scan-result page loads feel snappier on cold-cache requests
Loading...
Fixed multi-segment crop-resistant screenshot hash search — the endpoint was rejecting legitimate hash values produced by the imagehash library and now accepts the comma-joined format correctly
Loading...
Reduced false-positive "Compromised WordPress" flags on legitimate WordPress sites — the detector is more selective about what counts as a compromise indicator.
Loading...
Improved AI Security Verdict coverage on JavaScript-driven pages — pages whose content is rendered by scripts now reliably receive a full verdict.
Loading...
Improved IP geolocation accuracy on bot-protected scans — ASN, country and city now stay in sync with the captured IP addresses
Loading...
Long redirect URLs in scan result headers are collapsed to a single line with a click-to-expand button
Loading...
Improved JavaScript library detection accuracy — bundler chunk filenames are distinguished from libraries, avoiding spurious version numbers
Loading...
Fixed intermittent 500 errors on several API endpoints (OCR, favicon search, scan summary, high-risk search, analyzer stats) that occurred after the first cached request
Loading...
Improved AI Security Verdict accuracy — reduced false positives on corporate sites, news/media, and small business websites.
Loading...
API: Renamed several response fields for consistency across scan results, nameserver lookups, and PCAP endpoints
Loading...
Further improved AI brand impersonation detection with contextual awareness for venue names, geographic locations, and corroborating signal requirements
Loading...
Improved AI security verdict accuracy for brand impersonation detection, reducing false positives on sites that use third-party services
Loading...
Fixed missing ASN organization names for some IPs in the Domain & IP Information table
Loading...
New Advanced Search (SMQL) with 120+ filters, boolean logic, and sorting - Browse /search-advanced
Loading...
Added multi-signal phishing detection for Microsoft 365 credential phishing (AiTM proxies, static clones, obfuscated kits)
Loading...
Added stable behavioral signatures and behavior vectors for JavaScript similarity clustering - Browse /blog/stable-behavioral-signatures
Loading...
Improved database query performance and search responsiveness
Loading...
Fixed "Find Similar" links for behavioral code fingerprints on scan results
Loading...
Improved scan submission responsiveness and URL validation performance
Loading...
Improved threat intelligence coverage with additional feed sources and freshness monitoring
Loading...
Improved YARA malware detection accuracy and updated threat intelligence feeds
Loading...
Improved JavaScript analysis for external scripts with enhanced hybrid analysis pipeline
Loading...
Added crypto wallet drainer detection with blockchain RPC monitoring and brand impersonation checks
Loading...
Improved AI security analysis accuracy and network traffic analysis coverage
Loading...
Show full certificate hashes in Certificate Transparency Intelligence section
Loading...
Fixed Certificate Transparency API endpoints to correctly return DNS records and IP addresses for domains
Loading...
Infrastructure: Resolved search cluster issue and performed disk space optimization
Loading...
Published blog post: Detecting Coruna, the nation-state iOS exploit kit targeting Safari, with 16 new YARA detection rules - Visit /blog/coruna-ios-exploit-kit-detection
Loading...
Cleaner RDAP display — IP descriptions exclude cloud-provider internal metadata.
Loading...
Improved how domain registration age is interpreted across cross-domain redirects.
Loading...
Security hardening across scan result rendering.
Loading...
Skip AI analysis for error pages to reduce false alerts
Loading...
Reduced AI verdict false positives for news and article sites writing about brands
Loading...
Added title-domain mismatch detection to AI security analysis
Loading...
Fixed AI verdict false positive for gambling sites misclassified as phishing
Loading...
Added Content Security Policy header to frontend pages
Loading...
Fixed search query timeouts for faster hash and fingerprint lookups
Loading...
Improved accuracy: hosting platform false positive prevention, domain age scoring, and scam taxonomy
Loading...
Integrated network intrusion-detection alerts into AI Security Verdict for deeper threat detection.
Loading...
Improved AI security analysis with enhanced phishing detection and reduced false positives for legitimate websites
Loading...
Scanning performance improved 34x with optimized parallelization
Loading...
Improved credential exfiltration detection accuracy with reduced false positives
Loading...
Published blog post analyzing ShinyHunters phishing kit campaign with 21,090 domains scanned - Visit /blog/shinyhunters-phishing-kit-analysis
Loading...
Added malware warning indicators to script analysis pages
Loading...
Refined malware detection patterns achieving under 5% false positive rate
Loading...
Fixed AI analyzer to correctly identify critical malware patterns
Loading...
Added Meta/Facebook brand detection to security analysis
Loading...
Fixed AI classification thresholds for more accurate risk scoring
Loading...
Added trusted domain badge to individual script analysis pages
Loading...
Improved scan processing reliability with optimized timeout settings for better resource management
Loading...
Enhanced logging infrastructure for improved performance monitoring across distributed systems
Loading...
Improved network traffic capture quality by preventing empty packet captures from being stored
Loading...
Infrastructure: Optimized internal data management for better system performance
Loading...
Enhanced system health monitoring with TLS certificate analysis status tracking
Loading...
Enhanced scan pipeline reliability analysis for better error detection and automatic recovery
Loading...
Improved code analysis accuracy by reducing false positive detections in fingerprint matching
Loading...
Expand API documentation with 10 new endpoints: YARA malware detection (4 endpoints), registrar search, tracking keys analysis (3 endpoints), Chrome network debug logs, and nameserver domain lookups - Visit /api-docs
Loading...
Add confidence level indicators when identifying code libraries in scan results
Loading...
Improved accuracy in library identification by reducing false matches for generic filenames
Loading...
Launch Model Context Protocol (MCP) server for AI integration - enables Claude Desktop and other AI tools to directly access ScanMalware security scanning capabilities - Visit https://mcp.scanmalware.com
Loading...
Enhanced library detection accuracy for inline and embedded code blocks
Loading...
Substantially reduced threat-intelligence false positives on widely-used third-party content delivery services.
Loading...
Improved library version detection accuracy with better validation logic
Loading...
Add detection for programming interfaces and system calls used in JavaScript code
Loading...
Improved reliability of network traffic capture and analysis during scans
Loading...
Expand library detection capabilities by 355% with 47 new identification signatures
Loading...
Expanded threat-intelligence coverage to millions of indicators across network, file-hash, and structured-threat data.
Loading...
Fix scan result page error when analyzing forms with unusual field configurations
Loading...
Improved tracking of URL redirects to preserve fragment identifiers in destination URLs
Loading...
Improve code analysis reliability to 100% success rate, eliminating processing errors
Loading...
Launch automated copyright and licensing detection with 119% improvement in accuracy
Loading...
Add detection for JavaScript-based navigation and blob URLs for better tracking of client-side URL changes
Loading...
Add automatic URL preprocessing to unwrap redirect links from social media platforms and URL shorteners
Loading...
Enhanced IP geolocation display with full country names in Network tab
Loading...
Performance: Database query optimizations for faster domain search and tracking key lookups
Loading...
Add WAF and CDN identification to TLS fingerprint analysis across major providers.
Loading...
Add page-level JavaScript behavioral risk analysis on Scripts tab
Loading...
Add MD5 and SHA-1 hash search support to JavaScript search with direct links to script detail pages
Loading...
Improved domain registration (RDAP/WHOIS) caching with smart expiration-based refresh
Loading...
Improved JavaScript malware analysis with better code segment extraction and pattern matching
Loading...
Fix technology detection service - improved reliability for website fingerprinting
Loading...
Infrastructure: Improved network reliability for DNS lookups and domain intelligence
Loading...
Reduced false positives for legitimate country-specific variants of major brand websites.
Loading...
Improved form analysis to reduce false positive password field detections
Loading...
Add business legitimacy assessment for positive trust signals in security analysis
Loading...
Enhanced form classification to recognize legitimate booking forms and third-party services
Loading...
Add industry-aware brand detection to reduce false positives for legitimate businesses
Loading...
Improved scan reliability for sites protected by bot-detection systems.
Loading...
Add scan visibility selector UI with public, unlisted, and private options (coming soon)
Loading...
Fix malware scanning service and improve intrusion detection reliability
Loading...
Performance: Increased search database memory and extended Certificate Transparency query timeout for large searches
Loading...
Add dual search cluster monitoring to health checks for improved reliability
Loading...
Enhanced Certificate Transparency search performance and reliability
Loading...
Improved infrastructure monitoring with enhanced health checks for all services
Loading...
Refactored internal architecture for better scalability and maintainability
Loading...
Add dark mode support for YARA malware pattern detection results
Loading...
Launch YARA malware pattern detection with visual indicators on scan results
Loading...
Expand YARA malware detection capabilities by 23% (1,250 → 1,540 detection patterns)
Loading...
Add YARA malware pattern matching to JavaScript analysis for enhanced threat detection
Loading...
Add automated daily updates for YARA malware detection rules
Loading...
Launch unified search page with tabs for text, visual, and JavaScript code search
Loading...
Launch JavaScript Malware Analysis v2.0 with YARA patterns, fuzzy hashing (TLSH), webpack de-bundling, and ML-based code similarity detection
Loading...
Add library fingerprinting system to identify known JavaScript libraries and isolate suspicious code
Loading...
Infrastructure improvements: Updated to latest platform versions for better performance and security
Loading...
Add domain registration and nameserver information to scan results with DNS fallback support
Loading...
Launch JavaScript obfuscation detection to identify malicious code hiding techniques
Loading...
Improve scan reliability with automated retry logic, reducing error rate to under 6%
Loading...
Fix critical scanning issues and enhance error handling for improved stability
Loading...
Launch hybrid JavaScript fingerprinting with 19x coverage increase for better malware detection
Loading...
Fix GeoIP data enrichment for network analysis and IP geolocation
Loading...
Add trusted CDN whitelist badges to Scripts tab for better security transparency
Loading...
Fix screenshot loading issue on Visual Search page
Loading...
Add TLS Certificate Analysis API endpoint with CAA validation and Certificate Transparency data - Visit https://scanmalware.com/api-docs#tls
Loading...
Launch public changelog page with timezone-aware timestamps and clickable links - Visit /changelog
Loading...
Add RSS feed for changelog updates - Subscribe at /changelog.xml
Loading...
Launch security blog with articles on TLS certificates, CAA validation, and Certificate Transparency - Visit /blog
Loading...
Add RSS feed for blog posts - Subscribe at /rss.xml
Loading...
Add tag filtering for blog posts - Browse posts by topic
Loading...
Performance improvement: Database optimizations
Loading...
Add daily automated browser profile warmup for better bot detection evasion
Loading...
Expand browser profile warmup from 5 to 10 popular websites
Loading...
Security: Browser workers now run as non-root user for improved security
Loading...
Add CAA validation and certificate validity period checks to TLS analyzer
Loading...
Add hostname validation and certificate chain validation to TLS analyzer
Loading...
Add comprehensive security certificate test validation
Loading...
Fix TLS analyzer ECDSA key size false positive
Loading...
Implement TLS Certificate Analyzer with Certificate Transparency enrichment
Loading...
Optimize JavaScript fingerprinting performance
Loading...
Add CJK script detection and language code normalization
Loading...
Implement improved multi-signal language detection
Loading...
Implement multi-signal phishing clone detection
Loading...
Remove white background from favicons, make transparent
Loading...
Fix URL manipulation false positive for hash fragments in single-page apps
Loading...
Fix browser error URL exposure and improve AI analysis continuation logic
Loading...
Improved JavaScript fingerprinting processing speed with parallel workers
Loading...
Fix HTML upload race condition with inline data storage
Loading...
Enhanced reliability for JavaScript file downloads and analysis
Loading...
Fix null checks in expanded fingerprint metrics section
Loading...
Fix null handling for function count in JavaScript fingerprints
Loading...
Add obfuscated JavaScript detection for improved malware identification
Loading...
Add expanded JavaScript fingerprint metrics view
Loading...
Implement JavaScript fingerprinting feature for malware detection
Loading...
Faster JavaScript fingerprinting results for newly submitted scans

Showing recent updates and improvements