Changelog

Recent changes and improvements to ScanMalware.com

Loading...
Fixed intermittent 500 errors on several API endpoints (OCR, favicon search, scan summary, high-risk search, analyzer stats) that occurred after the first cached request
Loading...
Improved AI security verdict accuracy with established-domain leniency, SSO flow recognition, and self-branding detection — reducing false positives on corporate sites, news/media, and small business websites
Loading...
API: Renamed several response fields for consistency across scan results, nameserver lookups, and PCAP endpoints
Loading...
Further improved AI brand impersonation detection with contextual awareness for venue names, geographic locations, and corroborating signal requirements
Loading...
Improved AI security verdict accuracy for brand impersonation detection, reducing false positives on sites that use third-party services
Loading...
Fixed missing ASN organization names for some IPs in the Domain & IP Information table
Loading...
New Advanced Search (SMQL) with 120+ filters, boolean logic, and sorting - Browse /search-advanced
Loading...
Added multi-signal phishing detection for Microsoft 365 credential phishing (AiTM proxies, static clones, obfuscated kits)
Loading...
Added stable behavioral signatures and behavior vectors for JavaScript similarity clustering - Browse /blog/stable-behavioral-signatures
Loading...
Improved database query performance and search responsiveness
Loading...
Fixed "Find Similar" links for behavioral code fingerprints on scan results
Loading...
Improved scan submission responsiveness and URL validation performance
Loading...
Improved threat intelligence coverage with additional feed sources and freshness monitoring
Loading...
Improved YARA malware detection accuracy and updated threat intelligence feeds
Loading...
Improved JavaScript analysis for external scripts with enhanced hybrid analysis pipeline
Loading...
Added crypto wallet drainer detection with blockchain RPC monitoring and brand impersonation checks
Loading...
Improved AI security analysis accuracy and network traffic analysis coverage
Loading...
Show full certificate hashes in Certificate Transparency Intelligence section
Loading...
Fixed Certificate Transparency API endpoints to correctly return DNS records and IP addresses for domains
Loading...
Infrastructure: Resolved search cluster issue and performed disk space optimization
Loading...
Published blog post: Detecting Coruna, the nation-state iOS exploit kit targeting Safari, with 16 new YARA detection rules - Visit /blog/coruna-ios-exploit-kit-detection
Loading...
Improved RDAP display by filtering out OCITOKEN metadata from IP descriptions
Loading...
Fixed RDAP domain age trust bypass on cross-domain redirects
Loading...
Fixed JSON-LD XSS vulnerability and invalid character handling
Loading...
Skip AI analysis for error pages to reduce false alerts
Loading...
Reduced AI verdict false positives for news and article sites writing about brands
Loading...
Added title-domain mismatch detection to AI security analysis
Loading...
Fixed AI verdict false positive for gambling sites misclassified as phishing
Loading...
Added Content Security Policy header to frontend pages
Loading...
Fixed search query timeouts for faster hash and fingerprint lookups
Loading...
Improved accuracy: hosting platform false positive prevention, domain age scoring, and scam taxonomy
Loading...
Integrated IDS/Suricata network alerts into AI security analysis for deeper threat detection
Loading...
Improved AI security analysis with enhanced phishing detection and reduced false positives for legitimate websites
Loading...
Scanning performance improved 34x with optimized parallelization
Loading...
Improved credential exfiltration detection accuracy with reduced false positives
Loading...
Published blog post analyzing ShinyHunters phishing kit campaign with 21,090 domains scanned - Visit /blog/shinyhunters-phishing-kit-analysis
Loading...
Added malware warning indicators to script analysis pages
Loading...
Refined malware detection patterns achieving under 5% false positive rate
Loading...
Fixed AI analyzer to correctly identify critical malware patterns
Loading...
Added Meta/Facebook brand detection to security analysis
Loading...
Fixed AI classification thresholds for more accurate risk scoring
Loading...
Added trusted domain badge to individual script analysis pages
Loading...
Improved scan processing reliability with optimized timeout settings for better resource management
Loading...
Enhanced logging infrastructure for improved performance monitoring across distributed systems
Loading...
Improved network traffic capture quality by preventing empty packet captures from being stored
Loading...
Infrastructure: Optimized internal data management for better system performance
Loading...
Enhanced system health monitoring with TLS certificate analysis status tracking
Loading...
Enhanced scan pipeline reliability analysis for better error detection and automatic recovery
Loading...
Improved code analysis accuracy by reducing false positive detections in fingerprint matching
Loading...
Expand API documentation with 10 new endpoints: YARA malware detection (4 endpoints), registrar search, tracking keys analysis (3 endpoints), Chrome network debug logs, and nameserver domain lookups - Visit /api-docs
Loading...
Add confidence level indicators when identifying code libraries in scan results
Loading...
Improved accuracy in library identification by reducing false matches for generic filenames
Loading...
Launch Model Context Protocol (MCP) server for AI integration - enables Claude Desktop and other AI tools to directly access ScanMalware security scanning capabilities - Visit https://mcp.scanmalware.com
Loading...
Enhanced library detection accuracy for inline and embedded code blocks
Loading...
Fix IOC Matcher false positive issue - eliminated 85% false positives by properly filtering legitimate CDN services (Cloudflare Pages, Wix, IPinfo, TikTok CDN)
Loading...
Improved library version detection accuracy with better validation logic
Loading...
Add detection for programming interfaces and system calls used in JavaScript code
Loading...
Improved reliability of network traffic capture and analysis during scans
Loading...
Expand library detection capabilities by 355% with 47 new identification signatures
Loading...
Expand threat intelligence coverage to 4.5M+ indicators with ThreatFox (123K network IOCs), MalwareBazaar (3.1M file hashes), and MISP (6.9K threat indicators)
Loading...
Fix scan result page error when analyzing forms with unusual field configurations
Loading...
Improved tracking of URL redirects to preserve fragment identifiers in destination URLs
Loading...
Improve code analysis reliability to 100% success rate, eliminating processing errors
Loading...
Launch automated copyright and licensing detection with 119% improvement in accuracy
Loading...
Add detection for JavaScript-based navigation and blob URLs for better tracking of client-side URL changes
Loading...
Add automatic URL preprocessing to unwrap redirect links from social media platforms and URL shorteners
Loading...
Enhanced IP geolocation display with full country names in Network tab
Loading...
Performance: Database query optimizations for faster domain search and tracking key lookups
Loading...
Add WAF and CDN detection to TLS fingerprint analysis (Cloudflare, Akamai, Fastly, and more)
Loading...
Add page-level JavaScript behavioral risk analysis on Scripts tab
Loading...
Add MD5 and SHA-1 hash search support to JavaScript search with direct links to script detail pages
Loading...
Improved domain registration (RDAP/WHOIS) caching with smart expiration-based refresh
Loading...
Improved JavaScript malware analysis with better code segment extraction and pattern matching
Loading...
Fix technology detection service - improved reliability for website fingerprinting
Loading...
Infrastructure: Improved network reliability for DNS lookups and domain intelligence
Loading...
Reduced false positives for regional brand TLD variants (e.g., crocs.eu, nike.de)
Loading...
Improved form analysis to reduce false positive password field detections
Loading...
Add business legitimacy assessment for positive trust signals in security analysis
Loading...
Enhanced form classification to recognize legitimate booking forms and third-party services
Loading...
Add industry-aware brand detection to reduce false positives for legitimate businesses
Loading...
Infrastructure: Upgraded fallback worker for improved bot detection evasion
Loading...
Add scan visibility selector UI with public, unlisted, and private options (coming soon)
Loading...
Fix malware scanning service and improve intrusion detection reliability
Loading...
Performance: Increased search database memory and extended Certificate Transparency query timeout for large searches
Loading...
Add dual search cluster monitoring to health checks for improved reliability
Loading...
Enhanced Certificate Transparency search performance and reliability
Loading...
Improved infrastructure monitoring with enhanced health checks for all services
Loading...
Refactored internal architecture for better scalability and maintainability
Loading...
Add dark mode support for YARA malware pattern detection results
Loading...
Launch YARA malware pattern detection with visual indicators on scan results
Loading...
Expand YARA malware detection capabilities by 23% (1,250 → 1,540 detection patterns)
Loading...
Add YARA malware pattern matching to JavaScript analysis for enhanced threat detection
Loading...
Add automated daily updates for YARA malware detection rules
Loading...
Launch unified search page with tabs for text, visual, and JavaScript code search
Loading...
Launch JavaScript Malware Analysis v2.0 with YARA patterns, fuzzy hashing (TLSH), webpack de-bundling, and ML-based code similarity detection
Loading...
Add library fingerprinting system to identify known JavaScript libraries and isolate suspicious code
Loading...
Infrastructure improvements: Updated to latest platform versions for better performance and security
Loading...
Add domain registration and nameserver information to scan results with DNS fallback support
Loading...
Launch JavaScript obfuscation detection to identify malicious code hiding techniques
Loading...
Improve scan reliability with automated retry logic, reducing error rate to under 6%
Loading...
Fix critical scanning issues and enhance error handling for improved stability
Loading...
Launch hybrid JavaScript fingerprinting with 19x coverage increase for better malware detection
Loading...
Fix GeoIP data enrichment for network analysis and IP geolocation
Loading...
Add trusted CDN whitelist badges to Scripts tab for better security transparency
Loading...
Fix screenshot loading issue on Visual Search page
Loading...
Add TLS Certificate Analysis API endpoint with CAA validation and Certificate Transparency data - Visit https://scanmalware.com/api-docs#tls
Loading...
Launch public changelog page with timezone-aware timestamps and clickable links - Visit /changelog
Loading...
Add RSS feed for changelog updates - Subscribe at /changelog.xml
Loading...
Launch security blog with articles on TLS certificates, CAA validation, and Certificate Transparency - Visit /blog
Loading...
Add RSS feed for blog posts - Subscribe at /rss.xml
Loading...
Add tag filtering for blog posts - Browse posts by topic
Loading...
Performance improvement: Database optimizations
Loading...
Add daily automated browser profile warmup for better bot detection evasion
Loading...
Expand browser profile warmup from 5 to 10 popular websites
Loading...
Security: Browser workers now run as non-root user for improved security
Loading...
Add CAA validation and certificate validity period checks to TLS analyzer
Loading...
Add hostname validation and certificate chain validation to TLS analyzer
Loading...
Add comprehensive security certificate test validation
Loading...
Fix TLS analyzer ECDSA key size false positive
Loading...
Implement TLS Certificate Analyzer with Certificate Transparency enrichment
Loading...
Optimize JavaScript fingerprinting performance
Loading...
Add CJK script detection and language code normalization
Loading...
Implement improved multi-signal language detection
Loading...
Implement multi-signal phishing clone detection
Loading...
Remove white background from favicons, make transparent
Loading...
Fix URL manipulation false positive for hash fragments in single-page apps
Loading...
Fix browser error URL exposure and improve AI analysis continuation logic
Loading...
Improved JavaScript fingerprinting processing speed with parallel workers
Loading...
Fix HTML upload race condition with inline data storage
Loading...
Enhanced reliability for JavaScript file downloads and analysis
Loading...
Fix null checks in expanded fingerprint metrics section
Loading...
Fix null handling for function count in JavaScript fingerprints
Loading...
Add obfuscated JavaScript detection for improved malware identification
Loading...
Add expanded JavaScript fingerprint metrics view
Loading...
Implement JavaScript fingerprinting feature for malware detection
Loading...
Faster JavaScript fingerprinting results for newly submitted scans

Showing recent updates and improvements