Statistics
What ScanMalware saw in the last 12 hours: the infrastructure behind malicious websites, the threats they carry, and where scanned URLs come from.
Scans and malicious scans
All public scans per hour (UTC)
Show as table
| Period | Scans | Malicious |
|---|---|---|
| 09-25 14:00 UTC | 54 | 24 |
| 09-25 15:00 UTC | 153 | 27 |
| 09-25 16:00 UTC | 166 | 36 |
| 09-25 17:00 UTC | 155 | 30 |
| 09-25 18:00 UTC | 160 | 27 |
| 09-25 19:00 UTC | 160 | 21 |
| 09-25 20:00 UTC | 164 | 24 |
| 09-25 21:00 UTC | 183 | 30 |
| 09-25 22:00 UTC | 146 | 10 |
| 09-25 23:00 UTC | 177 | 32 |
| 09-26 00:00 UTC | 186 | 64 |
| 09-26 01:00 UTC | 139 | 31 |
| 09-26 02:00 UTC | 107 | 1 |
IP addresses hosting the most malicious sites
Distinct malicious hostnames per IP address
Networks (ASNs) with the most malicious sites
Distinct malicious hostnames per network
- 171
- 57
- 7
- 3
- 2
- 2
- 2
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
Domains with the most malicious subdomains
Distinct malicious subdomains under one registered domain
- 9
- 8
- 2
- 2
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
Hosting platforms most abused
Malicious sites on free-subdomain and app-hosting platforms
- 126
- 47
- 12
- 8
- 8
- 1
- 1
- 1
Threat types
Malicious scans by the kind of threat found
- Credential Phishing170
- Malware Distribution100
- Brand Impersonation34
- Other16
- Illegal Gambling15
- Investment/Crypto Scam4
- Fake Shopping2
- Advance Fee Fraud1
Top-level domains of malicious sites
Distinct malicious hostnames per TLD
- .dev154
- .app56
- .se18
- .com11
- .org4
- .io3
- .ru3
- .co2
- .de2
- .click1
- .digital1
- .fr1
- .net1
- .page1
- .ro1
Countries hosting the most malicious sites
Country of the hosting IP address. The second column leaves out shared CDN addresses, whose location is the network's, not the site's server.
| Country | All sites | Excl. CDN |
|---|---|---|
| 🇺🇸 United States | 229 | 7 |
| 🇩🇪 Germany | 11 | 2 |
| 🇸🇬 Singapore | 7 | 7 |
| 🇫🇷 France | 4 | 4 |
| 🇷🇺 Russia | 3 | 3 |
| 🇬🇧 United Kingdom | 2 | 2 |
| 🇧🇩 Bangladesh | 1 | 1 |
| 🇫🇮 Finland | 1 | 1 |
| 🇷🇴 Romania | 1 | 1 |
| 🇿🇦 South Africa | 1 | 1 |
Countries hosting the most malicious sites (own servers)
Sites not behind a shared CDN, by the country of their server
- 🇸🇬 Singapore7
- 🇺🇸 United States7
- 🇫🇷 France4
- 🇷🇺 Russia3
- 🇩🇪 Germany2
- 🇬🇧 United Kingdom2
- 🇧🇩 Bangladesh1
- 🇫🇮 Finland1
- 🇷🇴 Romania1
- 🇿🇦 South Africa1
Cities hosting the most malicious sites
Sites not behind a shared CDN, by the city of their server. The city is known for 13 of 29 such sites.
- 🇫🇷 Lauterbourg · France3
- 🇷🇴 Bucharest · Romania1
- 🇺🇸 Chicago · United States1
- 🇺🇸 Dallas · United States1
- 🇫🇮 Helsinki · Finland1
- 🇺🇸 Los Angeles · United States1
- 🇺🇸 Manassas · United States1
- 🇿🇦 Midrand · South Africa1
- 🇩🇪 Nuremberg · Germany1
- 🇺🇸 Phoenix · United States1
- 🇷🇺 St Petersburg · Russia1
Countries submitting the most URLs
Ranked by URLs submitted by people. Excludes ScanMalware's own automated scanning.
- 1.🇮🇹 Italy
- 2.🇺🇸 United States
- 3.🇪🇸 Spain
- 4.🇧🇷 Brazil
- 5.🇨🇱 Chile
- 6.🇩🇪 Germany
- 7.🇫🇷 France
- 8.🇬🇧 United Kingdom
- 9.🇮🇩 Indonesia
- 10.🇱🇹 Lithuania
Site traffic
Counted from 2026-09-25 (UTC). Scan views and visitors count people only: search engines, other crawlers and automated clients are left out.
Most viewed scans
Public scan results ranked by the number of people who opened them
- 1.padisahbet.yeni-koruma.icuIndex of /
- 2.psyrusec.comSign in to your account
- 3.sunny-fox-33db.pages.devCloudflare Speed Test 소개 | Cloudflare
- 4.artikel-69b5dd2c1248-dpnxxg3ylwbi.edgeone.dev0 コンテナガーデン向けの自動水やり装置 人気ランキング: A Practical Starter Guide
- 5.foreign-crimson-8t6kpaas-dpn7f7qb61y2.edgeone.devNext.js by Vercel - The React Framework
- 6.itauu.vercel.appBanco Itaú | Abra sua conta Personnalité no Itaú. Atendimento e benefícios pensados para você
- 7.reimagined-funicular-ivory.vercel.appNaver Sign in
- 8.preview-chemresolution.pages.devTechnical Resources | Chem Resolution Inc.
- 9.ziparvel.pages.devNamrata Shirodkar Kiss : 'సరిలేరు నీకెవ్వరు' మూవీ టీం ఫుల్ జోష్లో ఉంది. - Parzivel
- 10.spond.comSpond - The new standard for organizing groups
- 11.fluffy-pink-waub20ye-dpxglxsklgjm.edgeone.devTencent Edgeone
- 12.chubby-olive-5conlg0a-dpnd4j7ahk26.edgeone.devNext.js by Vercel - The React Framework
- 13.x.comVal d'Isère (@valdisere) / X
- 14.diezodontologia.comDiez Odontología | Dr. Diego Zoppi - Quilmes
- 15.dssprev.pages.devDelightfully Stuck Studios — Places worth getting stuck in
Countries visitors come from
Ranked by the number of people visiting ScanMalware
- 1.🇧🇷 Brazil
- 2.🇸🇬 Singapore
- 3.🇺🇸 United States
- 4.🇦🇷 Argentina
- 5.🇨🇳 China
- 6.🇲🇽 Mexico
- 7.🇧🇩 Bangladesh
- 8.🇫🇷 France
- 9.🇹🇷 Türkiye
- 10.🇨🇱 Chile
- 11.🇮🇹 Italy
- 12.🇺🇦 Ukraine
- 13.🇨🇴 Colombia
- 14.🇵🇭 Philippines
- 15.🇪🇨 Ecuador
- 16.🇻🇪 Venezuela
- 17.🇵🇪 Peru
- 18.🇷🇺 Russia
- 19.🇵🇾 Paraguay
- 20.🇵🇹 Portugal
Most requested domains via the API
Domain and subdomain lookups (certificate and host APIs)
- cosmos.windows-int.net5,004
- oceanai.ai2,844
- cruisepal.com2,844
- seamedix.com2,844
- memphismarine.com2,844
- oceanopt.ai2,844
- mariapps.in2,844
- smartpal.ai2,844
- example.com1,560
- trendmilcro.com1,498
- e2e.test1,113
- httpbin.org850
- bld3r.com720
- qld33.top700
- msb.com.vn654
Most requested registered domains via the API
Lookups grouped by registered domain; hover for how many names were looked up
- deere.com40,105
- kpmg.com37,975
- bmwgroup.com29,368
- tamu.edu20,018
- bmw.com18,132
- google.com10,349
- wjunction.com8,711
- zoho.com7,480
- onehousing.com.vn7,012
- magento.com6,718
- att.com6,256
- windows-int.net5,285
- eldoradobrasil.com.br4,416
- usiminas.com4,196
- ennov.com3,680
Busiest API endpoints
API requests by endpoint (our own systems excluded)
- /api/v1/search/smql1,000,436
- /api/v1/ct/dns/{host}998,419
- /api/v1/hosts/{host}997,463
- /api/v1/ct/dns/{x}7,595
- /api/v1/hosts/{x}7,594
- /api/v1/domains/{host}/scans4,250
- /api/v1/tls/{id}3,005
- /api/v1/jarm/scan/{id}2,956
- /api/v1/result/{id}2,014
- /api/v1/search/ip/{ip}1,967
- /api/v1/yara/{id}1,584
- /api/v1/search/jarm/{hash}1,571
- /api/v1/ioc/{id}1,567
- /api/v1/scans/{id}/jsfingerprints1,518
- /api/v1/rpki/{id}1,477
JavaScript
Scripts loaded by the 1,175 websites scanned in the last 12 hours, counted as the number of distinct websites. Third-party means the script comes from a different registered domain than the page.
Most popular libraries and frameworks
Websites where the library or framework was detected
- jQuery · JavaScript library357
- React · JavaScript framework91
- jQuery UI · JavaScript library35
- Bootstrap · UI framework34
- Vue.js · JavaScript framework34
- OWL Carousel · JavaScript library30
- Lightbox · JavaScript library21
- Swiper · JavaScript library18
- AMP · JavaScript framework17
- RequireJS · JavaScript framework12
- Lodash · JavaScript library11
- Nuxt.js · JavaScript framework10
- Hammer.js · JavaScript library9
- Moment.js · JavaScript library9
- Modernizr · JavaScript library8
Most used third-party script providers
Registered domain serving the script
- googletagmanager.com372
- cloudflare.com263
- google.com158
- yandex.ru126
- facebook.net125
- google-analytics.com112
- doubleclick.net103
- gstatic.com99
- jsdelivr.net82
- yastatic.net70
- googlesyndication.com60
- ajax.googleapis.com56
- cloudflareinsights.com49
- mail.ru48
- adtrafficquality.google44
Most loaded third-party scripts
Script URL without its query string
- www.googletagmanager.com/gtag/js349
- challenges.cloudflare.com/turnstile/v0/b/d76008a69eab/api.js187
- www.googletagmanager.com/gtm.js158
- challenges.cloudflare.com/turnstile/v0/api.js143
- connect.facebook.net/en_US/fbevents.js104
- mc.yandex.ru/metrika/tag.js101
- www.google-analytics.com/analytics.js100
- www.gstatic.com/recaptcha/releases/kemdRjWFxNjgsGdhRslyEPwU/recaptcha__en.js64
- www.google.com/recaptcha/api.js55
- yastatic.net/safeframe-bundles/0.89/host.js52
- yastatic.net/partner-code-bundles/libs/libs-edc4844f.js49
- yastatic.net/partner-code-bundles/libs/libs_render-edc4844f.js49
- yandex.ru/ads/system/context.js46
- ep2.adtrafficquality.google/sodar/sodar2.js44
- pagead2.googlesyndication.com/bg/gB2Im7ywZGaT6V0iKhMAgnnbTRH0TG-zboKpZQ5m5yk.js43
Most common first-party scripts
Script path served from the website's own domain
- /wp-includes/js/jquery/jquery.min.js99
- /wp-includes/js/jquery/jquery-migrate.min.js92
- /wp-includes/js/wp-emoji-release.min.js84
- /cdn-cgi/challenge-platform/h/b/scripts/jsd/d76008a69eab/main.js66
- /* (3 files)57
- /component---src-containers-sub-page-js-e7fb715774364f9d93eb.js53
- /dc6a8720040df98778fe970bf6c000a41750d3ae-71b279128d9d41aa1f02.js52
- /cdn-cgi/challenge-platform/h/b/orchestrate/chl_page/v141
- /wp-includes/js/dist/hooks.min.js33
- /wp-includes/js/dist/i18n.min.js32
- /cdn-cgi/scripts/5c5dd728/cloudflare-static/email-decode.min.js31
- /wp-includes/js/jquery/ui/core.min.js30
- /wp-content/plugins/elementor/assets/js/* (3 files)24
- /_next/static/chunks/* (22 files)23
- /cdn/s/trekkie.storefront.f1ba865b3fecd812ad617f74ac079261075e9edb.min.js22
TLS server fingerprints
JARM and JA4S describe how a web server answers a TLS connection; servers running the same software and configuration share a fingerprint. Counted as distinct websites. The malicious rankings order fingerprints by the share of their websites that were malicious (at least 10 websites, 5 of them malicious). JA4S is recorded since 23 September 2026.
Most common JARM fingerprints
JARM fingerprints most associated with malicious sites
| Fingerprint | Usual network | Sites | Malicious |
|---|---|---|---|
| 27d40d40d00040d1dc42d43d00041d5691268beec3bcca1d5ab3aacc89645f | Cloudflare, Inc. | 16 | 10 (63%) |
| 27d40d40d00040d00042d43d00041df04c41293ba84f6efe3a613b22f983e6 | Cloudflare, Inc. | 344 | 129 (38%) |
| 3fd3fd00000000000043d43d00043dc3b2afa8a5ec09b510a8559aff7899fb | Amazon.com, Inc. | 202 | 63 (31%) |
| 2ad2ad0002ad2ad22c42d42d000000a9aee03a49a8a804a0ef27cc7feba684 | Datacamp Limited | 19 | 5 (26%) |
| 27d40d40d00040d1dc42d43d00041d6183ff1bfae51ebd88d70384363d525c | Cloudflare, Inc. | 326 | 58 (18%) |
| 27d40d40d29d40d1dc42d43d00041ded961c16c68658e95145597cf992c36c | Google LLC | 84 | 10 (12%) |
| 2ad2ad0002ad2ad22c42d42d0000008a5941c13f67e0c0a2c8a36bfeef6920 | ACE | 71 | 8 (11%) |
| 40d40d40d00000000043d43d00043d6aff5ab0f4fc31897186312c9e639319 | Amazon.com, Inc. | 134 | 12 (9%) |
| 2ad2ad0002ad2ad00042d42d0000002059a3b916699461c5923779b77cf06b | Akamai International B.V. | 63 | 5 (8%) |
| 27d27d27d00027d00042d43d00041df04c41293ba84f6efe3a613b22f983e6 | Cloudflare, Inc. | 84 | 6 (7%) |
| 29d29d00029d29d00041d41d00041db78309d03c04b7072bacbf1ce396279b | Amazon.com, Inc. | 185 | 7 (4%) |
Most common JA4S fingerprints
| Fingerprint | Usual network | Sites | Malicious |
|---|---|---|---|
| t130200_1302_234ea6891581 | Cloudflare, Inc. | 1,092 | 229 (21%) |
| t130200_1302_a56c5b993250 | ACE | 955 | 59 (6%) |
| t130200_1301_a56c5b993250 | Amazon.com, Inc. | 494 | 26 (5%) |
| t130200_1303_a56c5b993250 | Amazon.com, Inc. | 367 | 76 (21%) |
| t1206h2_c02f_3603f09c43ba | Amazon.com, Inc. | 45 | 1 (2%) |
| t1207h1_c030_b948729f6510 | Telia Company AB | 19 | 1 (5%) |
| t1207h2_c030_b948729f6510 | Akamai Technologies, Inc. | 19 | 1 (5%) |
| t1207h2_c02f_b948729f6510 | Alibaba (US) Technology Co., Ltd. | 16 | 1 (6%) |
| t1205h1_c008_845f7282a956 | Wildcard UK Limited | 12 | 2 (17%) |
| t1206h2_c02b_3f14cc51fb76 | Cloudflare, Inc. | 12 | 2 (17%) |
| t1207h1_c02f_b948729f6510 | Akamai Technologies, Inc. | 12 | 0 (0%) |
| t1207h2_c02b_b948729f6510 | Rambler Internet Holding LLC | 10 | 0 (0%) |
| t1207h2_c02c_b948729f6510 | JSC RTComm.RU | 9 | 2 (22%) |
| t1204h2_c030_b252f78b95f6 | eTOP sp. z o.o. | 8 | 0 (0%) |
| t1206h1_c02f_cd2f8cf6dcd7 | LLC VK | 8 | 0 (0%) |
JA4S fingerprints most associated with malicious sites
| Fingerprint | Usual network | Sites | Malicious |
|---|---|---|---|
| t130200_1302_234ea6891581 | Cloudflare, Inc. | 1,092 | 229 (21%) |
| t130200_1303_a56c5b993250 | Amazon.com, Inc. | 367 | 76 (21%) |
| t130200_1302_a56c5b993250 | ACE | 955 | 59 (6%) |
| t130200_1301_a56c5b993250 | Amazon.com, Inc. | 494 | 26 (5%) |
A scan counts as malicious when our AI verdict rates it Confirmed scam or High risk, or our rule-based verdict rates it Malicious. Threat statistics cover all public scans; the submitting-country ranking covers URLs submitted by people and excludes ScanMalware's own automated scanning. Unlisted and private scans are never shown individually. Refreshed every 10–60 minutes depending on the window · generated 2026-09-26 02:47 UTC.