ScanMalware.com URL Scanner
by scanmalware.com in Security & trust
MCP server for ScanMalware.com URL scanning, malware detection, and analysis.
https://mcp.scanmalware.com/mcp
Last 30 days
- Uptime
- 100%
- Response time
- 266 ms typical, 266 ms slowest 5%
- Last check
- 4 h ago
- Next check
- in 2 h
How to call it
Add it to any MCP client that supports remote servers.
{
"mcpServers": {
"scanmalware-com-url-scanner": {
"type": "http",
"url": "https://mcp.scanmalware.com/mcp"
}
}
}128 tools
- get_recent_scans
List the most recent public scans, newest first (paginated with page and limit). Each row has the scan ID, URL, status, visibility and submission time. Unlisted and private scans are never included.
- submit_scan
Submit a URL to ScanMalware to be rendered and analysed in a sandboxed browser; returns the new scan_id. scan_type is required and sets who can see the result: 'public' lists the URL and its results in the public feed, visible to anyone and to search engines; 'unlisted' keeps the
- get_scan_summary
Get a compact summary of one scan: submitted URL, final URL after redirects, status, completion time and the security verdict (verdict text, risk level, confidence and risk factors). Useful as the first look at a scan; the verdict is empty for a few seconds after a scan completes
- wait_for_scan
Wait for a submitted scan to finish by polling its status every poll_interval_s seconds, up to timeout_s seconds (default 180). Returns the final compact summary (URL, final URL, status, completion time and the security verdict), or the last known status with timeout set to true
- get_scan_result
Get the full result document of one scan: URLs and redirects, page title, load times, links, network requests, IP addresses, JavaScript files, TLS, fuzzy hashes, screenshot hashes, favicon and the security verdict. The response is large; the compact summary is enough for a verdic
- search_scans
Search the archive of public scans by text in the URL, domain or page title (paginated); q needs at least 3 characters and search_type narrows the match (default 'all'). Each result has the scan ID, URL, status, title, submission time and hosting ASN.
- get_ai_analysis
Get the AI analysis of one scan: classification (LEGITIMATE to CONFIRMED_SCAM), scam type, risk score, confidence, impersonated brand and the key evidence behind it. The analysis is produced a few minutes after the scan completes and returns not found until then. It can disagree
- get_scan_progress
Get the progress of a running scan: current step, total steps, step name, percentage and status. Useful for checking whether a scan has finished before reading its results. scan_id is the UUID of a ScanMalware scan.
- get_scan_ioc
Check one scan against threat-intelligence indicator feeds: matching IP addresses and domains the page contacted, the threat types, and a summary of total and unique matches. scan_id is the UUID of a ScanMalware scan.
- get_tls_details
Get the TLS certificate the scanned site presented: subject, issuer, validity dates, whether it was valid or expired, and related details. scan_id is the UUID of a ScanMalware scan.
- get_tls_asn1
Get the raw ASN.1 structure of the TLS certificate from one scan, for detailed certificate inspection. scan_id is the UUID of a ScanMalware scan.
- get_technologies_by_scan
List the web technologies detected on a scanned page (frameworks, CMS, CDN, analytics and so on), with versions where known. scan_id is the UUID of a ScanMalware scan.
- get_bot_protection
Get the bot-protection and CAPTCHA services detected on a scanned page (for example Cloudflare Turnstile), with a detected flag. Phishing kits often use these to hide from scanners. scan_id is the UUID of a ScanMalware scan.
- get_yara_matches
Get the YARA rule matches recorded for one scan, with the matching rules and a summary by severity and category. scan_id is the UUID of a ScanMalware scan.
- get_jarm_signatures
Get the JARM TLS server fingerprints measured for the hosts in one scan, with whether each matches a known signature. A shared JARM often points to the same server software or hosting platform, so it is a weak pivot on its own. scan_id is the UUID of a ScanMalware scan.
- get_analyzer_results
List which analysis modules ran for one scan (for example JavaScript fingerprinting and AI analysis), with each module's status, success flag and timing. Useful for checking why a result is missing. scan_id is the UUID of a ScanMalware scan.
- get_clipboard_events
Get the clipboard writes the page attempted while it was scanned, with the event count and whether collection ran. Empty with an explanatory note when the page wrote nothing. scan_id is the UUID of a ScanMalware scan.
- get_js_fingerprints
List the JavaScript files a scanned page loaded, each with its fingerprint: hashes (SHA-256, SHA-1, MD5, normalized and fuzzy), size metrics, detected library and bundler. The include_* options add function lists, HTTP headers or ML vector details. Useful for collecting script ha
- get_scan_reports
List the user reports and votes filed about one scan (for example marked safe or malicious), with the total count; report_type filters by kind. Empty when nobody has reported the scan. scan_id is the UUID of a ScanMalware scan.
- get_domain_scans
List the recent scans of a domain and its subdomains, newest first, up to limit; status filters by scan status. Each row has matched_on: 'url' when the scan was submitted for a host under this domain, and only 'final_url' when another site redirected there. A verdict on a final_u
- get_domain_history
Get the scan history of a domain with the total count and the scans, paginated with page and limit.
- get_domain_stats
Get scan counts for a domain: total, unique, completed and failed scans, first and latest scan, and scans in the last 24 hours, 7 days and 30 days.
- search_by_ip
List scans of pages served from an IP address (paginated), each with scan ID, URL and time. On shared hosting and CDNs an IP serves many unrelated sites, so a match is not evidence of a connection.
- get_ip_stats
Get statistics for an IP address across the archive: total scans, unique URLs, first and last seen, geolocation, ASN and organisation, BGP and DNS data; paginated.
- search_by_asn
Get what the archive knows about an autonomous system (ASN number, without 'AS'): organisation, total scans, unique URLs, first and last seen and BGP prefixes; paginated.
- search_similar_scans
Find scans that look like this one by screenshot similarity, favicon or fuzzy page hash (methods, default screenshot), each with URL, final URL, title and what it matched by; paginated. Useful for finding copies of a phishing page on other hosts. scan_id is the UUID of a ScanMalw
- search_semantic
Search scans by meaning rather than exact words, comparing the query with scanned page content (for example 'bank login page asking for card details'). threshold (default 0.7) is the minimum similarity; an empty result means nothing was similar enough.
- search_by_favicon
Search scans by favicon hash (paginated): a mmh3 hash by default, or the favicon's MD5 with hash_type='md5'.
- search_ai_high_risk
List scans that the AI analysis rated high risk, optionally above min_risk_score and min_confidence, each with URL, title and the analysis. min_risk_score is on the AI's 0-10 risk scale (default 7) and min_confidence is a 0-100 percentage (default 70).
- search_ai_scam_type
List scans whose AI analysis named a given scam type, such as 'Phishing', each with URL, title, submission time and the analysis (verdict, classification, risk score). The match is on the scam type text the analysis produced.
- search_ai_classification
List scans whose AI analysis gave a specific classification: LEGITIMATE, LOW_RISK, MODERATE_RISK, HIGH_RISK or CONFIRMED_SCAM. Each result has the URL, title, submission time and the analysis.
- get_analyzer_stats
Get platform-wide statistics for the scan analysis modules: the modules and their run counts. Describes the service, not a particular scan.
- search_analyzer_high_risk
List scans that the security analyzer scored as high risk, highest first (paginated), each with URL, risk score, verdict, confidence and analysis time. min_risk_score raises the threshold.
- get_favicon
Get the favicon recorded for a scan_id: its size, MD5 and SHA-256 hashes, and the image base64-encoded. found is false when no favicon is stored for the scan.
- get_favicon_stats
Get favicon statistics across the archive: total favicons, those seen in the last 24 hours and the most common hashes with sample URLs. This aggregate query can take up to 90 seconds by default.
- get_screenshot_stats
Get screenshot statistics across the archive: total screenshots, hash coverage and the distribution of perceptual hash types.
- search_similar_screenshots
Find screenshots within max_distance (Hamming distance, default 3) of an integer perceptual hash (hash_type, default phash), each with scan, URL, title, distance and similarity score.
- search_ocr
Search OCR text (paginated). q must contain at least 3 characters after trimming. This query can take up to 90 seconds by default.
- search_ocr_pattern
Search the text read by OCR from scan screenshots for a pattern (paginated); case_sensitive controls matching. Useful for finding pages that show the same lure text as an image.
- search_by_jarm
List scans whose server presented this JARM TLS fingerprint (paginated). Large hosting platforms share JARMs across many unrelated sites, so check what the matches have in common.
Security scan
- No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.
Recent checks
| When | Result | HTTP | Time |
|---|---|---|---|
| 4 h ago | Passed | 200 | 266 ms |