90trust / 100

ScanMalware.com URL Scanner

by scanmalware.com in Security & trust

MCP serverPassing, checked 4 h ago

MCP server for ScanMalware.com URL scanning, malware detection, and analysis.

https://mcp.scanmalware.com/mcp

Last 30 days

All checks passedSome failedAll failedNot checked
Uptime
100%
Response time
266 ms typical, 266 ms slowest 5%
Last check
4 h ago
Next check
in 2 h

How to call it

Add it to any MCP client that supports remote servers.

{
  "mcpServers": {
    "scanmalware-com-url-scanner": {
      "type": "http",
      "url": "https://mcp.scanmalware.com/mcp"
    }
  }
}

128 tools

  • get_recent_scans

    List the most recent public scans, newest first (paginated with page and limit). Each row has the scan ID, URL, status, visibility and submission time. Unlisted and private scans are never included.

  • submit_scan

    Submit a URL to ScanMalware to be rendered and analysed in a sandboxed browser; returns the new scan_id. scan_type is required and sets who can see the result: 'public' lists the URL and its results in the public feed, visible to anyone and to search engines; 'unlisted' keeps the

  • get_scan_summary

    Get a compact summary of one scan: submitted URL, final URL after redirects, status, completion time and the security verdict (verdict text, risk level, confidence and risk factors). Useful as the first look at a scan; the verdict is empty for a few seconds after a scan completes

  • wait_for_scan

    Wait for a submitted scan to finish by polling its status every poll_interval_s seconds, up to timeout_s seconds (default 180). Returns the final compact summary (URL, final URL, status, completion time and the security verdict), or the last known status with timeout set to true

  • get_scan_result

    Get the full result document of one scan: URLs and redirects, page title, load times, links, network requests, IP addresses, JavaScript files, TLS, fuzzy hashes, screenshot hashes, favicon and the security verdict. The response is large; the compact summary is enough for a verdic

  • search_scans

    Search the archive of public scans by text in the URL, domain or page title (paginated); q needs at least 3 characters and search_type narrows the match (default 'all'). Each result has the scan ID, URL, status, title, submission time and hosting ASN.

  • get_ai_analysis

    Get the AI analysis of one scan: classification (LEGITIMATE to CONFIRMED_SCAM), scam type, risk score, confidence, impersonated brand and the key evidence behind it. The analysis is produced a few minutes after the scan completes and returns not found until then. It can disagree

  • get_scan_progress

    Get the progress of a running scan: current step, total steps, step name, percentage and status. Useful for checking whether a scan has finished before reading its results. scan_id is the UUID of a ScanMalware scan.

  • get_scan_ioc

    Check one scan against threat-intelligence indicator feeds: matching IP addresses and domains the page contacted, the threat types, and a summary of total and unique matches. scan_id is the UUID of a ScanMalware scan.

  • get_tls_details

    Get the TLS certificate the scanned site presented: subject, issuer, validity dates, whether it was valid or expired, and related details. scan_id is the UUID of a ScanMalware scan.

  • get_tls_asn1

    Get the raw ASN.1 structure of the TLS certificate from one scan, for detailed certificate inspection. scan_id is the UUID of a ScanMalware scan.

  • get_technologies_by_scan

    List the web technologies detected on a scanned page (frameworks, CMS, CDN, analytics and so on), with versions where known. scan_id is the UUID of a ScanMalware scan.

  • get_bot_protection

    Get the bot-protection and CAPTCHA services detected on a scanned page (for example Cloudflare Turnstile), with a detected flag. Phishing kits often use these to hide from scanners. scan_id is the UUID of a ScanMalware scan.

  • get_yara_matches

    Get the YARA rule matches recorded for one scan, with the matching rules and a summary by severity and category. scan_id is the UUID of a ScanMalware scan.

  • get_jarm_signatures

    Get the JARM TLS server fingerprints measured for the hosts in one scan, with whether each matches a known signature. A shared JARM often points to the same server software or hosting platform, so it is a weak pivot on its own. scan_id is the UUID of a ScanMalware scan.

  • get_analyzer_results

    List which analysis modules ran for one scan (for example JavaScript fingerprinting and AI analysis), with each module's status, success flag and timing. Useful for checking why a result is missing. scan_id is the UUID of a ScanMalware scan.

  • get_clipboard_events

    Get the clipboard writes the page attempted while it was scanned, with the event count and whether collection ran. Empty with an explanatory note when the page wrote nothing. scan_id is the UUID of a ScanMalware scan.

  • get_js_fingerprints

    List the JavaScript files a scanned page loaded, each with its fingerprint: hashes (SHA-256, SHA-1, MD5, normalized and fuzzy), size metrics, detected library and bundler. The include_* options add function lists, HTTP headers or ML vector details. Useful for collecting script ha

  • get_scan_reports

    List the user reports and votes filed about one scan (for example marked safe or malicious), with the total count; report_type filters by kind. Empty when nobody has reported the scan. scan_id is the UUID of a ScanMalware scan.

  • get_domain_scans

    List the recent scans of a domain and its subdomains, newest first, up to limit; status filters by scan status. Each row has matched_on: 'url' when the scan was submitted for a host under this domain, and only 'final_url' when another site redirected there. A verdict on a final_u

  • get_domain_history

    Get the scan history of a domain with the total count and the scans, paginated with page and limit.

  • get_domain_stats

    Get scan counts for a domain: total, unique, completed and failed scans, first and latest scan, and scans in the last 24 hours, 7 days and 30 days.

  • search_by_ip

    List scans of pages served from an IP address (paginated), each with scan ID, URL and time. On shared hosting and CDNs an IP serves many unrelated sites, so a match is not evidence of a connection.

  • get_ip_stats

    Get statistics for an IP address across the archive: total scans, unique URLs, first and last seen, geolocation, ASN and organisation, BGP and DNS data; paginated.

  • search_by_asn

    Get what the archive knows about an autonomous system (ASN number, without 'AS'): organisation, total scans, unique URLs, first and last seen and BGP prefixes; paginated.

  • search_similar_scans

    Find scans that look like this one by screenshot similarity, favicon or fuzzy page hash (methods, default screenshot), each with URL, final URL, title and what it matched by; paginated. Useful for finding copies of a phishing page on other hosts. scan_id is the UUID of a ScanMalw

  • search_semantic

    Search scans by meaning rather than exact words, comparing the query with scanned page content (for example 'bank login page asking for card details'). threshold (default 0.7) is the minimum similarity; an empty result means nothing was similar enough.

  • search_by_favicon

    Search scans by favicon hash (paginated): a mmh3 hash by default, or the favicon's MD5 with hash_type='md5'.

  • search_ai_high_risk

    List scans that the AI analysis rated high risk, optionally above min_risk_score and min_confidence, each with URL, title and the analysis. min_risk_score is on the AI's 0-10 risk scale (default 7) and min_confidence is a 0-100 percentage (default 70).

  • search_ai_scam_type

    List scans whose AI analysis named a given scam type, such as 'Phishing', each with URL, title, submission time and the analysis (verdict, classification, risk score). The match is on the scam type text the analysis produced.

  • search_ai_classification

    List scans whose AI analysis gave a specific classification: LEGITIMATE, LOW_RISK, MODERATE_RISK, HIGH_RISK or CONFIRMED_SCAM. Each result has the URL, title, submission time and the analysis.

  • get_analyzer_stats

    Get platform-wide statistics for the scan analysis modules: the modules and their run counts. Describes the service, not a particular scan.

  • search_analyzer_high_risk

    List scans that the security analyzer scored as high risk, highest first (paginated), each with URL, risk score, verdict, confidence and analysis time. min_risk_score raises the threshold.

  • get_favicon

    Get the favicon recorded for a scan_id: its size, MD5 and SHA-256 hashes, and the image base64-encoded. found is false when no favicon is stored for the scan.

  • get_favicon_stats

    Get favicon statistics across the archive: total favicons, those seen in the last 24 hours and the most common hashes with sample URLs. This aggregate query can take up to 90 seconds by default.

  • get_screenshot_stats

    Get screenshot statistics across the archive: total screenshots, hash coverage and the distribution of perceptual hash types.

  • search_similar_screenshots

    Find screenshots within max_distance (Hamming distance, default 3) of an integer perceptual hash (hash_type, default phash), each with scan, URL, title, distance and similarity score.

  • search_ocr

    Search OCR text (paginated). q must contain at least 3 characters after trimming. This query can take up to 90 seconds by default.

  • search_ocr_pattern

    Search the text read by OCR from scan screenshots for a pattern (paginated); case_sensitive controls matching. Useful for finding pages that show the same lure text as an image.

  • search_by_jarm

    List scans whose server presented this JARM TLS fingerprint (paginated). Large hosting platforms share JARMs across many unrelated sites, so check what the matches have in common.

Security scan

  • No findings. We scan names, descriptions and tool definitions for hidden instructions and other prompt-injection patterns.

Recent checks

WhenResultHTTPTime
4 h agoPassed200266 ms