ScanMalware.com URL Scanner
com.scanmalware.mcp/scanmalware-mcpMCP server for ScanMalware.com URL scanning, malware detection, and analysis.
Score: 100/100
Handshake verified by our own probe.
why this score
Tools · 128
Get recent public scans (paginated).
Submit a URL to ScanMalware for scanning. WARNING: scan_type defaults to 'public', which publishes the target URL and scan results in the public feed and makes them visible to other users and search e…
Get compact scan summary by scan_id.
Poll until a scan reaches a terminal status, returning the final summary.
Get full scan result by scan_id.
Search scans (q must be at least 3 characters).
Get AI analysis for a scan_id (if available).
Get scan progress by scan_id.
Get IOC matches for a scan_id.
Get TLS details for a scan_id.
Get TLS certificate ASN.1 data for a scan_id.
Get detected technologies for a scan_id.
Get bot-protection detection for a scan_id.
Get YARA matches for a scan_id.
Get JARM signatures for a scan_id.
Get analyzer results for a scan_id.
Get clipboard events for a scan_id.
Get JavaScript fingerprints for a scan_id.
Get available reports for a scan_id.
Get recent scans for a domain.
Get historical scans for a domain (paginated).
Get summary statistics for a domain.
Search scans by IP address (paginated).
Get IP statistics (paginated).
Search scans by ASN (paginated).
Search for scans similar to a scan_id (paginated).
Semantic search over scans (paginated).
Search scans by favicon hash (paginated).
Search AI high-risk scans.
Search AI scans by scam type.
Search AI scans by classification.
Get analyzer statistics overview.
Search analyzer high-risk scans (paginated).
Get the favicon for a scan_id: size, hashes, and the image itself base64-encoded. Use the md5 with search_by_favicon to pivot.
Get favicon statistics. This aggregate query can take up to 90 seconds by default.
Get screenshot statistics.
Search for similar screenshots by hash.
Search OCR text (paginated). q must contain at least 3 characters after trimming. This query can take up to 90 seconds by default; allow it to finish before retrying.
Search OCR by pattern (paginated).
Search scans by JARM signature (paginated).
Search scans by fuzzy hash (paginated).
Search scans by screenshot hash (paginated).
Search suspicious clipboard indicators (paginated).
Get recent malware threats.
Get recent YARA threats.
Get certificate transparency data for a domain.
Get CT DNS records for a domain.
Find CT domains on an IP address.
Find similar CT domains for a domain.
Get CT certificate timeline for a domain.
Get API root metadata.
Get API health status.
Get platform statistics.
Get latest capability stats.
Get capability stats by date.
Get clipboard statistics.
Get CPE statistics.
Get CPEs for a scan_id.
Search CPEs by pattern (paginated).
Get IDS alerts for a scan_id.
Get JARM statistics.
Get malware stats.
Get malware details for a scan_id.
Get YARA stats.
Get YARA results for a scan_id.
Get safe browsing stats.
Get safe browsing threats for a scan_id.
Get top tracking keys.
Search by tracking key (paginated).
Search technologies (paginated).
Get technology combinations (paginated).
Get popular technologies (paginated).
Get technology stats.
Search scans by nameserver.
Get RDAP details for a scan_id.
Search scans by registrar (paginated).
Submit a scan report.
Get OCR stats.
Get OCR data for a scan_id.
Get Open Graph data for a scan_id.
Get pastejacking findings for a scan_id.
Describe the network log (Chrome NetLog) for a scan_id: whether one exists, its size, and its encoding. The log itself is not returned - these are routinely tens of megabytes gzipped.
Get PCAP metadata for a scan_id.
Search favicon by mmh3 hash (paginated).
Get JS Fingerprinter2 results for a scan_id.
Get JS Fingerprinter2 stats.
Get JS Fingerprinter2 health check.
Get JS Fingerprinter2 fingerprint coverage.
Search JS obfuscation signals. Supply at least one of risk_level, min_risk_score, or has_eval; limit alone is not a filter. For example, use has_eval=true. Explicit false and a min_risk_score of 0 are…
Search JS malware families. Supply min_cluster_size (at least 1) or similarity_threshold (0 to 1), or both; limit alone is not a filter. For example, use min_cluster_size=2.
Search JS Fingerprinter2 by composite hash.
Search JS Fingerprinter2 by signature.
Search JS Fingerprinter2 similar scans.
Get JS segments for a scan_id.
Search JS segments by code hash.
Search JS segments by normalized hash.
Get suspicious JS segments for a scan_id.
Get unknown JS segments for a scan_id.
Run JS differential analysis for a scan_id.
Get JS fingerprint library inventory.
Search JS fingerprints by patterns. Supply at least one boolean filter: has_eval, has_crypto, has_websocket, high_entropy, no_library, or cdn_mismatch. For example, use has_eval=true. Explicit false i…
Search obfuscated JS fingerprints.
Search JS fingerprints by server type.
Search JS fingerprints by bundler type.
Search JS fingerprints by CDN.
Search JS fingerprints by detected library name. Use identifiers from get_js_library_inventory, such as 'react' or 'nextjs'. The display name 'Next.js' is accepted as an alias for 'nextjs'.
Search JS fingerprints by library version.
Search JS fingerprints by fuzzy hash.
Search JS fingerprints by MD5 hash.
Search JS fingerprints by normalized hash.
Search JS fingerprints by SHA1 hash.
Search JS fingerprints by SHA256 hash.
Find similar JS fingerprints by hash.
Search JS fingerprints by bundler (paginated).
Search JS fingerprints by library (paginated).
Search JS fingerprints by library version (paginated).
Search JS fingerprints by fuzzy hash (paginated).
Search JS fingerprints by MD5 (paginated).
Search JS fingerprints by normalized hash (paginated).
Search JS fingerprints by SHA1 (paginated).
Search JS fingerprints by SHA256 (paginated).
Get JS fingerprint by ID.
Find similar JS fingerprints.
Get JS fingerprint similarity counts.
Get JS fingerprint source.
Get JS fingerprint bundle statistics.
Get JS fingerprint library statistics.
Get JS fingerprint hash prevalence for a scan_id.
How to use
Add to your Claude Desktop / Cursor / Cline MCP config:
{
"mcpServers": {
"scanmalware.com_url_scanner": {
"url": "https://mcp.scanmalware.com/mcp",
"transport": "streamable-http"
}
}
}