AIScamHunter ist eine Sicherheits-Erweiterung der nächsten Generation, die Phishing, Malware, Krypto-Betrug, gefälschte Online-Shops, Tracker und bösartige Weiterleitungen in Echtzeit blockiert – mit lokalem Datenschutz, Erkennung auf Unternehmensniveau und einem integrierten Tools Center für erweiterte Sicherheitsanalysen.
AIScamHunter ist eine umfassende Browser-Sicherheitsplattform, die Websites, Skripte, Downloads, Weiterleitungen, SSL-Zertifikate und Betrugsmuster kontinuierlich analysiert, bevor Bedrohungen Ihre Daten gefährden können. Sie kombiniert mehr als 8 Bedrohungsdatenquellen, lokale Heuristiken und ein leistungsstarkes Tools Center für manuelle Sicherheitsprüfungen.
Every visited URL is automatically scanned using reputation, heuristics, SSL analysis, redirect chains, and script behaviour. Blocks malicious pages instantly via static rule sets and dynamic declarativeNetRequest rules.
Erkennt Typosquatting, Homoglyphen-Angriffe, DGA-Domains, gefälschte Anmeldeseiten, geklonte Websites und neue Phishing-Kampagnen mithilfe eines gewichteten Bewertungssystems (0–100).
Blocks trackers and ads from 30,000+ domains using 36 filter lists (EasyPrivacy, NoCoin, AdGuard, Peter Lowe's, BlocklistProject, 1Hosts, and more). Per‑domain statistics tracked in real time.
Detects look‑alike domains and cloned login pages impersonating 200+ major brands, and protects 80 legitimate financial domains (Stripe, PayPal, banks, crypto exchanges) from being misflagged when you enter payment details.
Fully compliant with Chrome's latest security model: service worker, declarative net request (static + dynamic rules), isolated storage, and download interception.
See exactly which tracker domains are blocked most often — sorted and ranked in the Activity tab. Filter by tracker type, view top 20 domains with live counts.
| Browser | Kompatibilität | Installation |
|---|---|---|
| ✓ Vollständig | Chrome Web Store | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chrome Web Store | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chromium-kompatibel | |
| ✓ Vollständig | Chromium-kompatibel | |
| ✓ Vollständig | Chromium-kompatibel | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ✓ Vollständig | Chrome-Erweiterungen | |
| ⚠ Teilweise | Eingeschränkte Unterstützung | |
| 🕐 Demnächst verfügbar | Firefox-Add-ons |
Besuchen Sie den offiziellen Store oder nutzen Sie den Direktlink auf unserer Website.
Klicken Sie auf „Zu Chrome hinzufügen“. Die Installation dauert nur wenige Sekunden.
Klicken Sie auf das Puzzle-Symbol und heften Sie AIScamHunter für einen schnellen Zugriff an.
Alle Sicherheitssysteme sind sofort einsatzbereit – keine Konfiguration erforderlich.
AIScamHunter combines multiple detection engines, behavioural analysis, external threat feeds (URLhaus, OpenPhish, Phishing Army), reputation APIs (Google Safe Browsing, URLScan, AbuseIPDB, VirusTotal) and native browser APIs. The current v1.0.8.5 release adds per‑category tracker breakdown (Analytics, Advertising, Fingerprinting, Cryptomining), a per‑site tracker info panel in the popup, and an expanded high‑reputation domain list for fewer false positives. These build on the 18‑language localised interface, official Chrome and Edge support, and the flagship tracker blocker (36 filter lists, 30,000+ domains) with per‑domain tracker statistics and Delete History.
Erkennt Domains, die Marken durch Zeichenaustausch, ähnlich aussehende kyrillische Zeichen und phonetische Tricks imitieren: paypa1.com, g00gle.com. paypa1.com, g00gle.com.
Monitors 14 high‑risk TLDs (.tk, .ml, .ga, .cf, .gq, .xyz, .top, .buzz, .club, .work, .click, .download, .zip, .mov) and uses entropy, consonant/vowel ratio and bigram analysis to detect algorithmically generated domains (DGA).
Resolves shortened links (bit.ly, tinyurl, etc.) and follows redirect chains to block cloaked malicious destinations. Uses SSRF protection on the server proxy.
Blocks trackers, ads, and analytics from 30,000+ domains using 36 filter lists: EasyPrivacy, NoCoin, Peter Lowe's, Fanboy Anti‑tracking, AdGuard (Base, Spyware, URL Tracking, Annoyances), BlocklistProject (Ads, Tracking, Malware, Phishing), 1Hosts, EasyList Cookie, and more. All blocking uses Chrome's declarativeNetRequest — both static rules and dynamic rules updated on every service worker restart.
Recognises 80 legitimate financial domains — Stripe, PayPal, Apple Pay, Google Pay, Square, Klarna, Adyen, banks and crypto exchanges — so real checkouts are never interrupted, while impostor pages, look‑alike domains and cloned logins of 200+ major brands are flagged.
Flags self‑signed, expired or expiring soon (<30 days) and abusable wildcard certificates often used by phishing sites. Weighted scoring from crt.sh certificate transparency data.
Kombiniert mehr als 8 Quellen (Google Safe Browsing, URLScan, AbuseIPDB, PhishDestroy, externe Feeds, PhishStats, DNS-Reputation, SSL-Analyse und lokale Heuristiken) mit dynamischer Gewichtung. Bewertung von 0 bis 100 mit anpassbaren Schwellenwerten.
Detects eval/atob, document.write injections, and cryptocurrency miners (CoinHive, Crypto‑Loot) in real time. Part of the 36 tracker lists include NoCoin specifically targeting cryptomining scripts.
Identifies malicious web skimmers and keyloggers injected into checkout and login pages, intercepting card data before it is captured by attackers.
Warns you before credentials leave the page to a suspicious destination, catching credential‑harvesting forms and cross‑site exfiltration attempts.
Monitors for suspicious Web Workers that run silently in the background, a common technique used by crypto miners and skimmers.
Runs local content analysis fully inside your browser with zero external API calls — page text and structure are scored locally for phishing patterns.
Shows a safe / suspicious / dangerous badge directly on search engine results so you can avoid risky links before clicking.
A live radar view of threats detected and blocked across your browsing session, giving an at‑a‑glance picture of your active protection.
Aggregates cross‑checked signals from phishing databases, domain intelligence feeds and reputation APIs into one weighted verdict.
Report confirmed threats to help protect the wider AIScamHunter community while your report stays fully anonymised.
Run protection in a fully offline, zero‑API mode — only local heuristics and cache are used, ideal for maximum privacy.
Blockiert ausführbare Dateien (.exe, .bat, .scr, .apk, .js, .msi), analysiert Downloads und bietet die Möglichkeit, verdächtige Dateien zu löschen.
Identifies cloned banking pages and fake stores via cross‑domain credential submissions, unrealistic discounts, and missing contact or legal notices.
Blockiert Browser-Sperrbildschirme, gefälschte Microsoft-/Apple-Warnungen und QR-Code-Phishing-Kampagnen (Quishing).
Bewegen Sie den Mauszeiger über einen Link: Bei Gefahr wird eine Warnung angezeigt. Rechtsklick → Link prüfen, Domain blockieren oder sofort vertrauen.
Increases detection sensitivity, forces HTTPS, blocks legacy plugins. Strict Private Mode forces DoH, blocks WebRTC leaks, auto‑cleans private tabs. Total Privacy Mode blocks third‑party cookies and disables Web Workers.
Periodic check (every 8s, only when tab is visible) detects replaced crypto addresses or unexpected clipboard changes. Respects browser permissions policy – no errors on restricted sites.
From the Private page (private.html), users can delete all scan history, stats, and activity events in one action. Resets counters, clears all stored events and daily aggregates. Confirmation dialog prevents accidental deletion.
Every blocked tracker request logs the originating domain. The Activity tab's tracker filter shows a ranked table of top domains with live block counts — sorted by most blocked. Stats update every 2 minutes via Chrome's declarativeNetRequest feedback API.
Jede Seite erhält eine Risikobewertung von 0 bis 100 auf Basis mehrerer Bedrohungsquellen. Die Schwellenwerte können angepasst werden (Strenger Modus, Sicherheitsmodus).
Wird eine kritische Bedrohung erkannt, zeigt eine detaillierte Warnseite Kategorie, Schweregrad, erkannte Signale und mögliche Aktionen an (einmal fortfahren, Domain vertrauen, Fehlalarm melden).
Sofortige Benachrichtigungen, wenn eine schädliche Website blockiert, ein Crypto-Drainer erkannt oder eine verdächtige Weiterleitung festgestellt wird. Deaktivierbar.
Blocks trackers, ads, and analytics from 30,000+ domains using 36 filter lists (EasyPrivacy, NoCoin, AdGuard, Peter Lowe's, BlocklistProject, 1Hosts, Fanboy, EasyList Cookie, and 27 more). Uses Chrome's declarativeNetRequest for efficient, native blocking. Per‑domain statistics tracked in the Activity tab.
Protects 80 legitimate financial domains (Stripe, PayPal, Apple Pay, Google Pay, Square, banks, crypto exchanges) so real checkouts never break, while look‑alike domains and cloned logins of 200+ major brands are scanned and blocked by the normal protection rules.
Complete toolkit: URL/domain scanner (batch up to 10), email risk checker, phone number validator, password vault, privacy cleaner, personal stats, persistent history of last 5 checks, sparklines and activity charts.
Verwendet crypto.getRandomValues() um starke Passwörter (8–64 Zeichen) mit Großbuchstaben, Zahlen, Symbolen und einer Echtzeit-Stärkeanzeige zu erzeugen.
Entfernt Browser-Spuren mit einem Klick, inklusive detaillierter Datenauswahl und Zeitbereichsvorgaben. Bereinigt außerdem IndexedDB und WebSQL.
From the Private page, delete all scan history, stats, and activity events in one action. Resets all counters and clears stored data. Confirmation dialog prevents accidental deletion.
Users can manually add domains to personal allowlist or blocklist. They override global rules and persist locally across browser sessions — no account or sync service required.
Enable/disable real‑time shield, safe mode, tracker blocking, download guard, notifications, strict mode, telemetry, strict private mode, total privacy mode. Reset statistics, clear activity log.
Vollständige Internationalisierung einschließlich Arabisch (Rechts-nach-Links). Das helle/dunkle Design wird mit den Systemeinstellungen synchronisiert.
Benutzer können Fehlalarme direkt von der Warnseite melden. Administratoren prüfen die Meldungen und aktualisieren globale Vertrauens- und Sperrlisten. Die Erweiterung aktualisiert diese Listen stündlich.
The Activity tab includes a dedicated tracker filter (🪤) that shows per‑domain block statistics — top 20 domains sorted by most blocked, with live counts from Chrome's declarativeNetRequest feedback API.
Prüft E-Mail-Adressen auf Wegwerf- oder schlechte Reputation (Disify API) sowie Telefonnummern gegen bekannte Betrugspräfixe. Verfügbar im Tools Center.
Das Tools Center (über das Popup oder die spezielle Seite private.html erreichbar) bietet leistungsstarke Sicherheitswerkzeuge und persönliche Statistiken. Der gesamte Verlauf wird lokal gespeichert.
Check any URL or domain with multi‑source analysis (Google Safe Browsing, URLScan, PhishDestroy, local heuristics). Returns risk score, category, detected signals. Supports batch scanning of up to 10 URLs at once. Persistent history of last 5 checks with sparklines.
Detects disposable or low‑reputation email addresses via Disify API (HTTPS). Checks if email is valid, disposable, or has low reputation score. Batch mode available.
Verifies phone numbers against a curated list of known scam prefixes and flags likely scam numbers. Country selection included.
Visualises scans, blocked threats, and tracker blocks over 24h, 7 days, and 30 days. Sparkline graphs on stat cards show weekly trends. Dedicated tracker stat card shows total trackers blocked.
Erzeugt kryptografisch sichere Passwörter (crypto.getRandomValues). Adjustable length (8‑64 chars), character sets, and a live strength meter (weak → very strong).
Entfernt Browser-Spuren mit einem Klick, inklusive detaillierter Datenauswahl und Zeitbereichsvorgaben. Bereinigt außerdem IndexedDB und WebSQL.
From the Private page, permanently delete all scan history, stats, activity events, and daily aggregates. Resets all counters (pages scanned, threats blocked, warnings, downloads, trackers) to zero. Confirmation dialog prevents accidental deletion.
Click the tracker stat card in the Activity tab to see a ranked table of top 20 tracker domains by block count. Data comes from Chrome's declarativeNetRequest feedback API — shows real blocked requests, not estimates.
Spezialisierter Schutz für Kryptowährungsnutzer vor Drainers, gefälschten Wallets und Giveaway-Betrug.
Überwacht gefährliche Web3-Aufrufe wie approve, transferFrom, personal_sign, eth_signTypedData, wallet_switchEthereumChain and more on pages that inject window.ethereum or window.solana.
Analysiert Texte und Countdown-Timer, um Betrugsmaschen wie „Elon Musk Giveaway“, „Verdopple deine Kryptowährungen“ und gefälschte Airdrops zu erkennen.
Erkennt Phishing-Websites, die sich als MetaMask, Binance, Coinbase, Ledger, Trust Wallet, Phantom usw. ausgeben, indem Typosquatting und irreführende Subdomains erkannt werden.
Erkennt, wenn eine kopierte Krypto-Adresse (z. B. eine Ethereum-Adresse beginnend mit 0x...) unbemerkt durch eine bösartige Adresse ersetzt wird. Löst eine kritische Warnung aus.
AIScamHunter includes a private admin dashboard that aggregates user reports, manages global allow/block lists, and improves detection for all users. The dashboard displays total installations, active users, threat activity, and per‑domain statistics.
From the warning page or popup, users can report a blocked domain as a false positive. The report includes domain, timestamp, and anonymised user hash.
Trust → adds to global allowlist; Block → adds to global blocklist; Resolve → removes the report without global changes. Decisions sync to all users via shared JSON files.
The extension polls the server every hour for updated trusted/blocked lists. Admin changes propagate to all users within ≤60 minutes.
Anonymous event statistics (event type, category, severity, hashed user id, country) plus the domain of flagged events are sent to improve detection for the whole community. No email, no name and no full browsing URLs are stored. Telemetry is enabled by default and can be disabled with one toggle in settings.
Total installations are counted via the register telemetry event, which fires only once per genuine first install (stored in chrome.storage.local). Reinstalls after storage clear also register. The service worker restart on idle does not re-trigger registration — the _hasRegistered flag survives restarts.
The admin dashboard shows real‑time tracker block counts, per‑domain statistics from the dynamic rule matching, and threat activity trends. Updates hourly via telemetry data.
Heuristics (typosquatting, DGA, form analysis, script scanning) run entirely on your device. Only optional safe browsing checks go through secured proxies.
Applied locally in the detection engine — 80 legitimate financial domains (Stripe, PayPal, Apple Pay, Google Pay) are never misflagged, so payment data stays on your device and real checkouts are never interrupted. Clones of 200+ major brands are detected locally.
Extension can be enabled in incognito (manual activation). Private‑browsing activity is kept in an isolated incognito profile and wiped automatically once all private windows close.
A toggle in settings controls event statistics (event type, category, severity, hashed user id, country) and flagged‑domain data sent to improve global detection. No email, name or full URLs are stored. Registration fires once per genuine install.
Calls to Google Safe Browsing, URLScan, AbuseIPDB and VirusTotal are routed through AIScamHunter servers to hide your IP and avoid exposing API keys. SSRF protection on all server proxies.
Permanently delete all local scan history, stats, and activity events from the Private page. Confirmation dialog prevents accidental deletion. No server‑side data is affected.
| Permission | Reason |
|---|---|
| storage | Stores settings, allow/block lists, cache, stats, activity history, tracker domain counts, and user registration flag. |
| tabs | Retrieves the active tab URL and hostname for scanning and status display. |
| alarms | Manages scheduled tasks: telemetry queue, feed refresh, tracker count update (every 2 min), cache cleanup, keep‑alive pings. |
| downloads | Analyses and blocks dangerous downloads; post‑download file scanning and deletion. |
| notifications | Displays security alerts when threats are blocked. |
| cookies | Privacy cleaner and detection of suspicious cookies. |
| browsingData | Clears cache, history, downloads, form data, etc. |
| contextMenus | Adds scan/block/trust options to right‑click menu. |
| webNavigation | Monitors redirects and navigation events for real‑time analysis. |
| declarativeNetRequest | Efficient network request filtering — static rule sets (threats, trackers, safe mode) + dynamic rules for 30,000+ tracker domains. |
| activeTab | Provides access to the current tab for on‑demand scanning. |
| privacy | Enforces Strict Private Mode (WebRTC/DoH) and Total Privacy Mode (3rd‑party cookies). |
Note: Clipboard hijack detection uses the browser's asynchronous Clipboard API and respects each site's clipboard‑read permission — no extra manifest permission is requested. Per‑domain tracker statistics come from Chrome's declarativeNetRequest matched‑rule data when available.