AIScamHunter v1.0.7 — Official Documentation & Complete Security Guide
AIScamHunter Icon AIScamHunter Icon

Advanced AI‑Driven Browser Security — v1.0.7

AIScamHunter es una extensión de seguridad de nueva generación que bloquea en tiempo real el phishing, el malware, las estafas de criptomonedas, las tiendas falsas, los rastreadores y las redirecciones maliciosas, con privacidad local, detección de nivel empresarial y un Centro de Herramientas integrado para análisis avanzados. Version 1.0.7 is now available in 18 languages for both Chrome and Edge, along with store‑description and display refinements. Earlier, Version 1.0.6 introduced massive tracker blocking with 36 filter lists and 30,000+ domains, per‑domain tracker statistics, Activity tab tracker filter, and Delete History.

v1.0.7
Detección mediante IA
Payment Shield
36 Tracker Lists
Escudo Cripto
Escáner masivo de URL
Delete History
Per‑Domain Stats
Añadir a Chrome — Gratis

01. ¿Qué es AIScamHunter?

AIScamHunter es una plataforma integral de seguridad para navegadores que analiza continuamente sitios web, scripts, descargas, redirecciones, certificados SSL y patrones de fraude antes de que las amenazas puedan comprometer tus datos. Combina más de 8 fuentes de inteligencia de amenazas, heurísticas locales y un potente Centro de Herramientas para verificaciones de seguridad manuales.

🛡️ Protección web en tiempo real

Every visited URL is automatically scanned using reputation, heuristics, SSL analysis, redirect chains, and script behaviour. Blocks malicious pages instantly via static rule sets and dynamic declarativeNetRequest rules.

🧠 Heurísticas avanzadas

Detecta typosquatting, ataques con homógrafos, dominios DGA, páginas de inicio de sesión falsas, sitios clonados y campañas de phishing de última generación mediante una puntuación ponderada (0-100).

🪤 Massive tracker blocking

Blocks trackers and ads from 30,000+ domains using 36 filter lists (EasyPrivacy, NoCoin, AdGuard, Peter Lowe's, BlocklistProject, 1Hosts, and more). Per‑domain statistics tracked in real time.

💳 Payment Processor Shield

Protects 32 payment processor domains — Stripe, PayPal, Apple Pay and Google Pay included — from impersonation, phishing lures and malicious redirects when you're entering payment details.

⚡ Arquitectura Manifest V3

Fully compliant with Chrome's latest security model: service worker, declarative net request (static + dynamic rules), isolated storage, and download interception.

📊 Per‑domain tracker statistics

See exactly which tracker domains are blocked most often — sorted and ranked in the Activity tab. Filter by tracker type, view top 20 domains with live counts.

Importante: AIScamHunter works silently in the background and blocks dangerous content before any interaction. No configuration required – protection is active after installation. Tracker blocking and the payment processor shield are enabled by default.

02. Instalación y compatibilidad

NavegadorCompatibilidadInstalación
ChromeGoogle Chrome
✓ CompletaChrome Web Store
EdgeMicrosoft Edge
✓ CompletaExtensiones de Chrome
BraveBrave
✓ CompletaChrome Web Store
OperaOpera
✓ CompletaExtensiones de Chrome
Opera GXOpera GX
✓ CompletaExtensiones de Chrome
VivaldiVivaldi
✓ CompletaCompatible con Chromium
ArcArc
✓ CompletaCompatible con Chromium
ChromiumChromium
✓ CompletaCompatible con Chromium
YandexYandex Browser
✓ CompletaExtensiones de Chrome
WhaleWhale
✓ CompletaExtensiones de Chrome
Cốc CốcCốc Cốc
✓ CompletaExtensiones de Chrome
MaxthonMaxthon
✓ CompletaExtensiones de Chrome
Kiwi BrowserKiwi Browser (Android)
✓ CompletaExtensiones de Chrome
Comodo DragonComodo Dragon
✓ CompletaExtensiones de Chrome
Samsung InternetSamsung Internet
⚠ ParcialCompatibilidad limitada
FirefoxFirefox
🕐 PróximamenteComplementos de Firefox
Ir a Chrome Web Store

Visita la tienda oficial o utiliza el enlace directo disponible en nuestro sitio web.

Añadir al navegador

Haz clic en "Añadir a Chrome". La instalación solo tarda unos segundos.

Fijar la extensión

Haz clic en el icono de rompecabezas y fija AIScamHunter para acceder rápidamente.

Protección activa

Todos los sistemas de seguridad están operativos de inmediato, sin necesidad de configuración.

03. Sistemas de protección completos

AIScamHunter combines multiple detection engines, behavioural analysis, external threat feeds (URLhaus, OpenPhish, Phishing Army), reputation APIs (Google Safe Browsing, URLScan, AbuseIPDB, VirusTotal) and native browser APIs. The current v1.0.7 adds a fully localised 18‑language interface, official Chrome and Edge support and on‑device content analysis, alongside the flagship tracker blocker (36 filter lists, 30,000+ domains), per‑domain tracker statistics and Delete History.

🧬 Typosquatting y ataques con homógrafos

Detecta dominios que suplantan marcas mediante sustitución de caracteres, caracteres cirílicos similares y trucos fonéticos: paypa1.com, g00gle.com. paypa1.com, g00gle.com.

📛 TLD sospechosos y DGA

Monitors .xyz, .top, .shop, .click, .live and uses entropy, consonant/vowel ratio and bigram analysis to detect algorithmically generated domains (DGA). Covers 25+ suspicious TLDs.

🔗 Análisis de redirecciones y URL acortadas

Resolves shortened links (bit.ly, tinyurl, etc.) and follows redirect chains to block cloaked malicious destinations. Uses SSRF protection on the server proxy.

🪤 Massive tracker blocking

Blocks trackers, ads, and analytics from 30,000+ domains using 36 filter lists: EasyPrivacy, NoCoin, Peter Lowe's, Fanboy Anti‑tracking, AdGuard (Base, Spyware, URL Tracking, Annoyances), BlocklistProject (Ads, Tracking, Malware, Phishing), 1Hosts, EasyList Cookie, and more. All blocking uses Chrome's declarativeNetRequest — both static rules and dynamic rules updated on every service worker restart.

💳 Payment Processor Shield

Recognises 32 legitimate payment processor domains — Stripe, PayPal, Apple Pay, Google Pay, Square, Klarna, Adyen and more — and flags impostor pages and malicious redirects before payment details are entered.

📅 Reputación SSL avanzada

Flags self‑signed, expired or expiring soon (<30 days) and abusable wildcard certificates often used by phishing sites. Weighted scoring from crt.sh certificate transparency data.

🤖 Puntuación de riesgo ponderada

Combina más de 8 fuentes (Google Safe Browsing, URLScan, AbuseIPDB, PhishDestroy, fuentes externas, PhishStats, reputación DNS, análisis SSL y heurísticas locales) con ponderaciones dinámicas. Puntuación de 0 a 100 con umbrales ajustables.

📦 Scripts ofuscados y mineros de criptomonedas

Detects eval/atob, document.write injections, and cryptocurrency miners (CoinHive, Crypto‑Loot) in real time. Part of the 36 tracker lists include NoCoin specifically targeting cryptomining scripts.

🎣 Skimmer & keylogger blocking

Identifies malicious web skimmers and keyloggers injected into checkout and login pages, intercepting card data before it is captured by attackers.

🔑 Credential leak detection

Warns you before credentials leave the page to a suspicious destination, catching credential‑harvesting forms and cross‑site exfiltration attempts.

⚙️ Web Worker monitoring

Monitors for suspicious Web Workers that run silently in the background, a common technique used by crypto miners and skimmers.

🤖 On‑Device Content Analysis

Runs AI‑style content analysis fully inside your browser with zero external API calls — page text and structure are scored locally for phishing patterns.

🔦 Search result safety ratings

Shows a safe / suspicious / dangerous badge directly on search engine results so you can avoid risky links before clicking.

📡 Threat Radar

A live radar view of threats detected and blocked across your browsing session, giving an at‑a‑glance picture of your active protection.

🗂️ Multi‑source intelligence

Aggregates cross‑checked signals from phishing databases, domain intelligence feeds and reputation APIs into one weighted verdict.

🤝 Community threat reporting

Report confirmed threats to help protect the wider AIScamHunter community while your report stays fully anonymised.

📴 Local‑only offline detection

Run protection in a fully offline, zero‑API mode — only local heuristics and cache are used, ideal for maximum privacy.

⛔ Protección contra descargas peligrosas

Bloquea archivos ejecutables (.exe, .bat, .scr, .apk, .js, .msi), analiza las descargas y permite eliminar archivos sospechosos.

🧾 Inicios de sesión falsos y tiendas fraudulentas

Identifies cloned banking pages and fake stores via cross‑domain credential submissions, unrealistic discounts, and missing contact or legal notices.

📞 Estafas de soporte técnico y quishing

Bloquea pantallas de bloqueo del navegador, falsas alertas de Microsoft/Apple y campañas de phishing mediante códigos QR (quishing).

🖱️ Advertencias al pasar el cursor y menú contextual

Pasa el cursor sobre cualquier enlace: se mostrará una advertencia si es peligroso. Clic derecho → analizar enlace, bloquear o confiar en el dominio al instante.

🌍 Safe mode & Strict Private Mode

Increases detection sensitivity, forces HTTPS, blocks legacy plugins. Strict Private Mode forces DoH, blocks WebRTC leaks, auto‑cleans private tabs. Total Privacy Mode blocks third‑party cookies and disables Web Workers.

📋 Detección de secuestro del portapapeles

Periodic check (every 8s, only when tab is visible) detects replaced crypto addresses or unexpected clipboard changes. Respects browser permissions policy – no errors on restricted sites.

🗑️ Delete History

From the Private page (private.html), users can delete all scan history, stats, and activity events in one action. Resets counters, clears all stored events and daily aggregates. Confirmation dialog prevents accidental deletion.

🪤 Per‑domain tracker statistics

Every blocked tracker request logs the originating domain. The Activity tab's tracker filter shows a ranked table of top domains with live block counts — sorted by most blocked. Stats update every 2 minutes via Chrome's declarativeNetRequest feedback API.

Fuentes de puntuación ponderada: Google Safe Browsing (25%), URLScan (9%), VirusTotal (10%), AbuseIPDB (8%), PhishDestroy (10%), external feeds (10%), PhishStats (4%), DNS reputation (3%), DNSBL (4%), SSL analysis (3%), domain age (2%), local heuristics (12%). All weights are dynamically adjusted based on strict/safe modes.

04. Todas las funciones en detalle

📊 Puntuación de riesgo dinámica

Cada página recibe una puntuación de riesgo de 0 a 100 basada en inteligencia procedente de múltiples fuentes. Los umbrales pueden personalizarse (modo estricto, modo seguro).

🚨 Página de advertencia segura

Cuando se detecta una amenaza crítica, una página de advertencia detallada muestra la categoría, la gravedad, las señales detectadas y las acciones disponibles (continuar una vez, confiar en el dominio, informar un falso positivo).

🔔 Notificaciones inteligentes

Alertas instantáneas cuando se bloquea un sitio malicioso, se identifica un crypto drainer o se detecta una redirección sospechosa. Se pueden desactivar.

🪤 Massive tracker blocker

Blocks trackers, ads, and analytics from 30,000+ domains using 36 filter lists (EasyPrivacy, NoCoin, AdGuard, Peter Lowe's, BlocklistProject, 1Hosts, Fanboy, EasyList Cookie, and 27 more). Uses Chrome's declarativeNetRequest for efficient, native blocking. Per‑domain statistics tracked in the Activity tab.

💳 Payment Processor Shield

Whitelists 32 payment processor domains so real Stripe, PayPal, Apple Pay and Google Pay checkouts never break, while everything outside the trusted list is still scanned and blocked by the normal protection rules.

📊 Centro de Herramientas con escáner masivo

Complete toolkit: URL/domain scanner (batch up to 10), email risk checker, phone number validator, password vault, privacy cleaner, personal stats, persistent history of last 5 checks, sparklines and activity charts.

🔐 Generador criptográfico de contraseñas

Utiliza crypto.getRandomValues() to generate strong passwords (4‑64 chars) with uppercase, digits, symbols and a real‑time strength indicator.

🧹 Limpiador y eliminador de privacidad

Eliminación con un clic de rastros de navegación con selección detallada de tipos de datos y rangos de tiempo predefinidos. También limpia IndexedDB y WebSQL.

🗑️ Delete History

From the Private page, delete all scan history, stats, and activity events in one action. Resets all counters and clears stored data. Confirmation dialog prevents accidental deletion.

🌐 Local allow/block lists

Los usuarios pueden añadir manualmente dominios a sus listas de permitidos o bloqueados. Estas reglas tienen prioridad sobre las globales y se conservan entre sesiones.

⚙️ Configuración avanzada

Enable/disable real‑time shield, safe mode, tracker blocking, download guard, notifications, strict mode, telemetry, strict private mode, total privacy mode. Reset statistics, clear activity log.

🌍 18 languages + RTL

Internacionalización completa, incluido el árabe (de derecha a izquierda). El tema claro/oscuro se sincroniza con las preferencias del sistema.

🔗 Sincronización administrativa y reporte de falsos positivos

Los usuarios pueden informar falsos positivos desde la página de advertencia. Los administradores revisan los informes y actualizan las listas globales de confianza o bloqueo. La extensión actualiza las listas cada hora.

🪤 Activity tab tracker filter

The Activity tab includes a dedicated tracker filter (🪤) that shows per‑domain block statistics — top 20 domains sorted by most blocked, with live counts from Chrome's declarativeNetRequest feedback API.

🧪 Verificación de fraudes por correo electrónico y teléfono

Comprueba direcciones de correo electrónico temporales o de baja reputación (API Disify) y números de teléfono asociados a prefijos utilizados en estafas conocidas. Disponible en el Centro de Herramientas.

05. Centro de Herramientas – utilidades avanzadas

El Centro de Herramientas (accesible desde la ventana emergente o la página dedicada private.html ) ofrece potentes herramientas de seguridad y estadísticas personales. Todo el historial se almacena localmente.

🌐 Escáner de URL / Dominios (por lotes)

Check any URL or domain with multi‑source analysis (Google Safe Browsing, URLScan, PhishDestroy, local heuristics). Returns risk score, category, detected signals. Supports batch scanning of up to 10 URLs at once. Persistent history of last 5 checks with sparklines.

📧 Email risk checker

Detects disposable or low‑reputation email addresses via Disify API (HTTPS). Checks if email is valid, disposable, or has low reputation score. Batch mode available.

📞 Phone number validator

Verifies phone numbers against a curated list of known scam prefixes and flags likely scam numbers. Country selection included.

📊 Gráficos de actividad y minigráficos

Visualises scans, blocked threats, and tracker blocks over 24h, 7 days, and 30 days. Sparkline graphs on stat cards show weekly trends. Dedicated tracker stat card shows total trackers blocked.

🔐 Bóveda de contraseñas (generador seguro)

Genera contraseñas criptográficamente seguras (crypto.getRandomValues). Adjustable length (4‑64 chars), character sets, and a live strength meter (weak → very strong).

🧹 Limpiador y eliminador de privacidad

Eliminación con un clic de rastros de navegación con selección detallada de tipos de datos y rangos de tiempo predefinidos. También limpia IndexedDB y WebSQL.

🗑️ Delete History

From the Private page, permanently delete all scan history, stats, activity events, and daily aggregates. Resets all counters (pages scanned, threats blocked, warnings, downloads, trackers) to zero. Confirmation dialog prevents accidental deletion.

🪤 Per‑domain tracker stats

Click the tracker stat card in the Activity tab to see a ranked table of top 20 tracker domains by block count. Data comes from Chrome's declarativeNetRequest feedback API — shows real blocked requests, not estimates.

06. Seguridad Crypto y Web3

Protección especializada para usuarios de criptomonedas contra drainers, billeteras falsas y estafas de sorteos.

💸 Detección de crypto drainers

Supervisa llamadas Web3 peligrosas como approve, transferFrom, personal_sign, eth_signTypedData, wallet_switchEthereumChain and more on pages that inject window.ethereum or window.solana.

🎁 Sorteos y airdrops falsos

Analiza textos y temporizadores de cuenta regresiva para detectar estafas como "Elon Musk giveaway", "duplica tus criptomonedas" y falsos airdrops.

👛 Páginas de billeteras falsas

Identifica sitios de phishing que suplantan a MetaMask, Binance, Coinbase, Ledger, Trust Wallet, Phantom y otros, utilizando typosquatting y trucos con subdominios.

📋 Secuestro del portapapeles (cripto)

Detecta cuando una dirección de criptomonedas copiada (por ejemplo una dirección Ethereum que comienza por 0x...) es reemplazada silenciosamente por una dirección maliciosa. Activa una alerta crítica.

07. Administration & false‑positive handling

AIScamHunter includes a private admin dashboard that aggregates user reports, manages global allow/block lists, and improves detection for all users. The dashboard displays total installations, active users, threat activity, and per‑domain statistics.

📢 User false‑positive reporting

From the warning page or popup, users can report a blocked domain as a false positive. The report includes domain, timestamp, and anonymised user hash.

🔧 Admin actions

Trust → adds to global allowlist; Block → adds to global blocklist; Resolve → removes the report without global changes. Decisions sync to all users via shared JSON files.

🔄 Hourly synchronisation

The extension polls the server every hour for updated trusted/blocked lists. Admin changes propagate to all users within ≤60 minutes.

📊 Anonymous telemetry (optional)

Anonymous event statistics (event type, category, severity, hashed user id, hashed domain) help improve detection. No personal data, IPs or full URLs are sent — domains are SHA‑256 hashed. Can be disabled in settings.

👥 User counting

Total installations are counted via the register telemetry event, which fires only once per genuine first install (stored in chrome.storage.local). Reinstalls after storage clear also register. The service worker restart on idle does not re-trigger registration — the _hasRegistered flag survives restarts.

🪤 Tracker statistics dashboard

The admin dashboard shows real‑time tracker block counts, per‑domain statistics from the dynamic rule matching, and threat activity trends. Updates hourly via telemetry data.

GDPR compliant: All user data is anonymised. You can disable telemetry or request data deletion at any time. No URLs, IPs, or personal identifiers are ever transmitted.

08. Privacy & data protection

Privacy‑first design: The majority of analysis is performed locally inside your browser – no URLs are sent to our servers by default. All blocking rules run natively via Chrome's declarativeNetRequest, so nothing is routed through external services.

🔒 Local processing

Heuristics (typosquatting, DGA, form analysis, script scanning) run entirely on your device. Only optional safe browsing checks go through secured proxies.

💳 Payment Processor Shield

Enforced locally through a static declarativeNetRequest allow rule for 32 payment domains — no payment data ever leaves your device. Real Stripe, PayPal, Apple Pay and Google Pay checkouts are never interrupted.

🕶️ Incognito mode support

Extension can be enabled in incognito (manual activation). Private‑browsing activity is kept in an isolated incognito profile and wiped automatically once all private windows close.

📊 Optional anonymised telemetry

A toggle in settings allows sending anonymous event statistics (event type, category, severity, hashed user id, hashed domain) to improve global detection. No personal identifiers, IPs or full URLs are ever transmitted — domains are SHA‑256 hashed. Registration fires once per genuine install.

🛡️ Proxied external APIs

Calls to Google Safe Browsing, URLScan, AbuseIPDB and VirusTotal are routed through AIScamHunter servers to hide your IP and avoid exposing API keys. SSRF protection on all server proxies.

🗑️ Delete History

Permanently delete all local scan history, stats, and activity events from the Private page. Confirmation dialog prevents accidental deletion. No server‑side data is affected.

09. Technical architecture

⚙️ Manifest V3 core

  • Service worker (background.js)
  • Declarative Net Request: 3 static rule sets (threats, trackers, safe mode) + dynamic rules for tracker blocking
  • Isolated storage, alarms, notifications
  • Session & local caching

🌐 Threat intelligence sources

  • Google Safe Browsing (via proxy)
  • URLhaus, OpenPhish, Phishing Army
  • PhishStats, PhishDestroy
  • URLScan, VirusTotal, AbuseIPDB (via proxy)
  • DNS reputation (Google DoH), DNSBL
  • Certificate transparency (crt.sh)
  • Local heuristics (typosquatting, DGA, homoglyphs)

📂 Internal rule sets

  • Malware & phishing (financial, crypto, gov, shipping)
  • Tracker blocking — 36 filter lists, 30,000+ domains (static + dynamic DNR rules)
  • Safe mode: HTTPS upgrade, block legacy plugins
  • Download guard: executable extensions
  • Payment Processor Shield: 32 payment domains whitelisted via static allow rule

📈 Weighted scoring engine

  • Weights: Google Safe Browsing 25%, URLScan 9%, VirusTotal 10%, AbuseIPDB 8%, PhishDestroy 10%, PhishStats 4%, external feeds 10%, DNS reputation 3%, DNSBL 4%, SSL analysis 3%, domain age 2%, local heuristics 12%.
  • Dynamic adjustment for strict/safe mode
  • Contextual reduction (no login/banking keywords)
  • Session cache (TTL 30 min)

🪤 Dynamic tracker rules

  • 36 filter lists parsed on every service worker restart
  • Domains converted to DNR dynamic rules in batches of 500
  • Max 30,000 domains, rule IDs 900000+
  • Per‑domain tracking via getMatchedRules feedback
  • Rule→domain mapping stored for live statistics

💳 Payment Processor Shield

  • Static DNR allow rule protecting 32 payment domains
  • Stripe, PayPal, Apple Pay, Google Pay, Square, Klarna, Adyen and more
  • Keeps legitimate checkouts working while threats are blocked

10. Permissions explained

PermissionReason
storageStores settings, allow/block lists, cache, stats, activity history, tracker domain counts, and user registration flag.
tabsRetrieves the active tab URL and hostname for scanning and status display.
alarmsManages scheduled tasks: telemetry queue, feed refresh, tracker count update (every 2 min), cache cleanup, keep‑alive pings.
downloadsAnalyses and blocks dangerous downloads; post‑download file scanning and deletion.
notificationsDisplays security alerts when threats are blocked.
cookiesPrivacy cleaner and detection of suspicious cookies.
browsingDataClears cache, history, downloads, form data, etc.
contextMenusAdds scan/block/trust options to right‑click menu.
webNavigationMonitors redirects and navigation events for real‑time analysis.
clipboardReadDetects clipboard hijacking (only when tab is visible, 8s interval).
declarativeNetRequestEfficient network request filtering — static rule sets (threats, trackers, safe mode) + dynamic rules for 30,000+ tracker domains.
declarativeNetRequestFeedbackProvides matched rule data for per‑domain tracker statistics — shows real blocked request counts in the Activity tab.
activeTabProvides access to the current tab for on‑demand scanning.
privacyEnforces Strict Private Mode (WebRTC/DoH) and Total Privacy Mode (3rd‑party cookies).

11. Frequently asked questions

🔍 General
⚙️ Instalación
🛡️ Protección
🪤 Tracker Blocking
🔒 Privacidad
💰 Crypto
👥 Administración