AIScamHunter v1.0.8.5 — Official Documentation & Complete Security Guide
AIScamHunter Icon AIScamHunter Icon
logo dark logo white

Advanced Smart Analysis‑Driven Browser Security — v1.0.8.5

AIScamHunter est une extension de sécurité nouvelle génération qui bloque en temps réel le phishing, les malwares, les arnaques crypto, les faux sites marchands, les traqueurs et les redirections malveillantes — avec une confidentialité locale par défaut, une détection de niveau professionnel et un Centre d’Outils intégré pour les analyses avancées.

v1.0.8.5
Smart Analysis Detection
Brand Impersonation
36 Tracker Lists
Bouclier Crypto
Analyseur d’URL en lot
Delete History
Per‑Domain Stats
Ajouter à Chrome — Gratuit

01. Qu’est-ce qu’AIScamHunter ?

AIScamHunter est une plateforme complète de sécurité pour navigateur qui analyse en continu les sites web, scripts, téléchargements, redirections, certificats SSL et schémas d’arnaques avant qu’une menace ne puisse compromettre vos données. Elle combine plus de 8 sources de renseignement sur les menaces, des heuristiques locales et un puissant Centre d’Outils pour les vérifications de sécurité manuelles.

🛡️ Protection web en temps réel

Every visited URL is automatically scanned using reputation, heuristics, SSL analysis, redirect chains, and script behaviour. Blocks malicious pages instantly via static rule sets and dynamic declarativeNetRequest rules.

🧠 Heuristiques avancées

Détecte le typosquatting, les attaques par homoglyphes, les domaines DGA, les fausses pages de connexion, les sites clonés et les campagnes de phishing émergentes grâce à un système de notation pondéré (0 à 100).

🪤 Massive tracker blocking

Blocks trackers and ads from 30,000+ domains using 36 filter lists (EasyPrivacy, NoCoin, AdGuard, Peter Lowe's, BlocklistProject, 1Hosts, and more). Per‑domain statistics tracked in real time.

💳 Brand Impersonation Shield

Detects look‑alike domains and cloned login pages impersonating 200+ major brands, and protects 80 legitimate financial domains (Stripe, PayPal, banks, crypto exchanges) from being misflagged when you enter payment details.

⚡ Architecture Manifest V3

Fully compliant with Chrome's latest security model: service worker, declarative net request (static + dynamic rules), isolated storage, and download interception.

📊 Per‑domain tracker statistics

See exactly which tracker domains are blocked most often — sorted and ranked in the Activity tab. Filter by tracker type, view top 20 domains with live counts.

Important : AIScamHunter works silently in the background and blocks dangerous content before any interaction. No configuration required – protection is active after installation. Tracker blocking and brand impersonation protection are enabled by default.

02. Installation et compatibilité

NavigateurCompatibilitéInstallation
ChromeGoogle Chrome
✓ ComplèteChrome Web Store
EdgeMicrosoft Edge
✓ ComplèteExtensions Chrome
BraveBrave
✓ ComplèteChrome Web Store
OperaOpera
✓ ComplèteExtensions Chrome
Opera GXOpera GX
✓ ComplèteExtensions Chrome
VivaldiVivaldi
✓ ComplèteCompatible Chromium
ArcArc
✓ ComplèteCompatible Chromium
ChromiumChromium
✓ ComplèteCompatible Chromium
YandexYandex Browser
✓ ComplèteExtensions Chrome
WhaleWhale
✓ ComplèteExtensions Chrome
Cốc CốcCốc Cốc
✓ ComplèteExtensions Chrome
MaxthonMaxthon
✓ ComplèteExtensions Chrome
Kiwi BrowserKiwi Browser (Android)
✓ ComplèteExtensions Chrome
Comodo DragonComodo Dragon
✓ ComplèteExtensions Chrome
Samsung InternetSamsung Internet
⚠ PartielSupport limité
FirefoxFirefox
🕐 Bientôt disponibleModules complémentaires Firefox
Accéder au Chrome Web Store

Visitez la boutique officielle ou utilisez le lien direct disponible sur notre site web.

Ajouter au navigateur

Cliquez sur « Ajouter à Chrome ». L’installation ne prend que quelques secondes.

Épingler l’extension

Cliquez sur l’icône en forme de puzzle et épinglez AIScamHunter pour un accès rapide.

Protection active

Tous les systèmes de sécurité sont opérationnels immédiatement — aucune configuration requise.

03. Systèmes de protection complets

AIScamHunter combines multiple detection engines, behavioural analysis, external threat feeds (URLhaus, OpenPhish, Phishing Army), reputation APIs (Google Safe Browsing, URLScan, AbuseIPDB, VirusTotal) and native browser APIs. The current v1.0.8.5 release adds per‑category tracker breakdown (Analytics, Advertising, Fingerprinting, Cryptomining), a per‑site tracker info panel in the popup, and an expanded high‑reputation domain list for fewer false positives. These build on the 18‑language localised interface, official Chrome and Edge support, and the flagship tracker blocker (36 filter lists, 30,000+ domains) with per‑domain tracker statistics and Delete History.

🧬 Typosquatting et attaques par homoglyphes

Détecte les domaines qui imitent des marques à l’aide de substitutions de caractères, de lettres cyrilliques ressemblantes et de techniques phonétiques : paypa1.com, g00gle.com. paypa1.com, g00gle.com.

📛 TLD suspects et DGA

Monitors 14 high‑risk TLDs (.tk, .ml, .ga, .cf, .gq, .xyz, .top, .buzz, .club, .work, .click, .download, .zip, .mov) and uses entropy, consonant/vowel ratio and bigram analysis to detect algorithmically generated domains (DGA).

🔗 Analyse des redirections et des URL raccourcies

Resolves shortened links (bit.ly, tinyurl, etc.) and follows redirect chains to block cloaked malicious destinations. Uses SSRF protection on the server proxy.

🪤 Massive tracker blocking

Blocks trackers, ads, and analytics from 30,000+ domains using 36 filter lists: EasyPrivacy, NoCoin, Peter Lowe's, Fanboy Anti‑tracking, AdGuard (Base, Spyware, URL Tracking, Annoyances), BlocklistProject (Ads, Tracking, Malware, Phishing), 1Hosts, EasyList Cookie, and more. All blocking uses Chrome's declarativeNetRequest — both static rules and dynamic rules updated on every service worker restart.

💳 Brand Impersonation Shield

Recognises 80 legitimate financial domains — Stripe, PayPal, Apple Pay, Google Pay, Square, Klarna, Adyen, banks and crypto exchanges — so real checkouts are never interrupted, while impostor pages, look‑alike domains and cloned logins of 200+ major brands are flagged.

📅 Réputation SSL avancée

Flags self‑signed, expired or expiring soon (<30 days) and abusable wildcard certificates often used by phishing sites. Weighted scoring from crt.sh certificate transparency data.

🤖 Évaluation du risque pondérée

Combine plus de 8 sources (Google Safe Browsing, URLScan, AbuseIPDB, PhishDestroy, flux externes, PhishStats, réputation DNS, analyse SSL et heuristiques locales) avec des pondérations dynamiques. Score de 0 à 100 avec seuils ajustables.

📦 Verschleierte scripts et mineurs crypto

Detects eval/atob, document.write injections, and cryptocurrency miners (CoinHive, Crypto‑Loot) in real time. Part of the 36 tracker lists include NoCoin specifically targeting cryptomining scripts.

🎣 Skimmer & keylogger blocking

Identifies malicious web skimmers and keyloggers injected into checkout and login pages, intercepting card data before it is captured by attackers.

🔑 Credential leak detection

Warns you before credentials leave the page to a suspicious destination, catching credential‑harvesting forms and cross‑site exfiltration attempts.

⚙️ Web Worker monitoring

Monitors for suspicious Web Workers that run silently in the background, a common technique used by crypto miners and skimmers.

🤖 On‑Device Content Analysis

Runs local content analysis fully inside your browser with zero external API calls — page text and structure are scored locally for phishing patterns.

🔦 Search result safety ratings

Shows a safe / suspicious / dangerous badge directly on search engine results so you can avoid risky links before clicking.

📡 Threat Radar

A live radar view of threats detected and blocked across your browsing session, giving an at‑a‑glance picture of your active protection.

🗂️ Multi‑source intelligence

Aggregates cross‑checked signals from phishing databases, domain intelligence feeds and reputation APIs into one weighted verdict.

🤝 Community threat reporting

Report confirmed threats to help protect the wider AIScamHunter community while your report stays fully anonymised.

📴 Local‑only offline detection

Run protection in a fully offline, zero‑API mode — only local heuristics and cache are used, ideal for maximum privacy.

⛔ Protection contre les téléchargements dangereux

Bloque les fichiers exécutables (.exe, .bat, .scr, .apk, .js, .msi), analyse les téléchargements et offre la possibilité de supprimer les fichiers suspects.

🧾 Faux formulaires de connexion et fausses boutiques

Identifies cloned banking pages and fake stores via cross‑domain credential submissions, unrealistic discounts, and missing contact or legal notices.

📞 Arnaques au faux support technique et quishing

Bloque les écrans de verrouillage du navigateur, les fausses alertes Microsoft/Apple et les campagnes de phishing par QR code (quishing).

🖱️ Alertes au survol et menu contextuel

Survolez un lien : un avertissement s’affiche s’il est dangereux. Clic droit → analyser le lien, bloquer ou approuver le domaine instantanément.

🌍 Safe mode & Strict Private Mode

Increases detection sensitivity, forces HTTPS, blocks legacy plugins. Strict Private Mode forces DoH, blocks WebRTC leaks, auto‑cleans private tabs. Total Privacy Mode blocks third‑party cookies and disables Web Workers.

📋 Détection du détournement du presse-papiers

Periodic check (every 8s, only when tab is visible) detects replaced crypto addresses or unexpected clipboard changes. Respects browser permissions policy – no errors on restricted sites.

🗑️ Delete History

From the Private page (private.html), users can delete all scan history, stats, and activity events in one action. Resets counters, clears all stored events and daily aggregates. Confirmation dialog prevents accidental deletion.

🪤 Per‑domain tracker statistics

Every blocked tracker request logs the originating domain. The Activity tab's tracker filter shows a ranked table of top domains with live block counts — sorted by most blocked. Stats update every 2 minutes via Chrome's declarativeNetRequest feedback API.

Sources de notation pondérée : Google Safe Browsing 0.25, typosquatting analysis 0.16, URL intelligence 0.14, local heuristics 0.12, PhishDestroy 0.10, URLScan 0.09, VirusTotal 0.10, AbuseIPDB 0.08, threat swarm 0.06, favicon similarity 0.06, certificate transparency (crt.sh) 0.05, external feeds 0.10, DNSBL 0.04, PhishStats 0.04, DNS reputation 0.03, SSL analysis 0.03, domain age 0.02, Wayback archive age 0.02. Weights are relative scores (not percentages) applied per source when that signal is available; Strict and Safe modes add fixed score adjustments and move the blocking threshold.

04. Toutes les fonctionnalités en détail

📊 Score de risque dynamique

Chaque page reçoit un score de risque de 0 à 100 basé sur des données provenant de multiples sources. Les seuils peuvent être personnalisés (mode strict, mode sécurisé).

🚨 Page d’avertissement sécurisée

Lorsqu’une menace critique est détectée, une page d’interception détaillée affiche la catégorie, le niveau de gravité, les signaux détectés et les actions possibles (continuer une fois, approuver le domaine, signaler un faux positif).

🔔 Notifications intelligentes

Alertes instantanées lorsqu’un site malveillant est bloqué, qu’un crypto drainer est détecté ou qu’une redirection suspecte se produit. Désactivables.

🪤 Massive tracker blocker

Blocks trackers, ads, and analytics from 30,000+ domains using 36 filter lists (EasyPrivacy, NoCoin, AdGuard, Peter Lowe's, BlocklistProject, 1Hosts, Fanboy, EasyList Cookie, and 27 more). Uses Chrome's declarativeNetRequest for efficient, native blocking. Per‑domain statistics tracked in the Activity tab.

💳 Brand Impersonation Shield

Protects 80 legitimate financial domains (Stripe, PayPal, Apple Pay, Google Pay, Square, banks, crypto exchanges) so real checkouts never break, while look‑alike domains and cloned logins of 200+ major brands are scanned and blocked by the normal protection rules.

📊 Centre d’Outils avec scanner par lots

Complete toolkit: URL/domain scanner (batch up to 10), email risk checker, phone number validator, password vault, privacy cleaner, personal stats, persistent history of last 5 checks, sparklines and activity charts.

🔐 Générateur cryptographique de mots de passe

Utilise crypto.getRandomValues() pour générer des mots de passe robustes (8 à 64 caractères) avec majuscules, chiffres, symboles et indicateur de robustesse en temps réel.

🧹 Nettoyeur et destructeur de données privées

Suppression en un clic des traces de navigation avec sélection détaillée des types de données et plages temporelles prédéfinies. Nettoie également IndexedDB et WebSQL.

🗑️ Delete History

From the Private page, delete all scan history, stats, and activity events in one action. Resets all counters and clears stored data. Confirmation dialog prevents accidental deletion.

🌐 Local allow/block lists

Users can manually add domains to personal allowlist or blocklist. They override global rules and persist locally across browser sessions — no account or sync service required.

⚙️ Paramètres avancés

Enable/disable real‑time shield, safe mode, tracker blocking, download guard, notifications, strict mode, telemetry, strict private mode, total privacy mode. Reset statistics, clear activity log.

🌍 18 languages + RTL

Internationalisation complète incluant l’arabe (écriture de droite à gauche). Le thème clair/sombre se synchronise avec les préférences système.

🔗 Synchronisation administrateur et signalement des faux positifs

Les utilisateurs peuvent signaler les faux positifs depuis la page d’avertissement. Les administrateurs examinent les signalements et mettent à jour les listes globales de confiance ou de blocage. L’extension actualise ces listes toutes les heures.

🪤 Activity tab tracker filter

The Activity tab includes a dedicated tracker filter (🪤) that shows per‑domain block statistics — top 20 domains sorted by most blocked, with live counts from Chrome's declarativeNetRequest feedback API.

🧪 Vérification des arnaques par e-mail et téléphone

Vérifie les adresses e-mail jetables ou à faible réputation (API Disify) ainsi que les numéros de téléphone associés à des préfixes connus pour les arnaques. Disponible dans le Centre d’Outils.

05. Centre d’Outils – utilitaires avancés

Le Centre d’Outils (accessible depuis la fenêtre contextuelle ou la page dédiée private.html ) fournit de puissants outils de sécurité et des statistiques personnelles. Tout l’historique est stocké localement.

🌐 Analyseur d’URL / Domaines (par lots)

Check any URL or domain with multi‑source analysis (Google Safe Browsing, URLScan, PhishDestroy, local heuristics). Returns risk score, category, detected signals. Supports batch scanning of up to 10 URLs at once. Persistent history of last 5 checks with sparklines.

📧 Email risk checker

Detects disposable or low‑reputation email addresses via Disify API (HTTPS). Checks if email is valid, disposable, or has low reputation score. Batch mode available.

📞 Phone number validator

Verifies phone numbers against a curated list of known scam prefixes and flags likely scam numbers. Country selection included.

📊 Graphiques d’activité et mini-tendances

Visualises scans, blocked threats, and tracker blocks over 24h, 7 days, and 30 days. Sparkline graphs on stat cards show weekly trends. Dedicated tracker stat card shows total trackers blocked.

🔐 Coffre-fort de mots de passe (générateur sécurisé)

Génère des mots de passe cryptographiquement robustes (crypto.getRandomValues). Adjustable length (8‑64 chars), character sets, and a live strength meter (weak → very strong).

🧹 Nettoyeur et destructeur de données privées

Suppression en un clic des traces de navigation avec sélection détaillée des types de données et plages temporelles prédéfinies. Nettoie également IndexedDB et WebSQL.

🗑️ Delete History

From the Private page, permanently delete all scan history, stats, activity events, and daily aggregates. Resets all counters (pages scanned, threats blocked, warnings, downloads, trackers) to zero. Confirmation dialog prevents accidental deletion.

🪤 Per‑domain tracker stats

Click the tracker stat card in the Activity tab to see a ranked table of top 20 tracker domains by block count. Data comes from Chrome's declarativeNetRequest feedback API — shows real blocked requests, not estimates.

06. Sécurité Crypto & Web3

Protection spécialisée pour les utilisateurs de cryptomonnaies contre les drainers, les faux portefeuilles et les arnaques aux cadeaux promotionnels.

💸 Détection des crypto drainers

Surveille les appels Web3 dangereux : approve, transferFrom, personal_sign, eth_signTypedData, wallet_switchEthereumChain and more on pages that inject window.ethereum or window.solana.

🎁 Faux giveaways / airdrops frauduleux

Analyse le contenu textuel et les comptes à rebours afin de détecter les arnaques du type « Elon Musk Giveaway », « doublez vos cryptos » et les faux airdrops.

👛 Fausses pages de portefeuilles crypto

Identifie les sites de phishing usurpant l’identité de MetaMask, Binance, Coinbase, Ledger, Trust Wallet, Phantom, etc., grâce à la détection du typosquatting et des sous-domaines trompeurs.

📋 Détournement du presse-papiers (crypto)

Détecte lorsqu’une adresse crypto copiée (par exemple une adresse Ethereum commençant par 0x...) est discrètement remplacée par une adresse malveillante. Déclenche une alerte critique.

07. Administration & false‑positive handling

AIScamHunter includes a private admin dashboard that aggregates user reports, manages global allow/block lists, and improves detection for all users. The dashboard displays total installations, active users, threat activity, and per‑domain statistics.

📢 User false‑positive reporting

From the warning page or popup, users can report a blocked domain as a false positive. The report includes domain, timestamp, and anonymised user hash.

🔧 Admin actions

Trust → adds to global allowlist; Block → adds to global blocklist; Resolve → removes the report without global changes. Decisions sync to all users via shared JSON files.

🔄 Hourly synchronisation

The extension polls the server every hour for updated trusted/blocked lists. Admin changes propagate to all users within ≤60 minutes.

📊 Anonymous telemetry (optional)

Anonymous event statistics (event type, category, severity, hashed user id, country) plus the domain of flagged events are sent to improve detection for the whole community. No email, no name and no full browsing URLs are stored. Telemetry is enabled by default and can be disabled with one toggle in settings.

👥 User counting

Total installations are counted via the register telemetry event, which fires only once per genuine first install (stored in chrome.storage.local). Reinstalls after storage clear also register. The service worker restart on idle does not re-trigger registration — the _hasRegistered flag survives restarts.

🪤 Tracker statistics dashboard

The admin dashboard shows real‑time tracker block counts, per‑domain statistics from the dynamic rule matching, and threat activity trends. Updates hourly via telemetry data.

GDPR compliant: Telemetry stores only anonymised event statistics and the domain of flagged events — no email, name or full browsing URLs. You can disable telemetry or request data deletion at any time.

08. Privacy & data protection

Privacy‑first design: The majority of analysis is performed locally inside your browser, and all blocking rules run natively via Chrome's declarativeNetRequest so nothing is routed through external services. Optional telemetry (on by default) sends only anonymised event statistics and flagged‑domain data — disabling telemetry stops all outgoing analytics.

🔒 Local processing

Heuristics (typosquatting, DGA, form analysis, script scanning) run entirely on your device. Only optional safe browsing checks go through secured proxies.

💳 Brand Impersonation Shield

Applied locally in the detection engine — 80 legitimate financial domains (Stripe, PayPal, Apple Pay, Google Pay) are never misflagged, so payment data stays on your device and real checkouts are never interrupted. Clones of 200+ major brands are detected locally.

🕶️ Incognito mode support

Extension can be enabled in incognito (manual activation). Private‑browsing activity is kept in an isolated incognito profile and wiped automatically once all private windows close.

📊 Optional anonymised telemetry

A toggle in settings controls event statistics (event type, category, severity, hashed user id, country) and flagged‑domain data sent to improve global detection. No email, name or full URLs are stored. Registration fires once per genuine install.

🛡️ Proxied external APIs

Calls to Google Safe Browsing, URLScan, AbuseIPDB and VirusTotal are routed through AIScamHunter servers to hide your IP and avoid exposing API keys. SSRF protection on all server proxies.

🗑️ Delete History

Permanently delete all local scan history, stats, and activity events from the Private page. Confirmation dialog prevents accidental deletion. No server‑side data is affected.

09. Technical architecture

⚙️ Manifest V3 core

  • Service worker (background.js)
  • Declarative Net Request: 3 static rule sets (threats, trackers, safe mode) + dynamic rules for tracker blocking
  • Isolated storage, alarms, notifications
  • Session & local caching

🌐 Threat intelligence sources

  • Google Safe Browsing (via proxy)
  • URLhaus, OpenPhish, Phishing Army
  • PhishStats, PhishDestroy
  • URLScan, VirusTotal, AbuseIPDB (via proxy)
  • DNS reputation (Google DoH), DNSBL
  • Certificate transparency (crt.sh)
  • Local heuristics (typosquatting, DGA, homoglyphs)

📂 Internal rule sets

  • Malware & phishing (financial, crypto, gov, shipping)
  • Tracker blocking — 36 filter lists, 30,000+ domains (static + dynamic DNR rules)
  • Safe mode: HTTPS upgrade, block legacy plugins
  • Download guard: executable extensions
  • Brand impersonation: look‑alike domains and cloned logins for 200+ major brands; 80 legitimate financial domains protected from misflagging

📈 Weighted scoring engine

  • Relative weights: Google Safe Browsing 0.25, typosquatting 0.16, URL intelligence 0.14, local heuristics 0.12, PhishDestroy 0.10, URLScan 0.09, VirusTotal 0.10, AbuseIPDB 0.08, threat swarm 0.06, favicon similarity 0.06, certificate transparency (crt.sh) 0.05, external feeds 0.10, DNSBL 0.04, PhishStats 0.04, DNS reputation 0.03, SSL analysis 0.03, domain age 0.02, Wayback archive age 0.02.
  • Fixed score adjustments and threshold changes for strict/safe mode
  • Contextual reduction (no login/banking keywords)
  • Session cache (TTL 30 min)

🪤 Dynamic tracker rules

  • 36 filter lists parsed on every service worker restart
  • Domains converted to DNR dynamic rules in batches of 500
  • Max 30,000 domains, rule IDs 900000+
  • Per‑domain tracking via Chrome declarativeNetRequest matched‑rule statistics
  • Rule→domain mapping stored for live statistics

🏷️ Brand Impersonation Shield

  • Detects look‑alike domains and cloned login pages for 200+ major brands
  • 80 legitimate financial domains (Stripe, PayPal, Apple Pay, Google Pay, Square, Klarna, Adyen, banks, crypto exchanges) are never misflagged
  • Keeps legitimate checkouts working while threats are blocked

10. Permissions explained

PermissionReason
storageStores settings, allow/block lists, cache, stats, activity history, tracker domain counts, and user registration flag.
tabsRetrieves the active tab URL and hostname for scanning and status display.
alarmsManages scheduled tasks: telemetry queue, feed refresh, tracker count update (every 2 min), cache cleanup, keep‑alive pings.
downloadsAnalyses and blocks dangerous downloads; post‑download file scanning and deletion.
notificationsDisplays security alerts when threats are blocked.
cookiesPrivacy cleaner and detection of suspicious cookies.
browsingDataClears cache, history, downloads, form data, etc.
contextMenusAdds scan/block/trust options to right‑click menu.
webNavigationMonitors redirects and navigation events for real‑time analysis.
declarativeNetRequestEfficient network request filtering — static rule sets (threats, trackers, safe mode) + dynamic rules for 30,000+ tracker domains.
activeTabProvides access to the current tab for on‑demand scanning.
privacyEnforces Strict Private Mode (WebRTC/DoH) and Total Privacy Mode (3rd‑party cookies).

Note: Clipboard hijack detection uses the browser's asynchronous Clipboard API and respects each site's clipboard‑read permission — no extra manifest permission is requested. Per‑domain tracker statistics come from Chrome's declarativeNetRequest matched‑rule data when available.

11. Frequently asked questions

🔍 General
⚙️ Installation
🛡️ Protection
🪤 Tracker Blocking
🔒 Confidentialité
💰 Crypto
👥 Administration