LIVE_FEED
--:--:--[HIGH]shop-***-deals.comMagecart skimmer (Group 7)// US-EAST--:--:--[HIGH]wp-***-blog.netDrive-by iframe → exploit kit// EU-WEST--:--:--[MEDIUM]cdn-***-helper.ioObfuscated cryptominer (CoinIMP)// AP-SOUTH--:--:--[HIGH]auth-***-login.coCredential phishing kit (16shop)// EU-CENTRAL--:--:--[MEDIUM]media-***-files.orgMalicious redirect chain → ClickFix// US-WEST--:--:--[HIGH]support-***-desk.comFakeUpdates / SocGholish payload// US-EAST--:--:--[LOW]track-***-pixel.appUnauthorized 3rd-party tracker// EU-NORTH--:--:--[MEDIUM]img-***-host.ruDrive-by download (TLD reputation)// EU-EAST--:--:--[HIGH]api-***-stats.xyzC2 beacon (Cobalt Strike profile)// AP-EAST--:--:--[LOW]promo-***-coupon.shopAffiliate cloaking + cookie stuff// US-CENTRAL--:--:--[HIGH]shop-***-deals.comMagecart skimmer (Group 7)// US-EAST--:--:--[HIGH]wp-***-blog.netDrive-by iframe → exploit kit// EU-WEST--:--:--[MEDIUM]cdn-***-helper.ioObfuscated cryptominer (CoinIMP)// AP-SOUTH--:--:--[HIGH]auth-***-login.coCredential phishing kit (16shop)// EU-CENTRAL--:--:--[MEDIUM]media-***-files.orgMalicious redirect chain → ClickFix// US-WEST--:--:--[HIGH]support-***-desk.comFakeUpdates / SocGholish payload// US-EAST--:--:--[LOW]track-***-pixel.appUnauthorized 3rd-party tracker// EU-NORTH--:--:--[MEDIUM]img-***-host.ruDrive-by download (TLD reputation)// EU-EAST--:--:--[HIGH]api-***-stats.xyzC2 beacon (Cobalt Strike profile)// AP-EAST--:--:--[LOW]promo-***-coupon.shopAffiliate cloaking + cookie stuff// US-CENTRAL
← назад към блога
Engineering2026-06-048 мин. четене

Anatomy of a Scan: What the Engine Actually Does

A scan is not a curl request. We walk through every stage — from queueing a URL to producing a verified verdict — so you know exactly what powers your alerts.

Every scan begins as a job in a priority queue. Paid plans with short intervals get higher priority, but every job runs the same pipeline so results are comparable across tiers.

Stage one is acquisition: a real Chromium instance, not a header-only fetch, loads the page with JavaScript enabled. We hook service worker registration, fetch initiators, and dynamic import calls so nothing loaded at runtime escapes the record.

Stage two is analysis. We diff the observed script tree against your baseline, score new or mutated resources, and run behavioral heuristics that flag exfiltration patterns — POSTs to freshly registered domains, keystroke listeners on payment fields, or obfuscated payloads decoded at runtime.

Stage three is verification. Before anything reaches your inbox, suspicious findings are re-run in a clean session to rule out flakiness. Only a stable, reproduced result becomes a verdict — that is why our alerts are worth acting on.