Many well-known and widely used websites use a phishing script, which scans your local computer for remote access programs.

We informed you a few days ago that eBay.com scans visitors' computers when they browse the website.
This port scan was conducted by LexisNexis' ThreatMetrix fraud protection script used to identify potentially compromised computers making fraudulent purchases.
When running, a feature of this product uses WebSockets to scan 14 different TCP ports on the visitor's computer.

All of these ports are intended for remote access that are commonly used for legitimate purposes, but have also been known to be used for malicious purposes. These ports, their identifiers, and associated applications are listed below.

While every e-commerce website should use methods to detect fraud, many found it too annoying to port scan a visitor's computer for programs without permission.
Many well-known websites use the same script
While none are as big as eBay (in terms of visitors), many of the websites that use ThreatMetrix's anti- fraud scripts are well-known brands
Of the websites tested, we saw scanning on Citibank, TD Bank, Ameriprise, Chick-fil-A, Lendup, BeachBody, Equifax IQ connect, TIAA-CREF, Sky, GumTree, and WePay.
When using the port scanning script, it was done differently depending on the website.
For example, Citibank, Ameriprise, and TIAA-CREF ports immediately scanned computers when the website.
TD Bank, Chick-fil-A, Lendup, Equifax IQ connect, Sky, GumTree, and WePay scan visitors trying to log in.
For BeachBody.com, port scans are only performed at check out.
Other well-known companies use the script as well. This list includes Netflix, Target, Walmart, ESPN, Lloyd Bank, HSN, Telecharge, Ticketmaster, TripAdvisor, PaySafeCard, and possibly even Microsoft.
How to block ThreatMetrix port scanning
If you find these port scans annoying and a privacy risk, you can use the uBlock Origin adblocker in Firefox to block them.
In tests, uBlock is unable to block port scanning in the new Microsoft Edge or Google Chrome, as the extension does not have sufficient permissions to unlink DNS CNAME records.
