qwzVirusDetect
THREAT INTELLIGENCE · BINARY FORENSICS

Online File &
Malware Scanner.

Check suspicious files for malware indicators before you open them. Review static evidence of credential access, file transfers and remote-control capabilities.

No file executionNo automatic file sharingEvidence with every finding
Start an inspection
Checking detection-engine availability…
01 / INSPECT

What would you like to check?

Files · Links · Trace · Images

Drop your file here

PE executables, scripts and ZIP archives · Up to 50 MiB

Selection starts an upload to this server. Unknown formats receive limited byte checks.

ZIP inspection has no file-count limit. Up to 32 MiB per entry and 64 MiB expanded in total; a 20-second inspection budget applies. Encrypted, oversized and nested entries are reported as uninspected.

No sample is executed. This scanner reviews submitted content and cannot replace antivirus protection on your device.

Check suspicious files with evidence you can review.

Upload an EXE, Python script or ZIP archive to inspect bounded content, YARA matches, decoded strings and supported binary structure. Reports explain the matched evidence and which checks were completed.

Can I scan a ZIP archive?

Yes. ZIP entries are inspected within the stated time and size budgets. Encrypted, nested and oversized entries are listed as uninspected, with reasons.

Does a result prove a file is safe?

No. Static markers can be missing or ambiguous. The scanner does not execute files, and cannot guarantee detection of encrypted or unknown malware. Keep antivirus protection enabled on your device.

EXPLORE THE TOOLS

File scanning, link checking and redirect tracing.

Know the limits

Know what the evidence means.

01 · Inspect

The scanner checks bounded file content with YARA, decoded strings and PE imports. ClamAV signature scanning is disabled. This is not device antivirus protection.

02 · Explain

YARA checks combinations linked to token collection, credential access, file uploads and remote commands. These are static indicators, not observed behavior.

03 · Report coverage

Show skipped entries, connection failures and unsupported formats. Incomplete checks never become a clean bill of health.

What happens to your data?

The web application buffers uploads in memory for bounded static checks. ClamAV is not enabled. No automatic sample submission, external hash lookup, Discord forwarding or visitor analytics is implemented.

URL inspection makes requests to the submitted destination and its redirects; those servers see the scanner’s connection. Reports stay in this page until you export them or close/reload it. No new scan history is saved in browser storage.

Hosting providers, reverse proxies and operating systems may have their own logs, buffering or swap. This application cannot guarantee secure memory erasure or control infrastructure retention.

Older versions may have saved a local scan history.