Online file & malware scanner
Review malware indicators in EXE files, Python scripts and ZIP archives, with explanations and inspection coverage.
Check suspicious files for malware indicators before you open them. Review static evidence of credential access, file transfers and remote-control capabilities.
PE executables, scripts and ZIP archives · Up to 50 MiB
Selection starts an upload to this server. Unknown formats receive limited byte checks.
ZIP inspection has no file-count limit. Up to 32 MiB per entry and 64 MiB expanded in total; a 20-second inspection budget applies. Encrypted, oversized and nested entries are reported as uninspected.
Check image metadata and appended data · PNG or JPEG
Up to 50 MiB and 8 megapixels. Selection starts an upload.
GPS metadata is a privacy finding, not a malware verdict. Pixel-level hidden messages and image exploits are outside this check.
No sample is executed. This scanner reviews submitted content and cannot replace antivirus protection on your device.
Uploading and waiting for the server…
This is the path observed by this server, not a guarantee of your browser's destination. JavaScript, cookies, location and the destination's rules can change the route. URLs are shown as text to prevent accidental navigation.
Inspected contents and structure. A component is not necessarily malicious.
Upload an EXE, Python script or ZIP archive to inspect bounded content, YARA matches, decoded strings and supported binary structure. Reports explain the matched evidence and which checks were completed.
Yes. ZIP entries are inspected within the stated time and size budgets. Encrypted, nested and oversized entries are listed as uninspected, with reasons.
No. Static markers can be missing or ambiguous. The scanner does not execute files, and cannot guarantee detection of encrypted or unknown malware. Keep antivirus protection enabled on your device.
Review malware indicators in EXE files, Python scripts and ZIP archives, with explanations and inspection coverage.
Inspect public links for tracking-domain indicators, HTTPS issues and available page evidence.
See where a shortened link leads. Review the ordered URL path, connection details and stop reasons.
The scanner checks bounded file content with YARA, decoded strings and PE imports. ClamAV signature scanning is disabled. This is not device antivirus protection.
YARA checks combinations linked to token collection, credential access, file uploads and remote commands. These are static indicators, not observed behavior.
Show skipped entries, connection failures and unsupported formats. Incomplete checks never become a clean bill of health.
The web application buffers uploads in memory for bounded static checks. ClamAV is not enabled. No automatic sample submission, external hash lookup, Discord forwarding or visitor analytics is implemented.
URL inspection makes requests to the submitted destination and its redirects; those servers see the scanner’s connection. Reports stay in this page until you export them or close/reload it. No new scan history is saved in browser storage.
Hosting providers, reverse proxies and operating systems may have their own logs, buffering or swap. This application cannot guarantee secure memory erasure or control infrastructure retention.
Older versions may have saved a local scan history.