Online file & malware scanner
Review malware indicators in EXE files, Python scripts and ZIP archives, with explanations and inspection coverage.
Inspect a public URL before you open it. Review tracking-domain indicators, redirects, HTTPS checks and evidence from available page content.
PE executables, scripts and ZIP archives · Up to 50 MiB
Selection starts an upload to this server. Unknown formats receive limited byte checks.
ZIP inspection has no file-count limit. Up to 32 MiB per entry and 64 MiB expanded in total; a 20-second inspection budget applies. Encrypted, oversized and nested entries are reported as uninspected.
Check image metadata and appended data · PNG or JPEG
Up to 50 MiB and 8 megapixels. Selection starts an upload.
GPS metadata is a privacy finding, not a malware verdict. Pixel-level hidden messages and image exploits are outside this check.
No sample is executed. This scanner reviews submitted content and cannot replace antivirus protection on your device.
Uploading and waiting for the server…
This is the path observed by this server, not a guarantee of your browser's destination. JavaScript, cookies, location and the destination's rules can change the route. URLs are shown as text to prevent accidental navigation.
Inspected contents and structure. A component is not necessarily malicious.
The link checker reviews configured tracking-domain references, public destinations, HTTPS certificates and bounded HTML or text. Evidence is explained alongside any connection failures or missing coverage.
No. Tracking and monitoring services can have legitimate uses. A domain match is a reason to review the link, not proof that information was stolen.
A destination may refuse requests, fail certificate verification or return unsupported content. The report preserves completed checks and explains the stop. JavaScript and logged-in browsing are not performed.
Review malware indicators in EXE files, Python scripts and ZIP archives, with explanations and inspection coverage.
Inspect public links for tracking-domain indicators, HTTPS issues and available page evidence.
See where a shortened link leads. Review the ordered URL path, connection details and stop reasons.
The scanner checks bounded file content with YARA, decoded strings and PE imports. ClamAV signature scanning is disabled. This is not device antivirus protection.
YARA checks combinations linked to token collection, credential access, file uploads and remote commands. These are static indicators, not observed behavior.
Show skipped entries, connection failures and unsupported formats. Incomplete checks never become a clean bill of health.
The web application buffers uploads in memory for bounded static checks. ClamAV is not enabled. No automatic sample submission, external hash lookup, Discord forwarding or visitor analytics is implemented.
URL inspection makes requests to the submitted destination and its redirects; those servers see the scanner’s connection. Reports stay in this page until you export them or close/reload it. No new scan history is saved in browser storage.
Hosting providers, reverse proxies and operating systems may have their own logs, buffering or swap. This application cannot guarantee secure memory erasure or control infrastructure retention.
Older versions may have saved a local scan history.