qwzVirusDetect
THREAT INTELLIGENCE · BINARY FORENSICS

Suspicious Link &
URL Checker.

Inspect a public URL before you open it. Review tracking-domain indicators, redirects, HTTPS checks and evidence from available page content.

No file executionNo automatic file sharingEvidence with every finding
Start an inspection
Checking detection-engine availability…
01 / INSPECT

What would you like to check?

Files · Links · Trace · Images

Drop your file here

PE executables, scripts and ZIP archives · Up to 50 MiB

Selection starts an upload to this server. Unknown formats receive limited byte checks.

ZIP inspection has no file-count limit. Up to 32 MiB per entry and 64 MiB expanded in total; a 20-second inspection budget applies. Encrypted, oversized and nested entries are reported as uninspected.

No sample is executed. This scanner reviews submitted content and cannot replace antivirus protection on your device.

Understand what a suspicious link reveals.

The link checker reviews configured tracking-domain references, public destinations, HTTPS certificates and bounded HTML or text. Evidence is explained alongside any connection failures or missing coverage.

Does a tracking-domain match prove a link is malicious?

No. Tracking and monitoring services can have legitimate uses. A domain match is a reason to review the link, not proof that information was stolen.

Why can a URL check be incomplete?

A destination may refuse requests, fail certificate verification or return unsupported content. The report preserves completed checks and explains the stop. JavaScript and logged-in browsing are not performed.

EXPLORE THE TOOLS

File scanning, link checking and redirect tracing.

Know the limits

Know what the evidence means.

01 · Inspect

The scanner checks bounded file content with YARA, decoded strings and PE imports. ClamAV signature scanning is disabled. This is not device antivirus protection.

02 · Explain

YARA checks combinations linked to token collection, credential access, file uploads and remote commands. These are static indicators, not observed behavior.

03 · Report coverage

Show skipped entries, connection failures and unsupported formats. Incomplete checks never become a clean bill of health.

What happens to your data?

The web application buffers uploads in memory for bounded static checks. ClamAV is not enabled. No automatic sample submission, external hash lookup, Discord forwarding or visitor analytics is implemented.

URL inspection makes requests to the submitted destination and its redirects; those servers see the scanner’s connection. Reports stay in this page until you export them or close/reload it. No new scan history is saved in browser storage.

Hosting providers, reverse proxies and operating systems may have their own logs, buffering or swap. This application cannot guarantee secure memory erasure or control infrastructure retention.

Older versions may have saved a local scan history.