Drop the file here. Your browser inspects it locally — what it really is, whether it hides macros, scripts or programs — and sends only a fingerprint (SHA-256 hash) to check malware databases.
It is read by your browser. It is not uploaded, stored or sent anywhere.
The first bytes tell us if a "PDF" is really a Windows program, whether an Office document contains a macro project, and whether a PDF carries JavaScript or auto-run actions.
We compute the SHA-256 hash and ask abuse.ch MalwareBazaar (and VirusTotal, where enabled) whether that exact file is known malware.
No. Everything runs in your browser. The only thing sent is a 64-character hash that cannot be turned back into the file.
It is not known malware. New malware is produced faster than databases can catalogue it, so also weigh the other findings and whether you expected the file.
Programs and scripts (.exe, .js, .vbs, .lnk, .iso), macro-enabled Office files (.docm, .xlsm), HTML attachments that mimic login pages, and ZIPs containing any of these.
Built and maintained by the Arventiq Labs team in Bengaluru. Free for anyone, source on GitHub (MIT). Results are indications, not verdicts. Something wrong? Tell us.