Inspect a Suspicious File
Compare the extension against real magic bytes, compute hashes and look inside ZIPs.
What this tool can't tell you
This tool explains what a file is, it doesn't declare it "safe" or "dangerous". A clean result (extension matches, normal entropy, no macros) isn't a guarantee: malware keeps evolving and no local heuristic replaces an up-to-date antivirus. Use it to understand what you're looking at, not as a final verdict. Nothing about your file ever leaves the browser.
How do I check whether a file is really what it claims to be?
The suspicious file checker compares a file's extension against what it actually is inside, by reading its binary signature (magic bytes) — the same technique any operating system uses to recognize a format without trusting the filename. In seconds you'll see whether an "invoice.pdf" is really a PDF, a disguised executable, or something else entirely; compute its MD5, SHA-1 and SHA-256 hashes to verify it against a known-good value or look it up on VirusTotal by fingerprint; check its entropy to spot encrypted or packed content; and, if it's a ZIP (or an Office file, JAR, or APK, which are all ZIP under the hood), inspect the internal file listing for macros, paths that try to escape the destination folder, or an unusual compression ratio. Everything runs in your browser — the file is never uploaded anywhere. This tool explains what you're looking at; it doesn't replace antivirus software or claim to detect malware.
How to use Inspect a Suspicious File
- Drag the suspicious file into the box, or click to pick it from your device (up to 100 MB, any file type).
- Check the real-type-vs-extension verdict: the tool reads the file's first bytes and compares them against the filename to catch disguises, double extensions, or risky extensions.
- Copy any of the three hashes (MD5, SHA-1, SHA-256) with one click, or use the direct link to look up the SHA-256 on VirusTotal without uploading the file — it's a fingerprint lookup only.
- Check the entropy to see whether the content has recognizable patterns or looks encrypted/packed, and if the file is a ZIP, review its internal listing, macros, and possible zip-slip or zip-bomb signals.
- Download the .txt report as a record of the inspection — for example to attach to a support ticket or share with your security team.
Common use cases
An email attachment that doesn't feel right
You get a "quote.pdf" or "invoice.doc" from a sender you don't fully recognize. Before opening it, verify the extension matches the real type and the name isn't hiding a double, executable extension.
A file that's an odd size for what it claims to be
You were sent a "document.pdf" that's 40 MB when it should be a few hundred KB. Entropy and type detection help you understand whether something's packed or embedded that shouldn't be there.
Verify a download before you run it
You downloaded an installer from a source that isn't the official one. Compare its SHA-256 against the hash the developer published, or look it up on VirusTotal by fingerprint before double-clicking it.
Review a ZIP or Office file before opening it
A .xlsx or .docx that asked you to "enable content" to display properly is a classic macro signal. Check whether it contains vbaProject.bin and whether its internal paths are safe before deciding.
Confirm integrity after a transfer
You moved a large file between machines, over USB or over a network, and want to confirm it wasn't corrupted along the way by comparing its hash before and after.
Frequently asked questions
Does this tool detect viruses?
No. It explains what a file is — real type, whether it matches the extension, entropy, ZIP contents — so you can decide with more information. It isn't antivirus software and doesn't analyze behavior or check against known malware signatures; that's what the VirusTotal link is for, which queries dozens of antivirus engines' databases by fingerprint.
Does the file get uploaded anywhere, even to VirusTotal?
No. All the analysis (magic bytes, hashes, entropy, ZIP listing) happens in your browser using local JavaScript. The one external link is optional and manual: it takes you to VirusTotal's hash-search page, which queries its database with the SHA-256 already computed on your machine — your file never leaves your device unless you separately choose to upload it there yourself.
What does it mean when the extension doesn't match the real type?
It means the filename says one thing (say, .pdf) but the file's first bytes say another (say, the signature of a Windows executable). It could be a simple renaming mistake, or a deliberate attempt to disguise the file — the double-extension trick like "invoice.pdf.exe" is one of the most common attachment-phishing techniques, because Windows often hides the final extension.
Does high entropy mean the file is infected?
Not necessarily. High, uniform entropy is consistent with encryption or packing, but entirely legitimate compressed formats — ZIP, JPEG, MP4, PNG — also show high entropy, because compression removes patterns by design. It's a signal to look closer alongside the other results, not proof on its own.
What's a zip slip, and why does the tool warn me about it?
It's when a path inside a ZIP tries to escape the destination folder using "../" — for example, to overwrite a system file on extraction. A well-protected extractor blocks this, but not all of them do, so we flag it if it shows up in the file's internal listing.
Can I fully trust a "clean" result?
Not as an absolute guarantee. A result with no warnings (extension matches, normal entropy, no macros or suspicious paths) lowers the odds of an obvious surprise, but malware keeps evolving and no local heuristic replaces an up-to-date antivirus — or your own judgment about who sent you the file and why.