File Threat Analyzer

Heuristic safety check on a file — extension vs magic mismatch, double extensions, embedded scripts, size anomalies.

Analyzer Media & Files Updated Apr 19, 2026
How to Use
  1. Drop a file.
  2. Heuristic flags appear — this is a quick check, not antivirus.
  3. Upload the SHA-256 to VirusTotal if needed.
File
⚠️
Drop file to analyze
All local — no upload
Report
Waiting

Checks performed

Extension match
Magic vs .ext
Double extension
foo.pdf.exe
Embedded script
PDF /JS tag, macros
Shebang on non-script
#! in .png etc.
Very large text
Obfuscation hint
Executable
PE/ELF/Mach-O headers

About the File Threat Analyzer

File Threat Analyzer is a quick, free tool for image, audio and file tasks. It works in your browser and keeps everything on your device. Heuristic safety check on a file — extension vs magic mismatch, double extensions, embedded scripts, size anomalies.

How it works

Enter what you have and read the result as it updates live. It all runs on your own device, so it is quick and private, with nothing to install.

Want the deeper story? The Knowledge Base explains the ideas behind the tools in more detail.

Frequently Asked Questions

Is this AV?

No. It flags patterns commonly associated with malicious intent.

False positives?

Likely for edge cases — treat as hints, not verdicts.

How do I use the File Threat Analyzer?

Simply type your numbers and read the result, which refreshes the instant you change something. There is nothing to submit and nothing to wait for.

Does it cost anything or need an account?

No. The tool is completely free, there is no account to create, and it keeps working offline after the page first loads.

Is anything I type uploaded?

No. The tool works entirely on your device, so the values you enter never leave your browser.

Common Use Cases

Quick triage

Before opening unknown downloads.

Evidence

Document suspicious indicators.

Last updated: