Scanner · live

Is this file malware?

Drop a file up to 64 MB — or 128 MB when you're signed in. Your browser hashes it locally, 70+ antivirus engines weigh in, and the MT AI Engine commits to a verdict in plain English — with the reasoning cited and the counterfactuals shown. The raw file is processed temporarily and is not retained; its hash and report are public and permanent.

Scan a file

Drop it here, or

Your browser will hash the file with SHA-256 before anything leaves the device. If we already know the hash, the verdict is instant — zero bytes uploaded.

SHA-256 locally·Raw file not retained·Max 64 MB
Raw file not retainedSHA-256 hashed locallyPublic permanent report70+ AV enginesAI verdictFree · no account required
How your result comes together

From your device to a clear answer.

If the hash is already known, the report opens without uploading the file again.

  1. SHA-256 in your browser
    WebCrypto
  2. Hash cache lookup
    Instant hits
  3. 70+ AV engines
    VirusTotal network
  4. MT AI Engine
    Weighs every signal
  5. Verdict with reasoning
    Shareable report
70+
antivirus engines
Microsoft, Kaspersky, ESET & more
< 2s
hash-hit verdict
zero bytes uploaded
128 MB
per file for members
64 MB as a guest — sign in to double it
0
files retained
hash and report retained after scanning
How it works

Multi-engine scan meets an AI that reasons.

Everyone else tells you how many engines flagged the file — a 3/70 ratio and a shrug. We run that same network, then hand every signal to the MT AI Engine. It commits to one verdict, cites the evidence, and lists the counterfactuals that could make it wrong. You read the reasoning, not a score.

A verdict you can understand

The analysis weighs engine detections, sandbox behaviour, code-signing history, and comparable files, then explains the conclusion with concrete evidence you can inspect.

70+ antivirus engines

Every upload is cross-checked against the same network enterprise SOC teams rely on — Bitdefender, Kaspersky, ESET, Microsoft, Sophos, and 60+ more. Their individual results remain visible in the report.

Key signals you can cite

Every verdict surfaces the 3–5 concrete factors that drove it: engine names, MITRE techniques, signer strings, exact counts. No opaque scores — you see the evidence the call rests on.

Honest about its doubts

Each verdict ships with a "What could make us wrong?" panel listing the counterfactuals — so you know the weak points before you act on the reading. Transparency no other scanner offers.

Temporary processing — no file retention

When a hash is unknown, the file is temporarily processed and submitted to VirusTotal for analysis. MalwareTips retains the SHA-256 hash and report, not the binary after processing completes.

Hash-first lookup

Your browser hashes the file with SHA-256 before anything leaves it. If we've already seen that hash — as we have for most common malware and popular software — the verdict is instant. Zero bytes move.

Privacy

We don't keep your file

When a hash is unknown, the file is temporarily processed and submitted to VirusTotal for analysis. MalwareTips does not retain the binary after processing completes. We keep the SHA-256 and the verdict report — so the next person who scans the same file gets an instant answer without another upload.

Frequently asked

Quick answers.

Is this really free?
Yes. Guests get 64 MB per file and 20 scans per hour from one IP. Signed-in MalwareTips members get 128 MB per file and 100 scans per hour. No paid tier, no card, no trial countdown.
Where does my file go?
Your browser calculates the SHA-256 first. If the hash is unknown, the file is temporarily processed by MalwareTips and submitted to VirusTotal for analysis. MalwareTips retains the hash and report, not the binary after processing completes.
Can I scan without uploading?
If the file's SHA-256 is already in our network (as it is for most common malware and popular software), the verdict is instant. Your browser hashes the file locally, we check the hash, and you see the result in under two seconds — zero bytes transferred.
What file types are supported?
Anything that fits the size cap — 64 MB as a guest, 128 MB signed in. Windows executables (EXE, DLL, MSI), installers, Office documents, PDFs, archives (ZIP, RAR, 7z), Android APKs, scripts, shell binaries. If an antivirus can parse it, so can we.
Why an AI verdict? What does it add over antivirus scores?
Antivirus engines return cryptic labels like "Trojan.GenericKD.62714924" or "ML.Attribute.HighConfidence" — and they disagree with each other all the time. The MT AI Engine reads every engine's call alongside sandbox behaviour, signer history, and past MalwareTips verdicts on similar files, then commits to one answer: "RustDesk 1.4 — legitimate signed utility, the three detections are known AI-heuristic false positives", or "confirmed Lumma stealer, delete now." You see the 3-5 key signals it cited and the counterfactuals that could make it wrong.
Can I trust a single AI call?
That's the right question to ask. Every verdict includes the relevant engines, signer history, observed behaviour, uncertainty, and a Report-this-verdict button for staff review. The evidence remains visible so you can judge the conclusion instead of trusting a label blindly.
Have a suspicious download?

Scan it before you open it.

Free, anonymous, no account required — 64 MB per file, 20 scans per hour. Sign in for 128 MB and 100 scans per hour. Either way, the MT AI Engine reads the evidence and tells you what to do.

Scan a file