Is this file malware?
Drop a file up to 64 MB — or 128 MB when you're signed in. Your browser hashes it locally, 70+ antivirus engines weigh in, and the MT AI Engine commits to a verdict in plain English — with the reasoning cited and the counterfactuals shown. The raw file is processed temporarily and is not retained; its hash and report are public and permanent.
Drop it here, or
Your browser will hash the file with SHA-256 before anything leaves the device. If we already know the hash, the verdict is instant — zero bytes uploaded.
From your device to a clear answer.
If the hash is already known, the report opens without uploading the file again.
- SHA-256 in your browserWebCrypto
- Hash cache lookupInstant hits
- 70+ AV enginesVirusTotal network
- MT AI EngineWeighs every signal
- Verdict with reasoningShareable report
What people just scanned.
- Safe41m agocapture.exe2f368c24a735631b9c…0/75flagged
- Suspicious1h agoRoblox Account Manager.exebe9ddcdedf8c36c64e…30/75flagged
- Unknown3h ago1788601135574-726311465-ClearLustrousAtlanticridleyturtle.mp4233ac7b2ca8e635ea4…0/75flagged
- Malicious4h ago198macros.exea515d5965eaa6d7788…36/75flagged
- Safe5h agoninja_saga.exe59a5c6b81b9d0de8bb…2/75flagged
- Suspicious12h agosetup.exea76a101852e3b35cf6…0/76flagged
- Unknown13h agoBETAVENOPAY (1).rare0cf638f7f1d4d05b7…0/75flagged
- Safe14h agoinfectonator.zipb99b195cfced59e822…0/75flagged
Multi-engine scan meets an AI that reasons.
Everyone else tells you how many engines flagged the file — a 3/70 ratio and a shrug. We run that same network, then hand every signal to the MT AI Engine. It commits to one verdict, cites the evidence, and lists the counterfactuals that could make it wrong. You read the reasoning, not a score.
A verdict you can understand
The analysis weighs engine detections, sandbox behaviour, code-signing history, and comparable files, then explains the conclusion with concrete evidence you can inspect.
70+ antivirus engines
Every upload is cross-checked against the same network enterprise SOC teams rely on — Bitdefender, Kaspersky, ESET, Microsoft, Sophos, and 60+ more. Their individual results remain visible in the report.
Key signals you can cite
Every verdict surfaces the 3–5 concrete factors that drove it: engine names, MITRE techniques, signer strings, exact counts. No opaque scores — you see the evidence the call rests on.
Honest about its doubts
Each verdict ships with a "What could make us wrong?" panel listing the counterfactuals — so you know the weak points before you act on the reading. Transparency no other scanner offers.
Temporary processing — no file retention
When a hash is unknown, the file is temporarily processed and submitted to VirusTotal for analysis. MalwareTips retains the SHA-256 hash and report, not the binary after processing completes.
Hash-first lookup
Your browser hashes the file with SHA-256 before anything leaves it. If we've already seen that hash — as we have for most common malware and popular software — the verdict is instant. Zero bytes move.
We don't keep your file
When a hash is unknown, the file is temporarily processed and submitted to VirusTotal for analysis. MalwareTips does not retain the binary after processing completes. We keep the SHA-256 and the verdict report — so the next person who scans the same file gets an instant answer without another upload.
Quick answers.
Is this really free?
Where does my file go?
Can I scan without uploading?
What file types are supported?
Why an AI verdict? What does it add over antivirus scores?
Can I trust a single AI call?
Scan it before you open it.
Free, anonymous, no account required — 64 MB per file, 20 scans per hour. Sign in for 128 MB and 100 scans per hour. Either way, the MT AI Engine reads the evidence and tells you what to do.
Scan a file