Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

File Safety Inspector

See what a file really is and whether it can run code — before you open it.

Security No upload Works offline Free, no sign-up

File to inspect

Or try an example (made in your browser, with no working code in it):

The file is read on this device, in a background worker, and never uploaded, opened, rendered or run.

Next steps

About the File Safety Inspector

Before you open an attachment or a download, see what it really is. The inspector reads the file’s first bytes to name its true type — whatever its name claims — and then looks at the parts of each format that let a file act on its own: Office macros that run when a document opens, PDF JavaScript and launch actions, programs hidden in ZIP archives or behind a double extension, Windows shortcuts that start the command prompt, password-protected archives that scanners cannot open, fake sign-in pages saved as HTML. Each finding says in plain words what the trick is and what to do about it.

The file is read in your browser and never uploaded, opened or run. This is not antivirus: it has no list of known malware. It shows how a file could hurt you — which is often enough to decide not to open it.

How to use it

  1. Choose the file or drag it onto the page — any type, up to 300 MB. You can also paste a file you copied.
  2. Read the verdict and the findings: Danger marks a trick malware relies on, Caution a file that can run code or hides its contents, Note background information.
  3. Check What the file really is: the type found in the file’s bytes, and details such as a shortcut’s target, a PDF’s pages or an archive’s file count.
  4. For Office files, read the macro code under Macros (shown as text, never run). Links inside PDFs and documents are listed defanged, each checked for look-alike domains.
  5. Copy the report or download it as JSON for your IT team — every web address in them is defanged (hxxps://example[.]com), so nobody clicks one by mistake. If you choose, look up the file’s SHA-256 fingerprint on VirusTotal.

Examples

An “invoice” that is a program
Input
Invoice_0042.pdf.exe
Result
Danger signs found — A .exe file pretending to be a .pdf; A Windows program

Windows hides known file endings by default, so this file shows up as “Invoice_0042.pdf”.

A Word file that asks you to “Enable content”
Input
Quarterly report.docm, with a Document_Open macro
Result
Danger signs found — Macros that run on their own (1 module with code)

The macro’s source code is listed with what each call does, such as Shell (starts a program) or URLDownloadToFile (downloads a file).

An ordinary spreadsheet
Input
expenses.csv
Result
No red flags found

Common uses

  • Checking an e-mail or WhatsApp attachment you did not expect before opening it.
  • Finding out whether a “document” in a ZIP file is really a program, or whether an archive is password-protected so that no scanner can look inside.
  • Looking for macros, remote templates or DDE commands in an Office file before choosing “Enable content”.
  • Checking an APK sent in a chat — fake bank, KYC or traffic-challan apps — before installing it.
  • First-pass triage for an IT team: true type, fingerprints and a report to attach to a ticket.

What it checks

  • True type: the file’s signature bytes (with the Hex Viewer’s table of formats) against its name; double extensions, hidden right-to-left characters and names padded with spaces.
  • Office documents: VBA macros in .docm, .xlsm and .pptm files and in 97–2003 .doc, .xls and .ppt files, read and decompressed as Microsoft’s MS-OVBA specification describes; procedures that run by themselves (AutoOpen, Document_Open, Workbook_Open); calls such as Shell, CreateObject and URLDownloadToFile; Excel 4.0 macro sheets and very hidden sheets; templates and objects loaded from the internet; DDE commands; ActiveX controls; packaged programs; Equation Editor objects; password-protected documents. LibreOffice macros and RTF objects too.
  • PDF: the keywords that Didier Stevens’ pdfid counts — /JS, /JavaScript, /OpenAction, /AA, /Launch, /EmbeddedFile, /XFA and others — including names disguised with #xx escapes and names inside compressed object streams; attached files, links, and data after the end of the file.
  • Archives: the contents of ZIP, RAR, 7z, TAR and gzip files (read with the ZIP & RAR Extractor’s code): encrypted entries, programs, programs under harmless names, paths that escape the folder, compression bombs, archives inside archives.
  • Programs and shortcuts: Windows programs (architecture, signature block, packers), Android apps, Java, macOS and Linux programs, Windows shortcuts (target, arguments, a minimised window), disk images such as .iso and .vhd.
  • Web pages, scripts and small Windows files: HTML and SVG files with scripts, password forms that send to another site, HTML smuggling; PowerShell, batch and JavaScript files that download or decode code; .url, .scf, .reg, .iqy and .slk files; e-mails (.eml) and Outlook messages with their attachments; OneNote files with embedded programs.

Why these tricks matter

Office for Windows now blocks macros in files that came from the internet (Microsoft’s explanation), so attackers lean on other routes — the ones this inspector looks for:

  • Containers: files inside an .iso or .vhd disk image, or inside archives unpacked with some tools, do not inherit the “downloaded from the internet” mark that switches those protections on (MITRE ATT&CK T1553.005).
  • Names that lie: a double extension or the right-to-left override character makes a program look like a document.
  • Shortcuts and scripts: a .lnk file with a document icon that starts PowerShell or the command prompt.
  • HTML smuggling (T1027.006): a web page that assembles the harmful file inside your browser, after the e-mail filter has let the page through.
  • Template injection (T1221): a harmless-looking document that fetches a template with macros when it opens.
  • Password-protected archives, with the password in the same message, because no scanner can look inside them.

What the verdict means

  • Danger signs found: at least one trick that malware relies on and ordinary files rarely need — a program disguised as a document, macros that run by themselves, JavaScript that runs when a PDF opens, a template fetched from the internet. Do not open the file unless you are sure where it came from.
  • Be careful: the file can run code or hides what it contains — a program, a script, macros, an encrypted archive — but uses none of the typical tricks. Open it only if you expected it from someone you know.
  • No red flags found: no way was found for the file to run code or fetch something by itself. That is not a guarantee: a file can exploit a bug in the program that opens it, and this tool knows tricks, not malware.

Limitations

  • It is not antivirus and has no malware signatures: a harmful file that uses none of these tricks — such as one that exploits a bug in a PDF reader or image viewer — can look clean.
  • Encrypted content cannot be checked: password-protected archives and documents and encrypted PDFs show only what is visible from outside.
  • Macros are judged by their source code. Documents whose source was removed while the compiled code was kept (“VBA stomping”) can hide what a macro really does; they are flagged only when the source cannot be read.
  • Pictures are not read, so a QR code inside a PDF or document is not checked — take a screenshot and use the QR Code Safety Scanner.
  • Archives are listed and the first bytes of each file are identified, but the files inside are not inspected in full (and solid 7z and RAR archives are only listed): extract the interesting ones and check them separately.
  • Files up to 300 MB, because the whole file is read into memory.

Privacy

Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.

Frequently asked questions

Is my file uploaded?

No. Your browser reads it in a background worker, and the page sends nothing anywhere. Only if you click Look up the SHA-256 on VirusTotal does your browser open virustotal.com — with the file’s fingerprint, not the file.

Can the file harm my computer while it is checked here?

The inspector treats the file as data: it never opens, renders or runs it, and macro code and PDF JavaScript are shown as plain text. The risk comes later, if you open the file in the program it is meant for.

The result says “No red flags found”. Is the file safe?

It means none of the checks found a way for the file to act on its own. It can still be harmful: an exploit for a bug in a viewer needs none of these tricks, and any program can do anything once you run it. Trust the sender, not just the result.

Why is every program flagged?

A program can do anything a program can, and there is no way to tell a good one from a bad one by looking at its first bytes. The inspector shows what can be read — type, architecture, whether there is a signature block (not whether the signature is valid) and signs of packing. Install software only from its official website or app store.

What should I do with a dangerous attachment?

Do not open or forward it. If it seems to come from someone you know, ask them through another channel — a call or a new message — whether they sent it: accounts get hacked. At work, report it to your IT or security team with the JSON report. If you already opened it and shared bank or UPI details, call your bank at once; in India, report financial cyber fraud on the helpline 1930 or at cybercrime.gov.in.

How is this different from VirusTotal?

VirusTotal checks files you upload with many antivirus engines, and the contents of uploaded files may be shared with its premium customers — not a place for confidential documents. This inspector keeps the file on your device and explains its tricks instead of naming malware. The two work together: check the file here, then look up its fingerprint there.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.