Know what’s hiding
inside the document.
Upload an Office document, Windows installer, ZIP archive, JSON file, or JavaScript source. We’ll map static indicators into a report you can actually read.
Your uploads
Remembered in this browser only. These reports stay unlisted unless you publish them; one report is kept per file hash.
| File | Risk | Findings | Analyzed | Submissions |
|---|
Recent reports
| Detection | File | Confidence | Main finding | Comments |
|---|
No public reports yet. A signed-in report owner can list a report from its Community tab.
Findings
| Severity | Type | Keyword | What it means |
|---|
Document preview
Extracted modules
ThreatCheck · AMSI
Flagged-byte context
The excerpt shows up to 256 bytes immediately before ThreatCheck’s flagged-end offset. It is context, not proof that every displayed byte is malicious.
ZIP entries
| Entry | Size | Type | Static indicators | Status |
|---|
Why it was detected
What could cause this signature to trigger
Microsoft Defender scan
| Scanned item | Source | Size | SHA-256 | Defender |
|---|
Why it triggered
The risk comes from the content inside the installer, not the MSI wrapper. Each item below is a contained file or action with the reasons a scanner would be suspicious. This is a static explanation, not a Defender verdict.
Preliminary checks
Quick triage from oletools (oleid): file format, macros, external relationships and embedded objects. Nothing was opened or executed.
External references & URLs
| Type | Target | Found in |
|---|
Document parts
Packaged parts or OLE streams inside the document. Macro projects, embedded objects and ActiveX controls are highlighted.
| Part | Size | Kind |
|---|
Package identity & checks
Package signing and installed-file signing are separate checks. File-level signatures and SHA-256 hashes require extracting payload bytes; they are not inferred from the MSI database.
Packaged files
Names, sizes, and probable destinations come from MSI tables. Runtime properties and transforms can change the final paths.
| File | Size | Probable destination | File signature |
|---|
Registry changes
| Hive | Key | Name | Value |
|---|
Embedded streams & media
Binary-table streams are extracted and inspected with the contained files below (section 07); external media is listed only.
Contained-file inspection
| Archive entry | Size | Type | Static indicators | Status | Evidence |
|---|
Community
Sign in on WhyDetected and hand off an MSI to join the discussion.
Static analysis: