Know what’s hiding
inside the document.
Upload an Office document, Windows installer, ZIP archive, JSON file, or JavaScript source. We’ll map static indicators into a report you can actually read.
Findings
| Severity | Type | Keyword | What it means |
|---|
Extracted modules
ThreatCheck · AMSI
Flagged-byte context
The excerpt shows up to 256 bytes immediately before ThreatCheck’s flagged-end offset. It is context, not proof that every displayed byte is malicious.
ZIP entries
| Entry | Size | Type | Static indicators | Status |
|---|
Package identity & checks
Package signing and installed-file signing are separate checks. File-level signatures and SHA-256 hashes require extracting payload bytes; they are not inferred from the MSI database.
Packaged files
Names, sizes, and probable destinations come from MSI tables. Runtime properties and transforms can change the final paths.
| File | Size | Probable destination | File signature |
|---|
Registry changes
| Hive | Key | Name | Value |
|---|
Embedded streams & media
Binary-table entries are inventoried, not extracted or code-scanned in this version.
Contained-file inspection
| Archive entry | Size | Type | Static indicators | Status |
|---|
Community
Sign in on WhyDetected and hand off an MSI to join the discussion.
Static analysis: