Skip to content

Threat Scanner

Check any link, file hash or IP address against leading threat-intelligence sources at once.

FreeMulti-sourceNo sign-up
Try:
Only the item you enter is sent to the threat-intelligence sources. Nothing is stored with your IP address.

How to use the Threat Scanner

  1. Paste the suspicious itemA link from an email or message, a file hash from a download page, or an IP address from a log.
  2. Click ScanThe type is detected automatically and every relevant source is queried in parallel.
  3. Read the verdictGreen means no source flags it, amber means a few engines disagree, red means do not open it.

What each scan checks

You enterSources checkedFinds
URLVirusTotal, Google Safe Browsing, URLhausPhishing pages, malware downloads, scam sites
File hashVirusTotal, MalwareBazaarKnown viruses, trojans, ransomware samples
IP addressVirusTotal, AbuseIPDBAttack sources, spam senders, botnet hosts

How the verdict works

Antivirus engines sometimes disagree.

A single engine flagging a famous website is usually a false positive. So the scanner only shows Threat detected when a major blocklist lists the item, or when several engines agree.

Everything in between is marked Suspicious, with the engine names listed so you can judge for yourself.

Already clicked a bad link?

  • Close the page and do not enter any passwords or card details.
  • If you typed a password, change it now from a different, clean device.
  • Run a full scan with your antivirus, or a bootable rescue disk if the PC behaves strangely.
  • Check suspicious emails with the Email Header Analyzer to see where they really came from.

Frequently asked questions

What can the Threat Scanner check?

Three things: website links (URLs), file hashes (MD5, SHA-1 or SHA-256) and IP addresses. Paste any of them into the box - the scanner detects the type automatically.

Which threat databases are used?

Links are checked against VirusTotal, Google Safe Browsing and URLhaus. File hashes are checked against VirusTotal and MalwareBazaar. IP addresses are checked against VirusTotal and AbuseIPDB.

Why does a well-known site show one or two detections?

Some antivirus engines produce false positives. ScanWith only marks an item as dangerous when a major blocklist flags it or several engines agree. One or two hits show as "suspicious" so you can look at the details yourself.

How do I scan a file without uploading it?

Use the Online Virus Scanner. It calculates the file's SHA-256 fingerprint in your browser and looks it up, so the file itself never leaves your device.

Is a clean result a guarantee that something is safe?

No. It means none of the sources currently knows the item as malicious. Brand-new phishing pages and malware can take hours to be reported, so stay careful with unexpected links and attachments.

Is there a limit on scans?

The free VirusTotal tier allows a limited number of lookups per minute across all visitors. If you see a rate-limit message, wait a minute and try again.