← Blue Lantern Security

Is This File Safe? Scan a Suspicious File Before You Open It

Received an attachment or download you did not expect? Blue Lantern Security's Static Malware Analyzer inspects the file without running it: file-type verification, YARA signature matching, entropy analysis, packing detection, and suspicious-string extraction. You get each finding with its evidence, so you can decide before you double-click.

Scan a file with Blue Lantern Security

Web upload: any file type, up to 4.5 MB. Account required. The free tier includes 30 daily runs shared across the Static Malware Analyzer, Email Analyzer, and URL Threat Analyzer. No credit card required. Results are usually ready in about 30 seconds. See current pricing.

Static analysis looks at what a file contains, not what it does when executed. That makes it fast and safe to run on anything, and it also means a clean result is evidence rather than a guarantee. Treat the report as one input alongside where the file came from and why you received it.

What does the Static Malware Analyzer check?

Check What it looks for What it cannot establish alone
File type detection Whether the extension matches the file's real format (its magic bytes). A "PDF" that is actually an executable is a classic trick A matching type does not make the content safe
YARA rule matching Matches against Blue Lantern Security's curated rule set for known malware families and techniques Novel or heavily customized malware may not match any rule
Entropy analysis Regions of unusually high randomness that suggest encrypted or packed payloads embedded in the file Compressed media and archives are legitimately high-entropy
Portable executable sections Signs of packing or unusual section layouts in Windows executables Some legitimate software is packed to reduce size
Malicious string detection Strings commonly used by malware, such as suspicious API names, commands, or obfuscation patterns Noisier than YARA; a match is a lead, not a verdict
IOC extraction IP addresses, domains, URLs, and encoded strings found inside the file, for your own lookups Very noisy on large files; run it explicitly when you need the indicators

Choose the checks you want to run, or leave the selection empty to run the standard set (everything except IOC extraction). Each finding is reported as a pass or fail with its evidence, which reflects Blue Lantern Security's stance on risk scoring: show the work rather than a single opaque score.

How to check a suspicious file

  1. Do not open it. Leave the file closed, and do not accept "Enable editing" or "Enable macros" prompts while you investigate. If the file arrived by email, keep the message as well.
  2. Consider what the file contains. If it may hold confidential data, follow your organization's rules before uploading it anywhere. Blue Lantern Security deletes uploaded files within one day and keeps the report for one week.
  3. Upload it to the Static Malware Analyzer. Sign in, drag the file onto the upload area or click Select File, choose your checks, and submit. Files up to 4.5 MB are accepted through the web app.
  4. Read the findings. Open the completed report from the Monitoring Hub. A failed YARA or packing check deserves attention; so does a file-type mismatch on something that claimed to be a document.
  5. Verify the request independently. If the file came with a request to pay, sign in, or install something, confirm through a channel you already trust.

If the file arrived as an email attachment, check the email too. The Email Analyzer can optionally hand attachments to the Static Malware Analyzer as part of the same submission.

How should I interpret the result?

Result Practical next step
YARA match or packing detected Treat the file as hostile until proven otherwise. Do not open it, and report it to your IT or security contact if it is a work file
File-type mismatch only Ask why a "document" is really something else. Mismatches are common in phishing attachments and rare in legitimate mail
High entropy with no other findings Check whether the format is expected to be compressed (archives, images, video). If not, escalate
No findings The file did not match known patterns. Combine that with the sender and context before opening, and prefer a viewer that does not run macros or scripts
Failed or incomplete analysis Treat the result as unresolved, not clean. Retry, or ask your security team

Static analysis vs. sandbox detonation

Static analysis examines the bytes. A sandbox executes the file and watches what happens. They answer different questions and are often used together.

Method Question it helps answer Limitation
Static analysis (Blue Lantern Security) Does this file contain known-bad signatures, packing, or suspicious content? Cannot observe runtime behavior or decrypt payloads that only unpack in memory
Dynamic sandbox (for example ANY.RUN or Hybrid Analysis) What does the file do when executed: files dropped, processes spawned, network connections? Malware can detect sandboxes and stay quiet; execution takes longer and may require interaction
Multi-engine reputation (for example VirusTotal) What do many antivirus engines and prior submissions say about this hash? A new or targeted sample may have no history, and submissions may be shared with the community

For a more detailed comparison, see how Blue Lantern Security compares to VirusTotal. When the file is sensitive, check each service's sharing and retention terms before submitting it.

Can I automate file scanning?

Yes. Teams that want to scan files as part of a workflow, such as a SOAR playbook or a CI pipeline, can submit them through the REST API with a Seat License: send the file and the checks you want to run, keep the job ID, and fetch the completed result about 30 seconds later. The same engine and the same 4.5 MB limit apply. See automating static malware analysis through the API.

If a file may contain confidential data, check your organization's data-handling rules before submitting it to any service. Uploaded files are deleted within one day, as described below.

What happens to uploaded files?

Uploaded files are retained for no more than one day. Analysis reports are retained for one week and are accessible only to the user who generated them. Data is encrypted in transit and at rest. Review the Privacy Policy before submitting anything sensitive.

Common questions

Does Blue Lantern Security execute the file?

No. The Static Malware Analyzer never runs the file. It inspects the file's structure and contents. That is why it is safe to submit anything, and also why it cannot report runtime behavior.

What file types can I scan?

Any file type up to 4.5 MB through the web app: executables, scripts, Office documents, PDFs, archives, and more. The file-type check works from the file's real format, not its extension.

Does a clean result mean the file is safe?

No. It means the file did not match Blue Lantern Security's current rules and showed no packing or suspicious-content indicators. New malware, or a document whose danger lies in a link it asks you to click, can pass a static scan. Keep the sender and the request in mind.

Can I scan a password-protected archive?

The analyzer cannot look inside an encrypted archive. Attackers use password-protected ZIP files precisely because scanners cannot inspect them, so treat an unexpected encrypted archive with extra suspicion. Extract it only in an isolated environment.

Is it free?

Yes. The free tier includes 30 daily runs shared across the three analyzers. An account is required; no credit card is needed. API access and continuous monitoring require a Seat License at $15 per seat per month. Check current pricing.

What if I already opened the file?

Report it to your security contact if it was a work device. Run your endpoint protection, change any passwords you entered from a different device, and preserve the file for investigation rather than deleting it.

Open the Static Malware Analyzer

Related guides

Sources and further reading