About malbox
Inspect suspicious files safely. Nothing is ever run.
malbox helps you look inside suspicious files without opening or running them. Upload a file, paste base64 data, or provide a URL. The result is one report with file details, extracted strings, PE information, YARA matches, and checks for PDFs, Office macros, scripts, shellcode, and Windows shortcut files.
Every submission is inspected statically. The file is examined, not executed.
How it works
Submit
Upload a file, paste it as base64, or point at a URL.
Pick what runs
Choose from the tools suggested for the file type.
Analyse
Tools run in an isolated container with no network access.
Read the report
Review the findings in one tabbed report.
What it runs generated from the tools this platform actually runs
General Infos
Strings Extractions
PE Generic
PE FLARE
YARA
Shellcode
Scripts
Office / Macros
LNK / Shortcut
Handled with care
- Analysis runs in a temporary container with no network access, a read only filesystem, and no elevated privileges.
- Submitted files are never executed. Every result comes from static inspection.
- Samples are stored by their content hash, so the same file is never kept twice.
- Reports and logs age out on a retention schedule rather than being kept indefinitely.
malbox is a static analysis tool. It does not observe a file while it runs. The report provides indicators, not a final verdict. Review the full result before making a call.