Threat console

APK or suspicious file
Investigate in seconds.

Investigate installers, APK files, documents or attachments before opening them. Detect malware, spyware and trojanized apps.

01Input
02Results

What would you like to analyze?

AI-powered

Or pick a surface
Web & Links
Messages & Chats
Files & Apps
Identity & Payments

Investigate an installer, document or attachment before opening it.

Zero retention
Submissions are never stored.
Encrypted
TLS-secured in transit.
Live verdicts
20 free analyses / day

Step 02 · Results

Awaiting input

Analysis verdict

Run an analysis to surface the live verdict and evidence here.

Ready when you are.

Drop in a URL, message, or file above to populate your analysis verdict here.

  • Risk score with confidence band
  • Key signals and evidence summary
  • Recommended next steps to stay safe

ThreatSnaps analyses are AI-assisted guidance, not legal or financial advice. Always verify through official channels.

About this checker

Sideloaded Android APKs and unexpected attachments are how a large share of mobile and consumer malware lands. Upload the file and ThreatSnaps inspects the manifest, permissions, signatures and content statically - nothing is executed - and tells you whether the file matches malware, spyware or trojanized-app patterns.

Red flags to watch for

  • APK asks for accessibility, SMS, notification or device-admin permissions for a feature that does not need them.
  • Installer is signed by a developer name that does not match the brand it claims to be.
  • Document is a macro-enabled Office file or a password-protected archive received from an unfamiliar sender.

What to do if you were targeted

  • Do not install or open the file until you have verified its origin.
  • Install Android apps from the Play Store, App Store or the brand's official site - never from random links.
  • If you already installed a suspicious APK, revoke accessibility and device-admin permissions and run a mobile security scan.

Frequently asked questions

Are files executed during analysis?

No. The analyzer reads metadata, permissions and content statically. Nothing is run.

What file types are supported?

APK, common document formats (PDF, DOCX, XLSX), archives (ZIP) and installers up to a few megabytes.

Do you support iOS IPA files?

iOS sideloading is much less common; IPA analysis is on the roadmap.

Related checkers