Skip to scanner
FileScan

FileScan

Help

01

About FileScan

FileScan is a free online service that scans uploaded files for viruses and malware using the ClamAV antivirus engine.

02

How to use

1. Drag & drop a file, click to browse, or paste with ⌘/Ctrl + V. 2. Upload and scanning start automatically. 3. See the verdict — green for clean files, red when a threat is detected. 4. Use the SHA-256 hash to get a second opinion on VirusTotal.

03

Checking emails for phishing

Save an email as an .eml file and upload it to check it against known phishing emails and for spoofed links (where the URL shown differs from the real destination). [How to save as .eml] • Gmail: open the email, click "⋮" → "Download message" • Outlook (web / new Outlook): open the email, click "…" (More actions) → "Save as" or "Download" • Apple Mail (Mac): File → Save As → choose "Raw Message Source" as the format • Thunderbird: File → Save As → File Classic Outlook for Windows saves .msg files, and phone mail apps can't save .eml, so save the email from a web or desktop mail client instead. Spoofed links impersonating major brands (Amazon, Rakuten, major banks, card issuers, carriers, delivery companies and more) are detected, but text-only links like "Log in here" and QR-code tricks can't be detected.

04

About ClamAV

ClamAV is an open-source antivirus engine capable of detecting trojans, viruses, malware, and other threats. The virus definition database is updated regularly.

05

Privacy

Uploaded files are processed in memory only and discarded once the scan completes. File contents are never shared with third parties. The SHA-256 hash is calculated inside your browser.

06

Limitations

The maximum file upload size is 10MB. All file formats are supported, but 100% detection is not guaranteed. For critical files, we recommend verifying with multiple security tools.

Detection name

Txt.Backdoor.MetasploitPayload-9874938-0

Backdoor · Text / scripts

Risk
Critical
Verdict
Malware

Name breakdown

  1. TxtPlatform · Text / scripts
  2. BackdoorType · Backdoor
  3. MetasploitPayloadName · Metasploit
  4. 9874938Signature ID
  5. 0Revision

Overview

A signature that detects a Backdoor targeting Text / scripts.

Malware that opens a hidden "back door" so an attacker can control the computer remotely — used to steal data or deliver more malware.

About Metasploit

Metasploit is an open-source penetration testing framework developed by Rapid7. It's used in legitimate security assessments, but the payloads it generates (such as Meterpreter) are also used in real attacks. Unless you created the file yourself for testing, treat it as a backdoor that allows remote control.

What to do if it's detected

  1. 01Don't open or run the file — delete it.
  2. 02If you already opened or ran it, disconnect the device from the network and run a full scan with your security software.
  3. 03Change your passwords from a different, trusted device and check for suspicious logins.
  4. 04If it's a work device, report it to your IT department.

Could it be a false positive?

ClamAV false positives are uncommon but not impossible. If it's a file you need and the detection seems wrong, use the link on the result screen to check other engines on VirusTotal.

Check your own files

Drop a file into FileScan to scan it with ClamAV. No sign-up, and your file is never stored.

Scan a file →