Find out what a file really is.
Compare the filename with binary signatures, inspect archive contents, read executable headers and review technical warning signs without uploading or running the file.
Before you inspect
This is a structure inspector, not an antivirus.
The selected file stays in this browser tab. Pagan Earth does not upload it, execute it or submit it to a reputation service. A normal-looking structure does not prove that a file is safe, while a warning is a technical clue—not a malware verdict.
Attention report
What deserves a closer look
Warnings describe structure and naming. They do not determine intent.
Identity
Filename versus content
Structure
Technical properties
Archive explorer
Declared package contents
No files are extracted or opened automatically.
Hex preview
First 512 bytes
Offset · hexadecimal · ASCII
Text preview
Readable opening
Up to the first 32 KB
Keep the result
Export an inspection report
The report contains technical findings and filenames, so review it before sharing.
Know the limits
What the inspector can—and cannot—tell you.
Can this prove a file is safe?
No. The tool never executes code and does not use malware signatures or online reputation databases. It can expose mismatched extensions, executable structures, suspicious archive paths and other clues.
Why can a DOCX file be detected as a ZIP package?
DOCX, XLSX, PPTX, APK, JAR and EPUB are ZIP-based containers. The inspector reads the central directory and identifies the subtype from characteristic internal paths.
What does high entropy mean?
High entropy often appears in compressed, encrypted or packed data, including perfectly normal photos, videos and archives. It becomes interesting mainly when the declared file type does not explain it.
Does the tool upload archive filenames?
No. ZIP paths and sizes are read from the selected file in your browser. Nothing is extracted or transmitted.