Static inspection for Java archives

Know what a JAR contains before you trust it.

Darky RAT Check inspects Minecraft plugins, mods and Java archives at the class-file level. It maps JVM calls, recovers code, extracts network indicators and identifies connected high-risk behavior without launching the upload.

Files are not executed Temporary processing Detailed scan reports
PLG
Plugin checker

Paper, Spigot, Bukkit, BungeeCord and Velocity packages.

MOD
Mod checker

Fabric, Forge, NeoForge and Quilt packages.

JAR
Java scanner

General JAR archives and standalone JVM class files.

ANALYSIS COVERAGE

Inspection of the archive, classes and resources.

The scanner reads the uploaded archive, class files, metadata and packaged resources. Findings include the supporting file or code reference when available.

01

Archive and identity

Calculates cryptographic hashes, reads manifests and identifies supported plugin or mod metadata.

02

Bytecode inspection

Parses classes, methods, descriptors and verified JVM invocation targets from compiled code.

03

Code recovery

Provides decompiled Java source when available and JVM disassembly when source recovery is limited.

04

Network indicators

Extracts URLs, domains, sockets, webhooks, HTTP clients and outbound communication paths.

05

System capabilities

Identifies process execution, file access, native loading, reflection and dynamic class loading.

06

Embedded payloads

Inventories scripts, executables, native libraries, nested archives and unusual packaged resources.

Built specifically for Java and Minecraft files.

Multi-engine malware platforms are useful for antivirus detections, reputation and sandbox intelligence. Darky RAT Check adds a specialized view of JVM archives: plugin metadata, class structure, invocation maps, recovered source, strings, resources and behavior chains.

Use the report to review a file before installation. For high-risk or heavily obfuscated files, confirm the result with additional security tools or manual review.

See exactly how analysis works →
REPORT CONTENTSCode-level evidence
  • Verified JVM method callsIncluded
  • Recovered source or disassemblyIncluded
  • Plugin and mod metadataIncluded
  • Strings, URLs and domainsIncluded
  • Embedded files and nested archivesIncluded
  • Correlated suspicious capabilitiesIncluded
READY TO CHECK A FILE?

Inspect it before installing it.

Upload a Java archive and review the evidence report before placing it on a server or client.

Open scanner

Analysis notice: No automated scanner can guarantee that an obfuscated, encrypted or runtime-loaded file is safe. Use the report as one part of a broader security review.