Archive and identity
Calculates cryptographic hashes, reads manifests and identifies supported plugin or mod metadata.
Darky RAT CheckJAVA SECURITY ANALYSIS
Darky RAT Check inspects Minecraft plugins, mods and Java archives at the class-file level. It maps JVM calls, recovers code, extracts network indicators and identifies connected high-risk behavior without launching the upload.
The scanner reads the uploaded archive, class files, metadata and packaged resources. Findings include the supporting file or code reference when available.
Calculates cryptographic hashes, reads manifests and identifies supported plugin or mod metadata.
Parses classes, methods, descriptors and verified JVM invocation targets from compiled code.
Provides decompiled Java source when available and JVM disassembly when source recovery is limited.
Extracts URLs, domains, sockets, webhooks, HTTP clients and outbound communication paths.
Identifies process execution, file access, native loading, reflection and dynamic class loading.
Inventories scripts, executables, native libraries, nested archives and unusual packaged resources.
Multi-engine malware platforms are useful for antivirus detections, reputation and sandbox intelligence. Darky RAT Check adds a specialized view of JVM archives: plugin metadata, class structure, invocation maps, recovered source, strings, resources and behavior chains.
Use the report to review a file before installation. For high-risk or heavily obfuscated files, confirm the result with additional security tools or manual review.
See exactly how analysis works →Upload a Java archive and review the evidence report before placing it on a server or client.
Analysis notice: No automated scanner can guarantee that an obfuscated, encrypted or runtime-loaded file is safe. Use the report as one part of a broader security review.