Got a suspicious file or link? We'll tell you what it actually does.
GhostTrace handles infrastructure and entity attribution; when a sample turns out to be packed or obfuscated, our research partner Zenvoris — a reverse-engineering and deep binary analysis firm — handles the disassembly. One combined report either way.
In one sentence: Malware analysis is a two-tier service: a standard static/behavioral review of a suspicious file, script, or link ($399), or — for packed/obfuscated binaries that need real reverse-engineering — a deeper joint analysis with Zenvoris ($799).
What this service is
You send us the suspicious file, script, or link (never run it yourself first). We start with static analysis — examining the file without executing it: hashes, strings, embedded metadata, known-malware signature matches — then, where safe, controlled behavioral analysis in an isolated environment to observe what it actually does: network calls, file/registry changes, persistence mechanisms.
Some samples are straightforward — a single unpacked script or macro, quickly classified. Others are packed, obfuscated, or otherwise designed to resist casual inspection. For those, we route the sample to Zenvoris for full reverse-engineering and disassembly, and combine their findings with our own infrastructure and entity attribution (who's behind it, what else they're linked to) into one joint report.
Who this is for
- You received an unexpected attachment or link and want to know if it's safe before opening it.
- A file already ran on a device and you need to know what it did and whether data was exfiltrated.
- Your business received a suspicious executable, macro-enabled document, or script from an unknown sender.
- You found malware on a device or server and need a written report for insurance, a client, or an incident file.
How it works
Submit the sample
Upload the file or link through a secure, isolated intake — never open or run it yourself. Tell us where it came from and what you've already observed.
Static & behavioral analysis
We examine the sample without executing it, then — where safe — observe its behavior in an isolated environment. Packed or obfuscated samples are routed to Zenvoris for full disassembly.
Attribution & write-up
We trace any infrastructure the sample talks to — domains, IPs, known campaigns — and combine it with the technical findings into one plain-language report.
Recommendations
You get a clear verdict (malicious / suspicious / benign), what it does, and practical next steps — isolate a device, rotate credentials, notify affected parties, or nothing further needed.
What's included
- Static analysis: hashes, strings, metadata, known-signature matching.
- Controlled behavioral analysis in an isolated environment where safe to run.
- Full reverse-engineering and disassembly via Zenvoris for packed/obfuscated samples (Advanced tier).
- Infrastructure and entity attribution — domains, IPs, and known campaign links, where present.
- A plain-language written report with a clear verdict and practical next steps.
- Standard tier: $399. Advanced tier (packed/obfuscated, routed to Zenvoris): $799.
Frequently asked
Which tier do I need — Standard or Advanced?
You don't have to know in advance. Submit the sample at the Standard rate; if we determine during initial triage that it's packed or obfuscated and needs full reverse-engineering, we'll tell you before any Advanced-tier work (or its price difference) begins.
Is it safe to send you the file?
Yes — submission goes through a secure, isolated intake, and we never execute a sample outside a controlled, isolated analysis environment. Do not open, run, or forward the file yourself first.
What is Zenvoris?
Zenvoris is GhostTrace's reverse-engineering and deep binary analysis research partner. When a sample is packed or obfuscated enough to need full disassembly, they handle that piece and we combine it with our own infrastructure/entity attribution into one joint, dual-branded report. See our partnership page for details.
Can you remove the malware for me?
This service is analysis and reporting, not on-site remediation. Your report includes practical next steps (isolate the device, rotate credentials, restore from backup, etc.) you or your IT provider can act on.
How fast is turnaround?
Standard-tier samples are typically triaged and reported within a few business days. Advanced-tier samples routed to Zenvoris take longer, depending on complexity — your analyst sets expectations in the request thread once triage is complete.
Is this legal?
Yes — analyzing a sample you legitimately possess (received, found on your own systems, etc.) in an isolated environment is standard security practice. We don't access anyone else's systems or accounts.
Ready to get started?
Open a free account, describe your situation in plain language, and a GhostTrace analyst will pick it up within one business day.