URLs, IPs and hosts found anywhere in the file. Suspicious ones are highlighted — webhooks, downloads and dead-drops included. A link that downloads another .jar is flagged for follow-up. Click a row to open the file it was found in.
Obfuscation signs and known obfuscator watermarks. Obfuscation isn't malware on its own — paid mods use it — but heavy obfuscation hiding what a mod does is worth a look.
Archive map — one block per file, shaded by entropy
Browse the archive as a tree — open folders and nested jars, then any file. Classes show as decompiled source, .java and configs as source, images as preview. Files are marked with a dot coloured by the worst thing found in them: ● malicious · ● suspicious · ● worth a look · ● just noted.