Rho-9
ModForensics v3.0.1
Minecraft Mod Malware Forensics — Rho-9 Systems
STATIC ONLY
BRIDGE: OFFLINE
CACHE OFF
Load a decompiled mod file to begin analysis
ModForensics v3.0.1
Load a .zip (decompiled jar from decompiler.com), .litemod, .mrpack, or .class file.
.jar works too if the local decompile bridge is running and connected (see the BRIDGE pill above) — otherwise decompile first at decompiler.com and load the resulting .zip.

Full code viewer · strings · IOCs · flagged files · class refs · mixin targets · webhook kill.

◆ NEW IN v2.6: Stargazers/Baikal & WeedHack sigs · Skidfuscator/JNIC detection · Token-theft & crypto-wallet IOCs · Obfuscator heuristics · Entropy flagging · ROT-N brute · Copy-to-clipboard
◆ NEW IN v2.7: Aho-Corasick O(n) scanner · Full 202-opcode JVM table · tableswitch/lookupswitch · LOKI-style weighted scoring · RFC 4648 URL-safe base64 · SourceFile/InnerClass attributes · Entropy threshold 6.0
◆ NEW IN v3.0: Local Decompile Bridge · direct .jar support (static analysis only, no code execution) · auto-installing CFR/Vineflower engine · cross-platform (Windows/Linux/Termux) · SQLite-blob job storage wiped on shutdown · same-origin app serving
◆ FIXED IN v3.0.1 (2026-07-13): Mixin false positives — bare presence of @Overwrite/@Redirect no longer marks a mixin HIGH RISK on its own (both remain informational badges); danger now requires an actual dangerous method-name match. Was flagging routine gameplay mixins (e.g. toggle-sneak, HUD redirects) as high risk.
Select a file from the File Tree or click a flagged item to inspect it
String Picker — click any string to load & run
Load a file first
Input
Auto Manual
Pass Chain
Final Output