DeXRAY – Quaranthon continues
April 1, 2016 in Batch Analysis, Compromise Detection, DeXRAY, File Formats ZOO, Forensic Analysis, Incident Response, Malware Analysis, Software Releases
I have added support for QuickHeal <hash> Quarantine files.
The full list of supported or recognized file formats is listed below:
- AhnLab (V3B)
- ASquared (EQF)
- Avast (Magic@0=’-chest- ‘)
- Avira (QUA)
- BitDefender (BDQ)
- ESET (NQF)
- Kaspersky (KLQ)
- MalwareBytes Data files (DATA)
- MalwareBytes Quarantine files (QUAR)
- McAfee Quarantine files (BUP)
- Microsoft Forefront|Defender (Magic@0=0B AD|D3 45) – not handled yet; only recognized
- Panda <GUID> Zip files
- SUPERAntiSpyware (SDB)
- Symantec Quarantine Data files (QBD)
- Symantec Quarantine files (VBN)
- Symantec Quarantine Index files (QBI)
- TrendMicro (Magic@0=A9 AC BD A7 which is ‘VSBX’ string ^ 0xFF)
- QuickHeal <hash> files
- Vipre (<GUID>_ENC2)
- Any binary file (using X-RAY scanning)
The script can be downloaded here.
Comments are closed.