{"id":3594,"date":"2016-04-06T23:43:30","date_gmt":"2016-04-06T23:43:30","guid":{"rendered":"http:\/\/www.hexacorn.com\/blog\/?p=3594"},"modified":"2016-04-06T23:46:47","modified_gmt":"2016-04-06T23:46:47","slug":"dexray-twentin-quarantino","status":"publish","type":"post","link":"https:\/\/www.hexacorn.com\/blog\/2016\/04\/06\/dexray-twentin-quarantino\/","title":{"rendered":"DeXRAY &#8211; Twentin Quarantino"},"content":{"rendered":"<p>DeXRAY now supports over twenty Quarantine filetypes. I set a goal to look at one AV per day, unless I am busy with other stuff. So far, the results are kinda predictable: the most difficult to access with a debugger \/ crack \/ analyze are Chinese, Russian, and&#8230; Microsoft. The rest of the files took between 2 minutes to 2h of work max. It&#8217;s a great reversing experience as it&#8217;s heavily time-sensitive research (I want to crack it in one session), and at the same time I am learning about many pointers which I can use for further research and study. The guys @<a href=\"https:\/\/googleprojectzero.blogspot.com\">ProjectZero<\/a> are unfortunately right. The moment you start looking at AV internals you discover lots of juicy stuff. Ouch. I strongly believe the AV is _needed_ in a current &#8216;open ecosystem&#8217; setup existing in most of the companies, but it&#8217;s time AV vendors really review their code.<\/p>\n<p>Anyway&#8230;<\/p>\n<p>I have added support for Baidu .qv, CMC Antivirus *.cmc, and F-Prot .tmp Quarantine files. Confirmed Lavasoft AdAware\u00a0 to be using BitDefender&#8217;s Quarantine files (.bdq), confirmed Comodo stores Quarantine files w\/o encryption \ud83d\ude42<\/p>\n<p>The full list of supported or recognized file formats is listed below:<\/p>\n<ul>\n<li>AhnLab (V3B)<\/li>\n<li>ASquared (EQF)<\/li>\n<li>Avast (Magic@0=&#8217;-chest- &#8216;)<\/li>\n<li>Avira (QUA)<\/li>\n<li>Baidu (QV)<\/li>\n<li>BitDefender (BDQ)<\/li>\n<li>CMC Antivirus (CMC)<\/li>\n<li>Comodo &lt;GUID&gt; (not really; Quarantined files are not encrypted \ud83d\ude42<\/li>\n<li>ESET (NQF)<\/li>\n<li>F-Prot (TMP) (Magic@0=&#8217;KSS&#8217;)<\/li>\n<li>Kaspersky (KLQ)<\/li>\n<li>Lavasoft AdAware (BDQ) \/BitDefender files really\/<\/li>\n<li>MalwareBytes Data files (DATA)<\/li>\n<li>MalwareBytes Quarantine files (QUAR)<\/li>\n<li>McAfee Quarantine files (BUP)<\/li>\n<li>Microsoft Forefront|Defender (Magic@0=0B AD|D3 45) &#8211; not handled yet; only recognized<\/li>\n<li>Panda &lt;GUID&gt; Zip files<\/li>\n<li>SUPERAntiSpyware (SDB)<\/li>\n<li>Symantec Quarantine Data files (QBD)<\/li>\n<li>Symantec Quarantine files (VBN)<\/li>\n<li>Symantec Quarantine Index files (QBI)<\/li>\n<li>TrendMicro (Magic@0=A9 AC BD A7 which is &#8216;VSBX&#8217; string ^ 0xFF)<\/li>\n<li>QuickHeal &lt;hash&gt; files<\/li>\n<li>Vipre (&lt;GUID&gt;_ENC2)<\/li>\n<li>Any binary file (using X-RAY scanning)<\/li>\n<\/ul>\n<p>The script can be downloaded <a href=\"https:\/\/hexacorn.com\/download.php?f=DeXRAY.pl\">here<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>DeXRAY now supports over twenty Quarantine filetypes. I set a goal to look at one AV per day, unless I am busy with other stuff. So far, the results are kinda predictable: the most difficult to access with a debugger &hellip; <a href=\"https:\/\/www.hexacorn.com\/blog\/2016\/04\/06\/dexray-twentin-quarantino\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[28,12,21,19,46,9,44,5],"tags":[],"_links":{"self":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3594"}],"collection":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/comments?post=3594"}],"version-history":[{"count":6,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3594\/revisions"}],"predecessor-version":[{"id":3601,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/posts\/3594\/revisions\/3601"}],"wp:attachment":[{"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/media?parent=3594"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/categories?post=3594"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.hexacorn.com\/blog\/wp-json\/wp\/v2\/tags?post=3594"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}