Qu1cksc0pe tool allows you to statically analyze Windows, Linux, OSX executables and APK files.
You can get:
Qu1cksc0pe aims to get even more information about suspicious files and helps user realize what that file is capable of.
Usage
python3 qu1cksc0pe.py –file suspicious_file –analyze
Screenshot
Updates
09/10/2021
AndroidRuntime module. Now you can analyze android applications dynamically!!Available On
Note
Windows Subsystem Linux in Windows 10.Necessary python modules:
puremagic => Analyzing target OS and magic numbers.androguard => Analyzing APK files.apkid => Check for Obfuscators, Anti-Disassembly, Anti-VM and Anti-Debug.prettytable => Pretty outputs.tqdm => Progressbar animation.colorama => Colored outputs.oletools => Analyzing VBA Macros.pefile => Gathering all information from PE files.quark-engine => Extracting IP addresses and URLs from APK files.pyaxmlparser => Gathering informations from target APK files.yara-python => Android library scanning with Yara rules.prompt_toolkit => Interactive shell.frida => Performing dynamic analysis against android applications.
Installation of python modules: pip3 install -r requirements.txt
Gathering other dependencies:
https://virustotal.comsudo apt-get install binutilssudo apt-get install exiftoolsudo apt-get install stringsAlert
You must specify jadx binary path in Systems/Android/libScanner.conf
[Rule_PATH]
rulepath = /Systems/Android/YaraRules/
[Decompiler]
decompiler = JADX_BINARY_PATH <– You must specify this.
Installation
sudo pip3 install -r requirements.txtsudo python3 qu1cksc0pe.py --installUsage: python3 qu1cksc0pe.py --file suspicious_file --analyze
Multiple Analysis
Usage: python3 qu1cksc0pe.py --multiple FILE1 FILE2 ...
Hash scan
Usage: python3 qu1cksc0pe.py --file suspicious_file --hashscan
Folder scan
Supported Arguments:
--hashscan--packerUsage: python3 qu1cksc0pe.py --folder FOLDER --hashscan
Virus Total
Report Contents:
Threat CategoriesDetectionsCrowdSourced IDS ReportsUsage for –vtFile: python3 qu1cksc0pe.py --file suspicious_file --vtFile
Document scan
Usage: python3 qu1cksc0pe.py --file suspicious_document --docs
Programming language detection
Usage: python3 qu1cksc0pe.py --file suspicious_executable --lang
Interactive shell
Usage: python3 qu1cksc0pe.py --console
Domain
Usage: python3 qu1cksc0pe.py --file suspicious_file --domain
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
This category contains functions and strings about:
In MySQL Server 5.5 and earlier versions, the MyISAM was the default storage engine. So,…
A newly disclosed vulnerability in Microsoft Authenticator could expose one time sign in codes or…
Modrinth is a modern platform that’s rapidly changing the landscape of Minecraft modding, providing an…
A new, highly sophisticated malware campaign named BlackSanta has emerged, primarily targeting HR and recruitment…
Perplexity has unveiled an exciting new feature, Personal Computer, which allows AI agents to seamlessly…
In a recent cyber incident, a group named CARDINAL, associated with the label Russian Legion,…