Software
Now Reading
DeXRAY – decrypt Quarantine files for forensics
0

DeXRAY – decrypt Quarantine files for forensics

DeXRAY is a private tool that turned public a few years ago. It can help a digital forensic examiner to decrypt some AV Quarantine files. Here is the full list of supported or recognized file formats:

  • ASquared (EQF)
  • ESET (NQF)
  • Fortinet (Magic@0=0B AD) – not handled yet; only recognized
  • Kaspersky (KLQ) – based on the code by Optiv
  • MalwareBytes Data files (DATA)
  • MalwareBytes Quarantine files (QUAR)
  • McAfee Quarantine files (BUP) – not perfect, but it should still help
  • SUPERAntiSpyware (SDB)
  • Symantec Quarantine Data files (QBD)
  • Symantec Quarantine files (VBN) – not perfect, but it should still help
  • Symantec Quarantine Index files (QBI)
  • TrendMicro (Magic@0=A9 AC BD A7 which is ‘VSBX’ string ^ 0xFF) – based on the code by Optiv
  • Any binary file (using X-RAY scanning)

kav

For more info check the Hexacorn blog.

Download DeXRAY