InQuest has just released a new analysis suite for the researcher and hobbyist. Welcome to InQuest Labs!
Our CTO, Pedram Amini, presented Worm Charming: Harvesting Malware Lures for Fun and Profit at Blackhat USA 2019. During this talk, Pedram detailed the harvesting mechanism that drives the DFI portion of InQuest Labs. Capable of ingesting malware at scale, samples are fed through a lightweight and less featured version of Deep File Inspection to extract embedded logic, semantic content, metadata, and IOCs such as URLs, domains, IPs, e-mails, and file names.
Currently, Microsoft and Open Office documents, spreadsheets, and presentations are available for search and download. In the future, we will expand the public data set to include Adobe PDF documents, Java / Flash applets, and scriptlets, such as Powershell. You can search extracted layers and IOCs by keyword. Download samples. Pivot between samples by heuristic detections and IOCs. And more... either interactively through the web interface, or programmatically through our open API. Result sets from the API are limited to 1337 results at a time. Contact us directly if you wish to gain unfettered access.
Some of the capabilities found within InQuest Labs are:
- Deep File Inspection (DFI-LITE)
- Indicators of Compromise Database (IOC-DB)
- Aggregate Reputation Database (REP-DB)
- YARA Tools
The InQuest Labs introduction blog highlights some of the capabilities of IOC-DB and REP-DB. Expect follow-on blogs showcasing DFI-LITE and the YARA tools.
Introduction Blog
Checkout InQuest Labs Here