
All-in-One malware analysis tool.
You can get:
Qu1cksc0pe aims to get even more information about suspicious files and helps user realize what that file is capable of.
| Files | Analysis Type |
|---|---|
| Windows Executables (.exe, .dll, .msi, .bin) | Static, Dynamic |
| Linux Executables (.elf, .bin) | Static, Dynamic |
| MacOS Executables (mach-o) | Static |
| Android Files (.apk, .jar, .dex) | Static, Dynamic(for now .apk only) |
| Golang Binaries (Linux) | Static |
| Document Files | Static |
| VBScript/VBA Family (.vbs, .vbe, .vba, .vb, .bas, .cls, .frm) | Static (--docs) |
| HTML Documents (.html, .htm) | Static (--analyze) |
| JavaScript (.js) | Static (--analyze) |
| HTA / HTML Application (.hta) | Static (--analyze) |
| Windows Batch Scripts (.bat, .cmd) | Static (--analyze) |
| Windows Shortcut (.lnk) | Static (--analyze) |
| Archive Files (.zip, .rar, .ace) | Static |
| PCAP Files (.pcap) | Static |
| Powershell Scripts | Static |
| E-Mail Files (.eml) | Static |
python qu1cksc0pe.py --file suspicious_file --analyze
# Launch Web UI
python3 qu1cksc0pe.py --ui

03/03/2026
build_deb.sh): .deb post-install now bundles JADX v1.5.3 download, Ollama installation, and pyOneNote pip install so a fresh Kali/Parrot system is fully functional without any manual post-setup. Depends on default-jre-headless, unzip, curl | wget; adb/strace/ltrace moved to Recommends (non-blocking on systems that lack them).qu1cksc0pe.py, apkAnalyzer.py, emulator.py, pcap_analyzer.py, and email_analyzer.py now use sys.executable instead of shutil.which("python3"). Previously, sub-analyzers launched inside a virtualenv fell back to the system Python and raised ModuleNotFoundError for every pip-installed dependency (puremagic, androguard, pyaxmlparser, …).apkAnalyzer.py — resolve_decompiler_path() and is_valid_jadx_launcher() now catch PermissionError when scanning the /opt/Qu1cksc0pe/jadx/lib/ directory, falling back to an os.access() check. Previously the tool exited with an unhandled permission exception when run as a normal user and JADX was installed by root.archiveAnalyzer.py — RAR5 archives (and RAR archives on systems with unrar-free) returned an empty file list because unrar-free does not support RAR5. Added a two-stage fallback: (1) try rarfile with the best available extractor; (2) if infolist() is empty, fall back to 7z l (list-only, no password needed) parsed via the new _parse_7z_list() helper into a ListOnlyArchive wrapper. Password-protected archives are now listed without hanging — read() returns empty bytes so content scanning is skipped gracefully.apt install reminding the user to run ollama signin (AI features) and qu1cksc0pe --key_init (VirusTotal API key setup).02/03/2026
--console flag and Modules/console.py (interactive shell mode). All analysis capabilities remain fully available via the standard CLI flags.libscan variable (qu1cksc0pe.py), unused setup_scr variable (windows_static_analyzer.py, apkAnalyzer.py), and 11 no-op else: pass blocks (qu1cksc0pe.py, apkAnalyzer.py, domainCatcher.py, powershell_analyzer.py). All bare except: clauses in import guards tightened to except ImportError.Modules/android_dynamic_analyzer.py was missing import configparser — on Windows the ADB path lookup (adb_conf = configparser.ConfigParser()) would raise NameError at runtime. Import added.Modules/installer.sh): added set -euo pipefail, argument count and validity checks, source directory integrity verification, system user validation (rejects root as target user), python3/pip3 dependency checks, overwrite detection with confirmation prompt, trap ERR rollback on failure, fixed cp -r bug that nested the directory inside /opt/Qu1cksc0pe when destination already existed, pip now runs as the target user (sudo -u) instead of root, dos2unix guarded by command -v, uninstaller requires confirmation and reports when nothing is installed..animations/ (GIF demo files, ~80 MB across all historical versions) and RansomWare.WannaCry (test sample). Full clone size reduced from ~110 MB to ~5 MB.