QR Code

QR Code analysis within the Seqrite Malware Analysis Platform (SMAP) supports to detect malicious content embedded in QR codes. This feature will allow analysts to scan QR code data for threats such as phishing URLs, credential theft attempts, or links to malware-hosting sites.

You can upload a file containing a QR code for inspection. The platform will automatically decode the QR code and extract the embedded data (such as URLs, text, Email).
When a URL contains an attached payload (such as .doc, .docx, .pdf, .txt,) it is analyzed using both static and dynamic engines, whereas URLs without payloads are evaluated through threat intelligence lookups.

In both cases the platform provides URL verdict (Malicious, Unknown and clean) and Payload verdict (Ransomware, Malware, Suspicious, Unknown, and clean) along with contextual details to support further investigation.

Note: If a file contains multiple QR codes, only one code will be randomly selected for analysis.

Upload File for QR Code Analysis

To upload the file for QR code analysis, follow these steps:

  1. Log in to the Seqrite Malware Analysis Platform and click QR Code on left pane.
    Note: Supported file types for QR code analysis are .jpg, .png, .bmp, and .pdf.
  2. The uploaded file is visible in list of QR Code Analysis Report with details: file name, submitted on, URL, URL verdict (Unknown, Malicious or Clean), payload status, and payload verdict.
    Note: The payload (the file extracted from the QR Code) is visible once the analysis process begins.

  3. Click Analyze to start analyzing the payload.
    A popup Payload Detection in QR Code appears.

    Note: QR code payload analysis uses quota from Preliminary Analysis/Detonation Analysis.

  4. Click Proceed.

The system will download the payload from that URL and send it for analysis.

Filtering QR Code Analysis Reports

You can filter the QR code analysis reports based on URL Verdict, Payload Status, Payload Verdict and Upload Period.
To filter the QR code analysis report list, follow these steps:

  1. Log in to the Seqrite Malware Analysis Platform and click QR Code on left pane.
  2. On the QR Code page, click .
  3. Select the filter type and click Apply.
    The system displays filtered data.
Was this page helpful?