{"id":20674987,"url":"https://github.com/calinux-py/whodat","last_synced_at":"2025-06-15T19:33:43.865Z","repository":{"id":261717687,"uuid":"885122832","full_name":"calinux-py/WhoDAT","owner":"calinux-py","description":"WhoDAT is an InfoSec Analyzer for Nerds using VirusTotal, Google Safe Browsing, URLScan, Hybrid-Analysis, and OpenAI. Scan URLs, emails, headers, and attachments for malicious activity!","archived":false,"fork":false,"pushed_at":"2024-12-19T04:15:43.000Z","size":64571,"stargazers_count":4,"open_issues_count":0,"forks_count":0,"subscribers_count":2,"default_branch":"main","last_synced_at":"2024-12-19T04:36:48.587Z","etag":null,"topics":["anti-phishing","anti-phishing-tools","attachment-scanner","cybersecurity-ai","cybersecurity-python","cybersecurity-tools","email-analysis","email-analyzer","google-safe-browsing-api","hybrid-analysis","knowbe4","malicious-url","malicious-url-detection","phishing","phishing-defense","phishing-detection","url-analysis","url-scanner","urlscan-api","virustotal-api"],"latest_commit_sha":null,"homepage":"","language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/calinux-py.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2024-11-08T02:00:30.000Z","updated_at":"2024-12-19T04:15:46.000Z","dependencies_parsed_at":null,"dependency_job_id":"fe5a03c1-12c3-4738-997b-f9a15dda0c63","html_url":"https://github.com/calinux-py/WhoDAT","commit_stats":null,"previous_names":["calinux-py/whodat"],"tags_count":2,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/calinux-py%2FWhoDAT","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/calinux-py%2FWhoDAT/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/calinux-py%2FWhoDAT/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/calinux-py%2FWhoDAT/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/calinux-py","download_url":"https://codeload.github.com/calinux-py/WhoDAT/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":234376923,"owners_count":18822417,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["anti-phishing","anti-phishing-tools","attachment-scanner","cybersecurity-ai","cybersecurity-python","cybersecurity-tools","email-analysis","email-analyzer","google-safe-browsing-api","hybrid-analysis","knowbe4","malicious-url","malicious-url-detection","phishing","phishing-defense","phishing-detection","url-analysis","url-scanner","urlscan-api","virustotal-api"],"created_at":"2024-11-16T21:08:15.387Z","updated_at":"2025-06-15T19:33:43.850Z","avatar_url":"https://github.com/calinux-py.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"![Banner Image](https://github.com/calinux-py/WhoDAT/blob/main/config/WhoDatBanner.png?raw=true)\n# [\u003cimg src=\"https://github.com/calinux-py/WhoDAT/blob/main/whodat.png?raw=true\" alt=\"WhoDAT Logo\" width=\"3%\"\u003e](https://github.com/calinux-py/WhoDAT/tree/main) WhoDAT - InfoSec Analyzer for Nerds\n\nWhoDAT is a GUI-based cybersecurity tool for nerds. \n\nAnalyze emails, URLs, headers, IPs, and attachments for threats--using free APIs like VirusTotal, Google Safe Browsing, URLScan, and Hybrid Analysis.\n\n![Windows](https://img.shields.io/badge/platform-Windows-blue) ![Python](https://img.shields.io/badge/language-Python-darkgreen) ![OpenAI](https://img.shields.io/badge/OpenAI-412991?logo=openai\u0026logoColor=white) ![VirusTotal](https://img.shields.io/badge/VirusTotal-0078D4?logo=virustotal\u0026logoColor=white) ![Hybrid Analysis](https://img.shields.io/badge/Hybrid%20Analysis-004080?logo=hybridanalysis\u0026logoColor=white) ![Google Safe Browsing](https://img.shields.io/badge/Google%20Safe%20Browsing-34A853?logo=google\u0026logoColor=white) ![URLScan](https://img.shields.io/badge/URLScan-FFA500)\n\n[\u003cimg src=\"https://github.com/calinux-py/WhoDAT/blob/main/config/pocimg.png?raw=true\" alt=\"WhoDAT\" width=\"75%\"\u003e](https://github.com/calinux-py/WhoDAT/blob/main/config/pocimg.png?raw=true)\n\n[Download the portable executable version here!](https://github.com/calinux-py/WhoDAT/releases/download/whodatv1.4/whodat.exe)\n\n## Features\n\n### 🌐 Domain Analyzer\nAnalyze URLs, email addresses, and IP addresses to reveal their threat level:\n- **Website Analysis**: Search if a website is a known malicious site and take a secure screenshot using URLScan.io.\n- **Email Analysis**: Verifies if email domains are free, disposable, or associated with suspicious activity.\n- **URL Analysis**: Scans URLs to detect malware, phishing attempts, and suspicious redirects.\n- **IP Address Analysis**: Checks if an IP address has been associated with previous malicious activity.\n- **WHOIS Data**: Retrieves WHOIS information for domains to confirm registration dates, geographical origins, and other key details.\n- **DMARC Analysis**: Check if an email has been potentially spoofed.\n\n### 📨 Header Analyzer\nUncover security issues hidden in email headers:\n- **IP Address Analysis**: Extracts originating IPs and determines their geographic and ISP origins. IP addresses from outside the US are flagged (I'm American - edit the code to change noob).\n- **SPF, DKIM, and DMARC**: Validates authentication records to detect spoofing attempts.\n- **Intermediary Hop Analysis**: Identifies intermediate servers through header inspection.\n\n### 🔍 Sentiment Analyzer\nDetect phishing and other sus language in email content:\n- **Content Analysis**: Scans for urgency cues, suspicious language, and embedded links.\n- **OpenAI Integration**: Uses AI to provide a classification score and risk assessment based on content indicators.\n\n### 📎 Attachment Analyzer\nEnsure attachments are safe before opening:\n- **File Scanning**: Uploads files to VirusTotal and Hybrid Analysis to see if malicious or sus.\n- **Real-Time Reports**: Displays detailed findings from VirusTotal and Hybrid Analysis, including detection by antivirus engines and potential threat levels.\n- **QR Code Scanning**: Scan QR codes and automatically process the embedded link for malicious activity.\n\n---\n\n## Getting Started\n\n### Prerequisites\nEnsure you have Python 3.6+ installed. Install dependencies via:\n\n```powershell\npip install -r requirements.txt\n```\n\n### API Keys\n\n*API Keys are NOT required but will limit the usefulness considerably. They are free. Don't be lazy. You can skip the OpenAI API if you don't want AI analysis.*\n\nWhoDAT uses API keys from several services. All are FREE (except openai but its like a penny). Add your keys in config/config.ini under the relevant sections:\n\n- [VirusTotal](https://docs.virustotal.com/reference/overview)\n- [Google Safe Browsing](https://console.cloud.google.com/apis/api/safebrowsing.googleapis.com)\n- [URLScan](https://urlscan.io/docs/api/)\n- [OpenAI](https://platform.openai.com/docs/overview)\n- [Hybrid Analysis](https://hybrid-analysis.com/docs/api/v2)\n\n`NOTE: config/config.ini MUST be in the same directory as whodat.py/whodat.exe.`\n```\nWhoDAT(Python)/\n├── whodat.py\n├── utils.py\n├── gui.py\n├── analysis.py\n├── api.py\n├── config.py\n└── config/\n    └── config.ini\n\nWhoDAT(Portable Executable)/\n├── whodat.exe\n└── config/\n    └── config.ini\n```\n\n---\n\n### Usage\n[Download the Python script](https://github.com/calinux-py/WhoDAT/archive/refs/heads/main.zip) or [download the portable executable version](https://github.com/calinux-py/WhoDAT/releases/download/whodatv1.4/whodat.exe).\n\nStart the .exe or run whodat.py using Python.\n```\npython whodat.py\n```\n\nSelect Analysis Type: Choose a tab for the type of analysis you want to perform:\n1) Domain Analyzer: Enter email or URL for analysis.\n2) Header Analyzer: Paste email headers for validation.\n3) Sentiment Analyzer: Paste email content to assess phishing risk.\n4) Attachment Analyzer: Upload files for malware analysis.\nInterpret Results: Results are presented with color-coded risk indicators, making it easy to assess threat levels at a glance.\n\n## File Overview\n\n### File\tDescription\n- config.py\tManages API keys and retrieves credentials from a configuration file.\n- gui.py\tImplements the PyQt5-based GUI, providing a structured interface for each analysis type.\n- utils.py\tUtility functions for URL defanging, email obfuscation, and data formatting.\n- whodat.py\tMain application entry point, initializing the GUI.\n- analysis.py\tCore analysis logic, with background threads handling various tasks such as WHOIS checks, header parsing.\n- api.py\tManages API requests to external services (VirusTotal, URLScan, Safe Browsing, OpenAI) and processes responses.\n\n[\u003cimg src=\"https://github.com/calinux-py/WhoDAT/blob/main/config/poc.gif?raw=true\" alt=\"WhoDAT\" width=\"75%\"\u003e](https://github.com/calinux-py/WhoDAT/blob/main/config/poc.gif?raw=true)\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcalinux-py%2Fwhodat","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fcalinux-py%2Fwhodat","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fcalinux-py%2Fwhodat/lists"}