RSS Feed

Please wait while my feed loads

See more posts...

Newsletter

Subscribe to either one of our two newsletters for regular updates and information

Downloads newsletter

This is a weekly newsletter with download news, updates and other information

This is a monthly newsletter with software store information, offers and deals

DensityScout build 45

Quickly find even unknown malware with this interesting command-line tool from CERT Austria

by Mike Williams

Our Rating:
Your Rating:
Login to rate
Based on 0 ratings
License: Freeware
Operating Systems: Linux, Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8, Windows Vista (32 bit), Windows Vista (64 bit), Windows XP
Requirements:
Languages: English
Software Cost: Free
Date Updated: 08 January 2017
Watchlist: Add download to my watchlist
Downloads To Date: 374
Developer: CERT Austria
RSS News Feed: http://www.cert.at/all.warnings.specials.rss_2.0.xml
Back up your data with Acronis True Image 2016 with a 1-PC LIFETIME license, only £19.95, saving 50%, from store.downloadcrew.co.uk
DensityScout
Quickly find even unknown malware with this interesting command-line tool

DensityScout is an interesting command-line tool from CERT Austria which can highlight malware-related files on your PC.

The program uses an unusual mathematical technique to figure this out. Or, as the author puts it, DensityScout "calculates density (like entropy) for files of any file-system-path to finally output an accordingly descending ordered list".

But the underlying idea is this. Standard unpacked executable files will have an uneven spread of bytes; that is, some byte patterns will occur more often than others due to structures in the file. Malware is often packed, though, which not only conceals the real executable, but also means you'll have a more even distribution of byte usage throughout the file.

So what does this mean? The author recommends launching the program with a line like this.

densityscout -s cpl,exe,dll,ocx,sys,scr -p 0.1 -o results.txt c:\Windows\System32

(Be sure to read his SANS blog post on the program.)

Which essentially means scan all the executable files in the Windows System32 folder, saving the data to results.txt. Those results are then placed in order, with the lowest and most suspect values at the top. Which in our case started like this:

(0.02417) | c:\Windows\System32\FlashPlayerInstaller.exe
(0.16460) | c:\Windows\System32\DivX.dll
(0.22350) | c:\Windows\System32\iglhsip32.dll
(0.28759) | c:\Windows\System32\AuthFWGP.dll

And as you can see, the program has worked, at least to a degree: the two top values are "intruders", presumably packed (though also entirely legitimate, so of course you must check any highlighted files to see what they really are).

There's no magic solution here, then, and the program's command-line nature mean it's not exactly easy to use. But, if you're an expert who would like a little extra antivirus help then DensityScout could definitely come in handy occasionally.

Verdict:

A clever idea which could help you locate suspect files on your computer (though its command-line nature and general complexity mean it's strictly experts-only)

Your Comments & Opinion
 
Related Download Articles
 
Kaspersky Internet Security 2017

Kaspersky Internet Security 2017 17.0.0.611 build 11515

Trial Software

Kaspersky's powerhouse security suite

Panda Free Antivirus

Panda Free Antivirus 17.0.1

Freeware

A fast, easy-to-use antivirus tool

AVG Rescue CD (USB Flash Drive Edition)

AVG Rescue CD (USB Flash Drive Edition) v120.160420

Freeware

Free bootable USB-based environment to remove viruses and fix some PC startup problems

Re-Enable 2.0

Re-Enable 2.0

Freeware

Quickly repair your system after a virus attack

Other Download Articles From This Category
Avira Password Manager for Chrome

Avira Password Manager 0.5.2.710 for Chrome

Freeware

Store all your logins in one place

Dashlane for iOS

Dashlane for iOS 4.10.0

Freeware

Protect all your sensitive online data across desktop and mobile

KeyLock

KeyLock 2.0.0

Trial Software

Lock/ unlock your PC with a USB key

Hotspot Shield 6

Hotspot Shield 6.5.1

Freeware

Protect your computer and enjoy unrestricted internet access when using wifi hotspots

From Softwarecrew

Please wait while my feed loads

See more posts...

Our Price: $19.99
RRP: $39.99
Saving 50%
Buy Now
Offer Ends In:
 

Spotlight: Free Full Software

WhatsApp Messenger 2.17.5

Free Full Commercial Software

WhatsApp Messenger is the world's most popular instant messaging app for smartphones.

You can use it to send and receive text and voice messages, photos, videos, even call your friends in other countries, and because it uses your phone's internet connection it might not cost you anything at all (depending on whether you'll pay data charges).

It's easy to set up and use. There's no need to create and remember new account names or pins because it works with your phone number, and uses your regular address book to find and connect you with friends who use WhatsApp already.

You can talk one-to-one or in group chats, and because you're always logged in there's no way to miss messages. Even if your phone is turned off, WhatsApp will save your messages and display them as soon as you're back online.

There's plenty more (location sharing, contact exchange, message broadcasting) and the app is free for a year, currently $0.99/ year afterwards.

What's New in Version 2.17.5

• Bug fixes.

[...]
Value:
Free
Rating: