RSS Feed

Please wait while my feed loads

See more posts...

Newsletter

Subscribe to either one of our two newsletters for regular updates and information

Downloads newsletter

This is a weekly newsletter with download news, updates and other information

This is a monthly newsletter with software store information, offers and deals

DensityScout build 45

Quickly find even unknown malware with this interesting command-line tool from CERT Austria

by Mike Williams

Our Rating:
Your Rating:
Login to rate
Based on 0 ratings
License: Freeware
Operating Systems: Linux, Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8, Windows Vista (32 bit), Windows Vista (64 bit), Windows XP
Requirements:
Languages: English
Software Cost: Free
Date Updated: 08 January 2017
Watchlist: Add download to my watchlist
Downloads To Date: 386
Developer: CERT Austria
RSS News Feed: http://www.cert.at/all.warnings.specials.rss_2.0.xml
Buy Malwarebytes 3.0 Premium with a 1-PC license for only $29.99, saving 50% from store.downloadcrew.com
DensityScout
Quickly find even unknown malware with this interesting command-line tool

DensityScout is an interesting command-line tool from CERT Austria which can highlight malware-related files on your PC.

The program uses an unusual mathematical technique to figure this out. Or, as the author puts it, DensityScout "calculates density (like entropy) for files of any file-system-path to finally output an accordingly descending ordered list".

But the underlying idea is this. Standard unpacked executable files will have an uneven spread of bytes; that is, some byte patterns will occur more often than others due to structures in the file. Malware is often packed, though, which not only conceals the real executable, but also means you'll have a more even distribution of byte usage throughout the file.

So what does this mean? The author recommends launching the program with a line like this.

densityscout -s cpl,exe,dll,ocx,sys,scr -p 0.1 -o results.txt c:\Windows\System32

(Be sure to read his SANS blog post on the program.)

Which essentially means scan all the executable files in the Windows System32 folder, saving the data to results.txt. Those results are then placed in order, with the lowest and most suspect values at the top. Which in our case started like this:

(0.02417) | c:\Windows\System32\FlashPlayerInstaller.exe
(0.16460) | c:\Windows\System32\DivX.dll
(0.22350) | c:\Windows\System32\iglhsip32.dll
(0.28759) | c:\Windows\System32\AuthFWGP.dll

And as you can see, the program has worked, at least to a degree: the two top values are "intruders", presumably packed (though also entirely legitimate, so of course you must check any highlighted files to see what they really are).

There's no magic solution here, then, and the program's command-line nature mean it's not exactly easy to use. But, if you're an expert who would like a little extra antivirus help then DensityScout could definitely come in handy occasionally.

Verdict:

A clever idea which could help you locate suspect files on your computer (though its command-line nature and general complexity mean it's strictly experts-only)

Your Comments & Opinion
 
Related Download Articles
 
Bitdefender TrafficLight for Chrome 1.0.0.2

Bitdefender TrafficLight for Chrome 1.1.0.9

Freeware

Protect yourself from phishing sites, malware and more

Panda Free Antivirus

Panda Free Antivirus 18.3

Freeware

A fast, easy-to-use antivirus tool

AVG Rescue CD (USB Flash Drive Edition)

AVG Rescue CD (USB Flash Drive Edition) v120.160420

Freeware

Free bootable USB-based environment to remove viruses and fix some PC startup problems

Re-Enable 2.0

Re-Enable 2.0

Freeware

Quickly repair your system after a virus attack

Other Download Articles From This Category
Kaspersky Virus Removal Tool

Kaspersky Virus Removal Tool 15.0.19.0 build 2017.09.24

Freeware

Detect malware on your PC with this stand-alone security tool

Buttercup 0.24.0

Buttercup 0.24.3

Open Source

Cross-platform, free and open-source password manager

Avira Internet Security Suite

Avira Internet Security Suite v15.0.33

Trial Software

Protect and maintain your PC with Avira's latest security suite

Avira Free AntiVirus

Avira Free AntiVirus 2018 v15.0.33

Free, for personal-use only

Keep your PC safe from malware with Avira's latest release

From Softwarecrew

Please wait while my feed loads

See more posts...

Our Price: $19.95
RRP: $49.99
Saving 60%
Buy Now
Offer Ends In:
 

Spotlight: Free Full Software

WhatsApp Messenger 2.17.80

Free Full Commercial Software

WhatsApp Messenger is the world's most popular instant messaging app for smartphones.

You can use it to send and receive text and voice messages, photos, videos, even call your friends in other countries, and because it uses your phone's internet connection it might not cost you anything at all (depending on whether you'll pay data charges).

It's easy to set up and use. There's no need to create and remember new account names or pins because it works with your phone number, and uses your regular address book to find and connect you with friends who use WhatsApp already.

You can talk one-to-one or in group chats, and because you're always logged in there's no way to miss messages. Even if your phone is turned off, WhatsApp will save your messages and display them as soon as you're back online.

There's plenty more (location sharing, contact exchange, message broadcasting) and the app is free for a year, currently $0.99/ year afterwards.

What's New in Version 2.17.80

• Now you can delete messages you've sent by mistake. Just tap and hold a message you sent in the last 7 minutes, tap delete, and select "Delete for everyone." The message will be deleted for you and everyone in the chat. Requires the latest version of WhatsApp.
• Live location: now you can share your location in real-time with family and friends. Open any chat, tap the + icon > location, and tap "Share Live Location" to get started. 
• Fixed an issue that was preventing some message notifications from appearing on iOS 11.

[...]
Value:
Free
Rating: