The Finest Hand-Selected Downloads
Individually reviewed & tested
Store News

DensityScout build 45

Quickly find even unknown malware with this interesting command-line tool from CERT Austria

Rating:
(0)
Operating Systems:
Linux, Windows 10, Windows 7 (32 bit), Windows 7 (64 bit), Windows 8, Windows Vista, Windows XP
License:
Freeware
Developer:
CERT Austria
Software Cost:
Free
Category
Security
Date Updated:
08 January 2017
Downloads To Date:
1668
Languages:
English

DensityScout is an interesting command-line tool from CERT Austria which can highlight malware-related files on your PC.

The program uses an unusual mathematical technique to figure this out. Or, as the author puts it, DensityScout "calculates density (like entropy) for files of any file-system-path to finally output an accordingly descending ordered list".

But the underlying idea is this. Standard unpacked executable files will have an uneven spread of bytes; that is, some byte patterns will occur more often than others due to structures in the file. Malware is often packed, though, which not only conceals the real executable, but also means you'll have a more even distribution of byte usage throughout the file.

So what does this mean? The author recommends launching the program with a line like this.

densityscout -s cpl,exe,dll,ocx,sys,scr -p 0.1 -o results.txt c:\Windows\System32

(Be sure to read his SANS blog post on the program.)

Which essentially means scan all the executable files in the Windows System32 folder, saving the data to results.txt. Those results are then placed in order, with the lowest and most suspect values at the top. Which in our case started like this:

(0.02417) | c:\Windows\System32\FlashPlayerInstaller.exe
(0.16460) | c:\Windows\System32\DivX.dll
(0.22350) | c:\Windows\System32\iglhsip32.dll
(0.28759) | c:\Windows\System32\AuthFWGP.dll

And as you can see, the program has worked, at least to a degree: the two top values are "intruders", presumably packed (though also entirely legitimate, so of course you must check any highlighted files to see what they really are).

There's no magic solution here, then, and the program's command-line nature mean it's not exactly easy to use. But, if you're an expert who would like a little extra antivirus help then DensityScout could definitely come in handy occasionally.

Verdict:

A clever idea which could help you locate suspect files on your computer (though its command-line nature and general complexity mean it's strictly experts-only)

Your Comments & Opinion

Related Downloads Other Downloads From This Category

Comprehensive fully-featured security suite

Trial Software

Detect some hidden malware in seconds

Freeware

Block malware with China's favourite antivirus tool

Freeware
44,809,742
Downloads
Secure & Tested Software
6,478
Reviews
Instant Download 24/7
314,858
Members
10+ Years of Service