WAS – Automatic USB drive malware scanning tool for the security-minded person

WAS 1.0.0 released!
Automatic USB drive malware scanning tool for the security-minded person

How many times have you plugged in a USB drive and double clicked on a file without scanning for malware? I guess, MANY.

Wait A Sec!

Even if you are a security guy, you’ll often be in a hurry or absent minded and you trust your USB drive (and so does your computer). What can possibly go wrong? Getting pwned is only a click away. You may have an antivirus with realtime protection, but if it doesn’t have the signatures for a new virus it’s very possible that it will be unnoticed and even heuristic scan may fail in detecting a new virus. Viruses are getting increasingly sophisticated.

Luckily there are services like Virus Total that allow you to scan a file with multiple antiviruses in order to increase the detection rate.

You may head over to Virus Total website and upload all the files manually one by one or you may use one of the scripts already available that allow you to check a file using Virus Total API, but this tool is unique in his genre because:

  • it allows to detect automatically the insertion of a new USB key

  • scan recursively all the files contained in the USB drive

  • hash the files and check them against the database of files already scanned by Virus Total

  • get an audio message every time a new virus is detected

  • automatically visualize a report in CSV format at the end of the scan

Note:
although the core functions work in a crossplatform fashion, the automatic detection of a new USB key works only on Windows at the moment.
python was.py
Try It Now!
Did you enjoy this article?
Signup today and receive free updates straight in your inbox. We will never share or sell your email address.
I agree to have my personal information transfered to MailChimp ( more information )

Author: Fabio Baroni   Date: 2016-09-14 00:50:28

Leave a Reply

Your email address will not be published. Required fields are marked *