Jump to content
Existing user? Sign In

Sign In



Sign Up
Search In
  • More options...
Find results that contain...
Find results in...

How to setup a malware testing environment to protect yourself from malicious files


Younes
 Share

Recommended Posts

In this guide we will setup a malware testing environment with VirtualBox and windows 7.

Use this environment to test any files you do NOT trust to ensure your main device is not infected should it be malware you're opening.
Part 1 will be covered in the video below, Part 2 can be found at the bottom of this thread.

 

Part 1: Setting up the VM with Windows 7.
 

Requirements
 

- VirtualBox
Virtual Machine software.

https://www.virtualbox.org/wiki/Downloads


 

- Windows 7 ISO
I expect you to be able to find your own source for that.

 

 


Setup & installation process.

https://www.youtube.com/watch?v=0_JdKyYGJbs

 

 


Part 2: Putting together a malware analysis toolkit.

Useful tools
 

-Comodo firewall
Firewall that monitors your incoming and outgoing traffic.

https://personalfirewall.comodo.com/


 

-MalwareBytes anti-malware
Anti virus software.

https://www.malwarebytes.org/antimalware/


 

-Unlocker
Useful when removing malware, can unlock, destroy, etc.. files.

http://filehippo.com/download_unlocker/


 

-Regshot
Shows system and registery chances before and after your machine has been infected.

https://sourceforge.net/projects/regshot/

 

 

-IDA Freeware / Ollydbg
Disassembler & debugger that can help you reverse engineer compiled executeables and help you analyze their code, etc..

https://www.hex-rays.com/products/ida/support/download_freeware.shtml
http://www.ollydbg.de/


 

-OllyDumpEx
Memory dumper that dumps the system's memory in a file to help you disassemble a packed executable where the instructions are encoded or encrypted.

http://low-priority.appspot.com/ollydumpex/

 

 

-Process explorer / Process hacker
Replacement for task manager, helps you manage malicious processes.
 

https://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
http://processhacker.sourceforge.net/

 

 

-Wireshark
Popular network sniffer, useful to detect malicious network communication requests.

https://www.wireshark.org/#download

 

 

-ProcDOT / Process monitor
A file and registry monitor useful to show you how malware plants itself on your machine.

http://www.procdot.com/downloadprocdotbinaries.htm
https://technet.microsoft.com/en-us/sysinternals/bb896645.aspx


 

 

 

Useful online tools
 

http://app.webinspector.com/
http://www.threatexpert.com/submit.aspx
https://malwr.com/
http://anubis.iseclab.org/
http://virustotal.com

 

The above websites are useful for reverse engineering malware.
 

 


Final steps
 


When you have downloaded your desired tools, install Microsoft .NET Framework 4.5.2. When that is done, take a snapshot on your VM so you have a clean VM to restore back to.


1. Go to "Machine" -> "Take Snapshot..." .

k9zGuRq.jpg



2. Name it and hit "Ok".

UEgSPTn.jpg


3. The VM will now save it's current state.

O9iJkaC.png


When you want to restore your VM after testing malware, hit the "X" in the top right corner and select "Power off the machine" & "Restore to current snapshot (snapshot name)".

8A6oG9A.jpg


As you can see it will be rolled back to your clean VM.

JNfZ6l3.jpg

 


If you're going to transfer files via a shared folder, make sure it's on READ ONLY, when you're doing testing make sure you DISCONNECT the folder.
I personally use a USB drive to transfer, to prevent the malware I'm testing to escape the VM.

 

 


That's the end of this guide, I hope everyone was able to setup their VM, if something went wrong or you have any questions, don't hesitate to post them below. I will do my best to answer all your questions.
I welcome all critics, good or bad on my threads so feel free to leave a reply.

Link to comment
Share on other sites

  • 2 weeks later...
 Share

Contact

ltlimes

RSPS Partners

RedemptionRSPS

What is a RSPS?

A RSPS, also known as RuneScape private server, is an online game based on RuneScape, and controlled by independent individuals.

Popular RSPS Servers

oldschoolrsps Runewild RedemptionRSPS

Disclaimer

Runesuite is not affiliated with runescape, jagex, rune-server and runelocus in any way & exists solely for educational purposes.

×
×
  • Create New...