Difference between revisions of "VirtualBox: How to Setup your Malware Analysis"

From Embedded Lab Vienna for IoT & Security
Jump to navigation Jump to search
Line 36: Line 36:
=== Basic VM setup ===
=== Basic VM setup ===
Having installed VirtualBox you should see the home screen with button to create a new virtual machine and settings.
Having installed VirtualBox you should see the home screen with button to create a new virtual machine and settings.
[[File:basicsetup.png|800px|center|thumb|VirtualBox Setup and Home Screen]]
[[File:Vm basicsetup.png|800px|center|thumb|VirtualBox Setup and Home Screen]]


=== Advanced VM setup ===
=== Advanced VM setup ===

Revision as of 19:53, 5 December 2019

Summary

This documentation will provide you with a step-by-step guide to creating a virtual machine over VirtualBox. Though, we will not create a generic VM! This VM will provide you with a completely non-detectable environment for Malware Analysis.

As advanced malware nowadays is able to detect its environment (e.g. scanning for RAM, CPU cores, disk space, registry keys and even drivers) they are now able to stop their execution if they detect a virtualized environment. Therefore it is critical to setup your malware analysis VM correctly.

In order to render your VM undetectable we have chosen two state-of-the-art tools on Github. One only supports Windows as its host OS and the other is relying on dependencies only available on Ubuntu. Though we will use Windows 7 on both as the host VM as it is the most popular for malware attacks.

Requirements

  • Host Operating System: Ubuntu 16/18.04 or Windows 7/10
  • Guest Operating System: Windows 7 Home Premium 64-Bit
  • Software: VirtualBox 6.0.14
  • Tools for VM-hardening: VBoxHardenedLoader (for Windows) and antivmdetection (for Ubuntu)
  • Tool to check hardened VM: Pafish
  • Tool to simulate network: FakeNet

Sandboxing on Windows

Before we start, make sure you have downloaded the following:

  • Windows.iso
  • VirtualBox
  • VBoxHardenedLoader
  • Pafish (recommended)
  • FakeNet (recommended)

Regarding Pafish and FakeNet we recommend you to download them beforehand and make your own windows.iso that includes both. This will enable you to just drag and drop both from the virtual Windows installation CD on your VM, without the need to have a functioning Internet connection and download them.

Installing VirtualBox

VirtualBox Setup and Home Screen

The first step is to install VirtualBox. During the setup, we have to prevent it from installing the network drivers as they provide a weak point malware likes to scan for. After, finish the setup with the remaining configurations on default.


Basic VM setup

Having installed VirtualBox you should see the home screen with button to create a new virtual machine and settings.

VirtualBox Setup and Home Screen

Advanced VM setup

Starting VBoxHardenedLoader

Make sure to read

  • War and Peace
  • Lord of the Rings
  • The Baroque Cycle

Sandboxing on Ubuntu

Used Hardware

Device to be used with this documentation Maybe another device to be used with this documentation

Courses

References