Author: Tom Cocker
This repository contains the setup, workflow, and analysis documentation for a reproducible, fully isolated malware-analysis lab built on VMware Workstation Pro. The lab pairs a hardened Kali Linux VM for static analysis with a hardened Windows 10 VM for dynamic analysis, connected only to each other over a host-only network with no route to the internet or host.
Each virtual machine was hardened following standard containment practices, including disabled host-integration features (shared folders, clipboard, drag-and-drop), removed USB/sound devices, and snapshot-based rollback between every analysis run.
The lab environment consists of two virtual machines connected across one isolated VMware virtual network:
Machines:
| VM | Role | Toolchain |
|---|---|---|
| MalwareLab-Static | Analysis without execution | Ghidra, binwalk, exe2hex, strings, hashing utilities |
| MalwareLab-Dynamic | Execute and observe malware | Process Monitor, Process Explorer, Autoruns, Regshot, Wireshark, FakeNet-NG |
Networks:
| Network | Type | Purpose |
|---|---|---|
| VMnet2 | Host-only (192.168.150.0/24, static IPs, no DHCP/gateway) |
Isolated Kali↔Windows lab traffic; no route to host or internet |
| NAT | Temporary | Tool installs, updates, and sample downloads only — disabled and re-validated before analysis |
Documentation is organized into four directories at the root of the repository — setup, workflow-guides, reports, and artifacts.
setup contains everything needed to build the lab: VM creation and hardening, network isolation, toolchain installation, and sample sourcing. It's split into three subfolders — static-environment (Kali VM and toolchain), dynamic-environment (Windows VM and toolchain), and sample-sourcing (malware sample acquisition and handling).
workflow-guides contains the repeatable, step-by-step procedures followed during every analysis session — one guide for static analysis, one for dynamic analysis.
reports contains the written analysis for each malware sample, split into static and dynamic subfolders, one session write-up per sample.
artifacts contains screenshots gathered during each analysis session and are included in each report references by number (Artifact 000)
Complete the guides in the following order. Each guide assumes the previous has been completed.
| Step | Guide | Description |
|---|---|---|
| 1 | Kali VM Configuration | Build and harden the Kali VM |
| 2 | Static Tools Configuration | Install and verify the static toolchain |
| 3 | Windows VM Configuration | Build and harden the Windows VM |
| 4 | Dynamic Tools Configuration | Install and verify the dynamic toolchain |
| 5 | Sample Acquisition Guide | Source, hash, and stage malware samples |
| 6 | Static Workflow | Run a static analysis session |
| 7 | Dynamic Workflow | Run a dynamic analysis session |
| 8 | Sample Reports | Jigsaw, Kovter, and Asprox static/dynamic write-ups |
| ID | Name | Type | Notes |
|---|---|---|---|
| 001 | Jigsaw | Ransomware | .NET-based, file encryption + countdown ransom UI |
| 002 | Kovter | Trojan | Fileless, registry-based execution |
| 003 | Asprox | Botnet | C2 communication, JS-based distribution |
Full sourcing rationale and hashes: Sample Acquisition Guide.
The resources below assisted in the creation of this project's documentation and can be used for troubleshooting or further reading.
- VMware Workstation Pro Documentation
- Kali Linux Documentation
- NIST SP 800-125 — Guide to Security for Full Virtualization Technologies
- Wireshark User Guide
- FakeNet-NG
- Sysinternals Suite (Process Monitor, Process Explorer, Autoruns)
- Regshot
- Sikorski, M., & Honig, A. (2012). Practical Malware Analysis. No Starch Press.
- MITRE ATT&CK Framework
- theZoo — Malware Sample Repository