Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

Malware Analysis Lab

Author: Tom Cocker


Overview

This repository contains the setup, workflow, and analysis documentation for a reproducible, fully isolated malware-analysis lab built on VMware Workstation Pro. The lab pairs a hardened Kali Linux VM for static analysis with a hardened Windows 10 VM for dynamic analysis, connected only to each other over a host-only network with no route to the internet or host.

Each virtual machine was hardened following standard containment practices, including disabled host-integration features (shared folders, clipboard, drag-and-drop), removed USB/sound devices, and snapshot-based rollback between every analysis run.


Network Architecture

The lab environment consists of two virtual machines connected across one isolated VMware virtual network:

Machines:

VM Role Toolchain
MalwareLab-Static Analysis without execution Ghidra, binwalk, exe2hex, strings, hashing utilities
MalwareLab-Dynamic Execute and observe malware Process Monitor, Process Explorer, Autoruns, Regshot, Wireshark, FakeNet-NG

Networks:

Network Type Purpose
VMnet2 Host-only (192.168.150.0/24, static IPs, no DHCP/gateway) Isolated Kali↔Windows lab traffic; no route to host or internet
NAT Temporary Tool installs, updates, and sample downloads only — disabled and re-validated before analysis

Repository Structure

Documentation is organized into four directories at the root of the repository — setup, workflow-guides, reports, and artifacts.

setup contains everything needed to build the lab: VM creation and hardening, network isolation, toolchain installation, and sample sourcing. It's split into three subfolders — static-environment (Kali VM and toolchain), dynamic-environment (Windows VM and toolchain), and sample-sourcing (malware sample acquisition and handling).

workflow-guides contains the repeatable, step-by-step procedures followed during every analysis session — one guide for static analysis, one for dynamic analysis.

reports contains the written analysis for each malware sample, split into static and dynamic subfolders, one session write-up per sample.

artifacts contains screenshots gathered during each analysis session and are included in each report references by number (Artifact 000)


Reading Order

Complete the guides in the following order. Each guide assumes the previous has been completed.

Step Guide Description
1 Kali VM Configuration Build and harden the Kali VM
2 Static Tools Configuration Install and verify the static toolchain
3 Windows VM Configuration Build and harden the Windows VM
4 Dynamic Tools Configuration Install and verify the dynamic toolchain
5 Sample Acquisition Guide Source, hash, and stage malware samples
6 Static Workflow Run a static analysis session
7 Dynamic Workflow Run a dynamic analysis session
8 Sample Reports Jigsaw, Kovter, and Asprox static/dynamic write-ups

Samples

ID Name Type Notes
001 Jigsaw Ransomware .NET-based, file encryption + countdown ransom UI
002 Kovter Trojan Fileless, registry-based execution
003 Asprox Botnet C2 communication, JS-based distribution

Full sourcing rationale and hashes: Sample Acquisition Guide.



Resources

The resources below assisted in the creation of this project's documentation and can be used for troubleshooting or further reading.

Environment & Virtualization

Static Analysis Tools

Dynamic Analysis Tools

Malware Research

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors