Do The Things

Stop Talking, Start Doing

View on GitHub
13 November 2019

Put Malware In My Lab...safely?

by liteman

There are some excellent online resources describing how to put together basic malware analysis labs. I won’t rehash that content here.

One thing that seems to get breezed over or is missing entirely from a lot of the “How To Build A Malware Lab” articles, is how to safely get malware samples on to the ‘Victim’ VM without exposing the host to potential infection.

I want to walk through the options and look at the potential problems.

If you aren’t familiar with building a malware lab, please check out these excellent resources:

In terms of getting samples to the Victim VM, @MalwareTechBlog briefly mentions avoiding USB drives to transfer samples, and @MalwareUnicorn’s course is set up for hypervisor copy/paste to get samples from a host machine to a guest VM – however, she is using known samples that do not attempt VM escapes.

I want to cover the potential methods for file transfer here. Trying to find a balance between convenience and security.

Host-to-VM File Transfer Options

From most to least convenient:

tags: malware - malwarelab - malware@home