2.1. Virtual Machines
Virtual machines provide a safe sandbox for executing and analyzing malware. In
addition, they also provide the ability to take snapshots and to revert to an existing
snapshot at a later stage. This makes both static and dynamic analysis easier. For this
research, we used VMWare ESXi Server version 4.0 in order to host our Virtual
Machines. We used two virtual machines:
1. The Infected box, which is a Windows XP SP2 version 5.1.2800 virtual
machine with single 500MHz processor with 512 MB Ram and 4 GB disk
space. The host file (c:\Windows\System32\drivers\etc\host) was modified to
redirect traffic from the bots to the second VM described below. (Figure 1)
2. The C&C box, which is a Windows 2000 Server SP4 version 5.0.2195 virtual
machine. We are running a fake server script written in python. This script is
given in the section 10.7 entitled “Fake Server Script”.
Partager