악성코드 분석 1. 가상환경 구축(VirtualBox)
1. VirtualBox 다운로드
Downloads – Oracle VM VirtualBox
Download VirtualBox Here you will find links to VirtualBox binaries and its source code. VirtualBox binaries By downloading, you agree to the terms and conditions of the respective license. If you're looking for the latest VirtualBox 6.0 packages, see Virt
www.virtualbox.org
2. Windows, Kail 이미지 다운로드(.ova)
Virtual Machines - Microsoft Edge Developer
Virtual MachinesTest IE11 and Microsoft Edge Legacy using free Windows 10 virtual machines you download and manage locally Select a downloadVirtual Machines Select oneIE8 on Win7 (x86)IE9 on Win7 (x86)IE10 on Win7 (x86)IE11 on Win7 (x86)IE11 on Win81 (x86)
developer.microsoft.com
Download Kali Linux Virtual Images | Offensive Security
Want to download Kali Linux custom images? We have generated several Kali Linux VMware and VirtualBox images which we would like to share with the community. Note that the images provided below are maintained on a “best effort” basis and all future up
www.offensive-security.com
3. VirtualBox 환경설정
- VirtualBox에 Win 7.ova 업로드
- ① 환경설정 : VirtualBox 환경설정 → NatNetwork 설정(다른 Host간 통신을 하기 위한 설정)
- ② 환경설정 : IE11 Win7 환경설정 - NAT 네트워크 및 공유폴더 설정 후 Win7 시작
4. IE11-Win7 환경설정
- ID : IEUser / Password : Passw0rd!
- 첫번째, Windows Update 자동 업데이트 설정 해제 → 업데이트가 되는 경우 악성코드 실행 안되는 경우가 발생
- 두번째, IE11-Win7 절전 방지
- 7-zip 설치(https://www.7-zip.org)
- Sysinternals Sutie 설치(docs.microsoft.com/en-us/sysinternals/downloads/sysinternals-suite)
Sysinternals Suite - Windows Sysinternals
The Windows Sysinternals troubleshooting Utilities have been rolled up into a single suite of tools.
docs.microsoft.com
- 악성파일 샘플 다운로드(github.com/mikesiko/PracticalMalwareAnalysis-Labs)
mikesiko/PracticalMalwareAnalysis-Labs
Binaries for the book Practical Malware Analysis. Contribute to mikesiko/PracticalMalwareAnalysis-Labs development by creating an account on GitHub.
github.com
- pestudio 다운로드(www.winitor.com/features)
Winitor - Versions
Standard free Analysis of executable in a non-professional context.
www.winitor.com
- HxD Editor 다운로드(mh-nexus.de/en/hxd/)
HxD - Freeware Hex Editor and Disk Editor | mh-nexus
HxD - Freeware Hex Editor and Disk Editor HxD is a carefully designed and fast hex editor which, additionally to raw disk editing and modifying of main memory (RAM), handles files of any size. The easy to use interface offers features such as searching and
mh-nexus.de
- Notepad++ 다운로드(notepad-plus-plus.org/downloads/)
Downloads | Notepad++
notepad-plus-plus.org
- OllyDbg 1.1 다운로드 및 설정 후 IE11-Win7 Restart
5. 스냅샷 찍기