This document describes an automated method for on-execute malware testing using Oracle VM VirtualBox. It discusses copying malware into a guest VM, executing it, analyzing the results, reverting the guest to its original state, and then repeating the process. Tools like VBoxManage are used to automate functions like file copying, program execution, snapshotting and reverting. The FFRI AutoMonkey scripts automate the end-to-end process using these VirtualBox APIs. Performance when testing 20,000 samples showed a throughput of around 9 malwares per minute under the described hardware configuration.
Related topics: