IS 3523
Malware Analysis
The CISO has informed us that one of our client's machines may have been compromised by some ferocious malware. They want us to investigate the compromised box to determine what might have happened. The machine is located at their super secret engineering facility, but we are fortunate to have a virtual image of the compromised FTP Server on the SimSpace range. You can conduct root cause analysis of the FTP server using any tools you find useful. If you do well, you may even get a permanent slot on the incident response team.
Accessing the Compromised VM
Log in to your SimSpace account. Once logged in, access the Network Tab and find an available win-Xp-xx VM. Click on the win XP-XX VM and select the range. Open the win-Xp XX VM by selecting Open Console. Record what you see. At this point, treat it as the "suspect machine" and analyze the FTP Server. Once this is done, log in to another VM on the range you wish to use. In the terminal window, try pinging the win-Xp-xx VM. You can locate the IP address under Visualizations on the left-hand side of the screen. If you can ping your win-Xp-XX VM, you are ready to go.