Simple high-interactive client honeypot for traffic analysis of Drive-by Download
- Windows
- Host
- Guest
- Windows
- Virtual Box
- OpenVPN
- Server
- Client Software
- Wireshark
- Fiddler
- Git
-
Setup OpenVPN Server
-
Install Virtual Box on Host
Please set PATH so thatVBoxManage.exe
can be used -
Install Git for Windows on Host
Create repository to store the data
Repository's name is "starc.log
"
Please also set ssh key
Please clone directly below the drive (C:\starc.log
) -
Install Windows on VM
VM's name is "starc
"
No Login Password
No UAC
Create very vulnerable VM -
Install OpenVPN Client on VM
Be sure to connect confirmation!
Please put a config file named vpn.ovpn underC:\starc.log\config
on Host -
Install Wireshark on VM
Please set PATH so thattshark.exe
can be used -
Install Fiddler on VM
Please set PATH so thatfiddler.exe
&execaction.exe
can be used
Please make the appropriate settings,Decrypt HTTPS traffic
-
Make initial setting of Internet Explorer on VM
-
Delete all files under
%temp%
as much as possible on VM -
Set
starc.client.exe
to startup on VM -
Change VM settings
Delete clipboard share setting
Delete drag and drop setting
Delete share folder setting -
Create snapshot of VM
Snapshot's name is "setuped
"
$ starc.exe [URL]