VMware Communities
vmwareiscool1
Contributor
Contributor

Virus testing - how do I get my VM off of my ISP network (spectrum)

So, today I thought about trying some viruses on a VM. I remembered a website that I can get a lot of viruses from, but when I went to a virus link my ISP blocked it. Please help me get my VM off of my ISP network.

0 Kudos
15 Replies
scott28tt
VMware Employee
VMware Employee

How is the VM network connection configured?

 


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
0 Kudos
vmwareiscool1
Contributor
Contributor

It's on vmxnet3 right now

0 Kudos
scott28tt
VMware Employee
VMware Employee

Not what I meant - Bridged, NAT, custom?

 


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
0 Kudos
vmwareiscool1
Contributor
Contributor

Custom

0 Kudos
scott28tt
VMware Employee
VMware Employee

And now more information on the VMnet configuration…?

The more you share, the more help you can potentially receive…

 


-------------------------------------------------------------------------------------------------------------------------------------------------------------

Although I am a VMware employee I contribute to VMware Communities voluntarily (ie. not in any official capacity)
VMware Training & Certification blog
0 Kudos
louyo
Virtuoso
Virtuoso

you might download the eicar.txt file, that is a known test file for testing and most ISP's let it download. I use it for  testing. 

 

0 Kudos
vmwareiscool1
Contributor
Contributor

Can you send me the download?

0 Kudos
Technogeezer
Immortal
Immortal


Some unsolicited advice from a from a former certified CISSP

A) unless you know what you’re doing, don’t simply decide one day to “try some viruses”. Playing around with real viruses is like playing with fire. Do some research on the Morris worm of 1988 or Stuxnet to get an idea of what could go wrong  

B) Ideally to prevent contamination of the host, you’d run your experiments on dedicated hardware on its own network. 

C) if you insist on playing in a VM, the VM has to be as isolated as possible so that you do not cross-contaminate the host. That means turning off drag/drop, copy/paste and shared folders at an absolute minimum. You also would want to keep networking to NAT or ideally host-only with the host not having an IP address on the custom network. Even if you do these things you need to be aware that there may be vulnerabities in the hypervisor that could allow viruses to spread to the host.

D) in the interest of safety should anything go horribly wrong, back up every host on your network before doing anything and air-gap it so it can’t be contaminated. A make sure you know how to recover everything should you have to restore any system from bare metal. And make sure anything on your network is running a good, up to date  AV product  

E) If your ISP is blocking sites that provide viruses there is nothing you can do to get around that in Workstation or your host system. You’d have to resort to using another network provider that doesn’t block or maybe a VPN. But there’s no guarantee that a VPN won’t block those sites as well.

F)  To find the EICAR test file, you could do a web search for it, That would get you here https://www.eicar.org/download-anti-malware-testfile/

The EICAR test file is the safest method because it is not a real virus, but will trigger a response from AV scanners as if it was. Since it’s benign, it doesn’t require the precautions of A through E above. 

- Paul (Technogeezer)
Editor of the Unofficial Fusion Companion Guides
0 Kudos
a_p_
Leadership
Leadership

See https://www.eicar.org/download-anti-malware-testfile/ for test files, or even the test pattern that you can use to try, and save it in a simple text file.

André

0 Kudos
vmwareiscool1
Contributor
Contributor

I tried downloading it on my host, and it randomly got canceled

(sorry, i forgot about this post and didn't reply until 2023 lol)

0 Kudos
a_p_
Leadership
Leadership

LOL. No problem, I will respond next year 😉

Did you try to copy the eciar test string, and try to save it in a text.file yet?

André

0 Kudos
vmwareiscool1
Contributor
Contributor

If I can, i'll upload a video of how I did it

sadly, it didn't do the glitch

edit: I can! I uploaded it below

edit 2: i forgot to blur my downloads let me edit it rq

edit 3: heres the blurred version below

0 Kudos
a_p_
Leadership
Leadership

Downloads are usually blocked by an A/V.
Again, what if you copy the string X5... and paste it into a new text file on your PC?

André

0 Kudos
vmwareiscool1
Contributor
Contributor

Let me try.

edit: I did it and edited the video.

in summary, nothing wow even though i have malwarebytes

0 Kudos
vmwareiscool1
Contributor
Contributor

basically yeah i was playing roblox and malwarebytes scanned automatically and found my eicar.txt file as a virus

0 Kudos