Malware Analysis Series

Deep technical malware analysis reports, reverse engineering tools, unpacked stages, and recreated TTPs with detections for infamous malware families.


Project maintained by shaddy43 Hosted on GitHub Pages — Theme by mattgraham
MalwareAnalysisSeries
Malware Analysis Series — reverse engineer, understand, detect, defend

MalwareAnalysisSeries


Welcome to Malware Analysis Series, a curated home for in-depth malware analysis reports and articles, reverse-engineering tools and scripts, unpacked malware stages, and extracted TTPs. This open-source project dissects infamous malware families to share the deep technical insight that advanced analysis, reverse engineering and attack simulations.

Purpose

Malware Analysis Series aims to be a comprehensive resource for cybersecurity enthusiasts, researchers, and professionals. By unpacking how prominent malware families really work and how their techniques can be both reproduced and detected, the goal is to empower the community with practical knowledge and tools that sharpen understanding of modern threats and strengthen our collective defenses.

Whoami

shaddy43 avatar

Shayan Ahmed Khan

@shaddy43

Threat Researcher · Detection & Response · Offensive Tooling

#turning coffee into commits

I reverse engineer malware, rebuild its techniques as working code, and turn what I learn into detections.

6 malware families 46 ATT&CK techniques 19 TTPs recreated 8 detection rules

Malware Analysis Repositories

Latest
Emotet thumbnail

Emotet

Full analysis of a post-takedown Emotet variant across 3 stages: the obfuscated VBS dropper, the fileless X.dll decrypted from a bitmap resource, and its ECDH/AES-encrypted HTTP C2. With IoCs and ATT&CK mapping.

28 October 2024 • 12 minute read

LoaderBankingModular
Xloader4.3 / Formbook Infostealer thumbnail

Xloader4.3 / Formbook Infostealer

Full analysis of XLoader 4.3 (formerly FormBook): a .NET dropper, three injected stages, CRC-32/BZIP2 API hashing, RC4-encrypted core functions and Lagos Island ntdll unhooking. TTPs recreated with buildable code.

23 January 2024 • 25 minute read

Infostealer
Ryuk Ransomware thumbnail

Ryuk Ransomware

Full analysis of Ryuk ransomware: a two-stage dropper, SeDebugPrivilege token manipulation, mass process injection and the HERMES-derived multi-threaded AES/RSA encryptor. Includes YARA rules and IoCs.

26 November 2023 • 10 minute read

Ransomware
NanoCore RAT 1.2.2.0 thumbnail

NanoCore RAT 1.2.2.0

Full analysis of NanoCore RAT 1.2.2.0: a four-stage unpacking chain with process hollowing, GUID-keyed Rijndael/DES config decryption, the recovered RAT configuration and the SurveillanceEx keylogging plugin.

21 September 2023 • 14 minute read

RAT
MedusaLocker Ransomware thumbnail

MedusaLocker Ransomware

Full analysis of MedusaLocker ransomware: CMSTPLUA COM UAC bypass, the MDSLK defacement marker, programmatic scheduled-task persistence and AES-256/RSA encryption. Every TTP ships code plus a detection rule.

21 August 2023 • 9 minute read

Ransomware
CrackedHaven thumbnail

CrackedHaven

Why cracked software is dangerous, and how to check it: BinDiff patch diffing to verify what a cracked Adobe Photoshop amtlib.dll really changed, then a demonstration of how easily arbitrary code hides in the same binary.

10 March 2022 • 10 minute read

CrackingReverse Engineering

No analyses match your filter.

Disclaimer

It's important to emphasize that MalwareAnalysisSeries is intended strictly for educational and research purposes. I do not condone or support any form of malicious activity. The tools, scripts, and analysis reports provided here are meant to foster learning, enhance cybersecurity knowledge, and contribute to the collective defense against cyber threats. Any misuse or illegitimate use of the content within this repository is strongly discouraged and goes against the principles of ethical cybersecurity practices.

Join me in this mission to dissect, understand, and combat malware. Together, we can make cyberspace a safer environment for all.

Certifications

Buy Me A Coffee