Malware Analysis Series

Deep technical malware analysis reports, reverse engineering tools, unpacked stages, and recreated TTPs with detections for infamous malware families.


Project maintained by shaddy43 Hosted on GitHub Pages — Theme by mattgraham

MITRE ATT&CK Coverage

Every technique identified across the analyses in this project, mapped to the MITRE ATT&CK framework and grouped by tactic. 46 techniques across 5 malware families — click any family to jump to the analysis where it is described in detail.

Family Type Techniques Analysis
Emotet Loader / banking trojan 16 Read
XLoader 4.3 Infostealer / form grabber 16 Read
NanoCore 1.2.2.0 Remote access trojan 17 Read
Ryuk Ransomware 11 Read
MedusaLocker Ransomware 9 Read

CrackedHaven is a software-piracy awareness case study rather than a malware analysis, so it carries no ATT&CK mapping.


Initial Access

Technique ID Families
Phishing: Spearphishing Attachment T1566.001 Emotet

Execution

Technique ID Families
Command and Scripting Interpreter: Visual Basic T1059.005 Emotet

Persistence

Technique ID Families
Boot or Logon Autostart Execution: Registry Run Keys T1547.001 NanoCore, Ryuk, XLoader
Scheduled Task/Job: Scheduled Task T1053.005 MedusaLocker, NanoCore

Privilege Escalation

Technique ID Families
Abuse Elevation Control Mechanism T1548 XLoader
Abuse Elevation Control Mechanism: Bypass User Account Control T1548.002 MedusaLocker
Access Token Manipulation T1134 Ryuk

Defense Evasion

Technique ID Families
Obfuscated Files or Information T1027 Emotet, Ryuk
Obfuscated Files or Information: Software Packing T1027.002 NanoCore, XLoader
Obfuscated Files or Information: Dynamic API Resolution T1027.007 Emotet, NanoCore, Ryuk
Obfuscated Files or Information: Encrypted/Encoded File T1027.013 XLoader
Deobfuscate/Decode Files or Information T1140 Emotet
Reflective Code Loading T1620 Emotet, XLoader
Process Injection: Portable Executable Injection T1055.002 Ryuk
Process Injection: Process Hollowing T1055.012 NanoCore, XLoader
Impair Defenses: Disable or Modify Tools T1562.001 MedusaLocker, NanoCore, XLoader
Indicator Removal: File Deletion T1070.004 Emotet, Ryuk, XLoader
Subvert Trust Controls: Mark-of-the-Web Bypass T1553.005 Emotet, NanoCore
System Binary Proxy Execution: Regsvr32 T1218.010 Emotet
System Binary Proxy Execution: Rundll32 T1218.011 Emotet
Masquerading: Masquerade Task or Service T1036.004 NanoCore
Masquerading: Match Legitimate Name or Location T1036.005 Emotet
Hide Artifacts: Hidden Window T1564.003 NanoCore
Hide Artifacts: Resource Forking T1564.009 NanoCore
File and Directory Permissions Modification: Windows T1222.001 NanoCore
Virtualization/Sandbox Evasion T1497 XLoader

Credential Access

Technique ID Families
Credentials from Password Stores: Web Browsers T1555.003 XLoader
Input Capture T1056 XLoader
Input Capture: Keylogging T1056.001 NanoCore

Discovery

Technique ID Families
Process Discovery T1057 Ryuk, XLoader
System Information Discovery T1082 Emotet, XLoader
Network Share Discovery T1135 MedusaLocker, Ryuk

Lateral Movement

Technique ID Families
Remote Services: SMB/Windows Admin Shares T1021.002 MedusaLocker

Collection

Technique ID Families
Clipboard Data T1115 NanoCore, XLoader
Data from Local System T1005 NanoCore
Automated Collection T1119 NanoCore

Command and Control

Technique ID Families
Application Layer Protocol: Web Protocols T1071.001 Emotet, XLoader
Non-Application Layer Protocol T1095 NanoCore
Encrypted Channel: Asymmetric Cryptography T1573.002 Emotet
Data Encoding: Standard Encoding T1132.001 Emotet
Ingress Tool Transfer T1105 Emotet

Exfiltration

Technique ID Families
Exfiltration Over C2 Channel T1041 NanoCore, XLoader

Impact

Technique ID Families
Data Encrypted for Impact T1486 MedusaLocker, Ryuk
Service Stop T1489 MedusaLocker, Ryuk
Inhibit System Recovery T1490 MedusaLocker, Ryuk
Defacement: Internal Defacement T1491.001 MedusaLocker

Recreated TTPs

Techniques that ship with buildable source code, and where available a detection rule or query. Links point to the write-up first, then the code.

MedusaLocker

Every recreated technique here has an accompanying detection page with Sysmon, Defender and audit-log screenshots.

Technique ID Write-up · Detection · Code
Scheduled Task/Job: Scheduled Task T1053.005 Write-up · Detection · Code
Impair Defenses: Disable UAC T1562.001 Write-up · Detection · Code
Impair Defenses: Disable UAC Prompt T1562.001 Write-up · Detection · Code
Data Encrypted for Impact T1486 Write-up · Detection · Code
Impair Defenses: Terminate Processes T1562.001 Write-up · Detection · Code
Service Stop T1489 Write-up · Detection · Code
Inhibit System Recovery T1490 Write-up · Detection · Code
Network Share Discovery T1135 Write-up · Detection · Code

NanoCore

Technique ID Write-up · Code
Input Capture: Keylogging T1056.001 Write-up · Code
Scheduled Task/Job: Scheduled Task T1053.005 Write-up · Code
Boot or Logon Autostart: Registry Run Keys T1547.001 Write-up · Code
Clipboard Data T1115 Write-up · Code
Data from Local System (DNS cache) T1005 Write-up · Code
Impair Defenses: Disable or Modify Tools T1562.001 Write-up · Code
Subvert Trust Controls: Mark-of-the-Web Bypass T1553.005 Write-up · Code
Process Hollowing · Software Packing T1055.012 · T1027.002 Write-up · Code

XLoader

Technique ID Write-up · Code
Lagos Island ntdll unhooking T1562.001 Write-up · Code
Encrypted .text / memory patch T1027.013 Write-up · Code

Ryuk

Technique ID Write-up · Code
Data Encrypted for Impact T1486 Write-up · Code

Emotet

Candidate techniques are identified but not yet implemented — see the planned TTPs. Contributions welcome via CONTRIBUTING.md.


Notes on the mapping

← Back to all analyses