
Analyzing Ransomware Payment Wallets
FreeTrace ransomware payments using blockchain analysis.
Free · Opens the source repo
What Analyzing Ransomware Payment Wallets does
This skill provides a framework for tracing cryptocurrency payment flows associated with ransomware attacks. By leveraging blockchain analysis tools, it enables users to identify wallet clusters and track the movement of funds through mixers and exchanges. This is crucial for law enforcement and incident responders who need to attribute payments to specific ransomware groups and understand the financial trails left behind after a ransom is paid. The skill is particularly useful for threat intelligence analysts and investigators looking to build a comprehensive picture of ransomware operations.
The workflow begins by extracting wallet addresses from ransom notes, followed by querying blockchain explorer APIs to retrieve transaction histories. Users can then map fund flows and identify clusters of related wallets, which can indicate whether a ransomware group is reusing infrastructure across multiple incidents. The skill also allows for cross-referencing with known ransomware infrastructure, providing additional context and insights into the payment flows. This structured approach culminates in the generation of detailed attribution reports that can support legal and compliance efforts.
Designed for cybersecurity professionals, this skill is especially valuable for those involved in incident response, forensic analysis, and threat intelligence. It requires a solid understanding of the Bitcoin transaction model and common obfuscation techniques used by ransomware operators. While it does not allow for live payment interception, it serves as a powerful tool for passive analysis of public blockchain data, enabling users to gather actionable intelligence without direct interaction with malicious actors.
When to use it
Use this skill when investigating ransomware incidents involving cryptocurrency payments, especially when you need to analyze payment flows and identify wallet clusters.
When not to use it
Do not use this skill for real-time payment interception or direct engagement with ransomware operators, as it is designed for passive analysis only.
What you can build with it
Investigating a Ransomware Attack
A cybersecurity team uses this skill to trace the Bitcoin wallet from a ransom note, identifying fund movements and potential clusters of related wallets.
Supporting Law Enforcement
Law enforcement agencies utilize the skill to track ransom payments after a victim has paid, gathering evidence for prosecution.
Threat Intelligence Analysis
Threat analysts employ this skill to attribute ransomware campaigns by clustering payment infrastructure across multiple incidents.
How to install Analyzing Ransomware Payment Wallets
View source1. Install with the skills CLI
npx skills add mukul975/anthropic-cybersecurity-skills/analyzing-ransomware-payment-wallets --agent claude-code2. Or install it manually
Download the skill folder and drop it into ~/.claude/skills/ for all projects, or .claude/skills/ to scope it to one repo. Restart Claude Code so it picks up the new skill.
Anthropic's agentic coding CLI, and the reference implementation of Agent Skills. Drop a skill folder into ~/.claude/skills and Claude Code loads it automatically whenever a task matches the skill's description. Claude Code docs
Inside SKILL.md
Written by mukul975Analyzing Ransomware Payment Wallets
When to Use
- An organization has been hit by ransomware and the ransom note contains a Bitcoin or cryptocurrency wallet address that needs investigation
- Law enforcement or incident responders need to trace where ransom payments flowed after the victim paid
- Threat intelligence analysts are attributing ransomware campaigns by clustering payment infrastructure across incidents
- Investigators need to determine if a ransomware group is reusing wallet infrastructure across multiple victims
- Compliance or legal teams need evidence of fund flows for prosecution, sanctions enforcement, or insurance claims
Do not use this skill for live payment interception or to interact directly with ransomware operators. All analysis should be passive and read-only against public blockchain data.
Prerequisites
- Python 3.8+ with
requests,json, andhashliblibraries - Access to blockchain explorer APIs (blockchain.com, WalletExplorer.com, Blockstream.info)
- Familiarity with Bitcoin transaction model (UTXOs, inputs, outputs, change addresses)
- Understanding of common obfuscation techniques (mixers, tumblers, peel chains, cross-chain swaps)
- Optional: Chainalysis Reactor license for enterprise-grade cluster analysis
- Optional: OXT.me for advanced transaction graph visualization
Workflow
Step 1: Extract Wallet Address from Ransom Note
Parse the ransom note to identify the payment address(es):
Common address formats:
Bitcoin (P2PKH): 1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa (starts with 1)
Bitcoin (P2SH): 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy (starts with 3)
Bitcoin (Bech32): bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq (starts with bc1)
Monero: 4... (95 characters, much harder to trace)
Ethereum: 0x... (40 hex chars)
Step 2: Query Blockchain Explorer for Transaction History
Retrieve all transactions associated with the wallet:
import requests
def get_wallet_transactions(address):
"""Query blockchain.com API for address transactions."""
url = f"https://blockchain.info/rawaddr/{address}"
resp = requests.get(url, timeout=30)
resp.raise_for_status()
data = resp.json()
return {
"address": address,
"n_tx": data.get("n_tx", 0),
"total_received_satoshi": data.get("total_received", 0),
"total_sent_satoshi": data.get("total_sent", 0),
"final_balance_satoshi": data.get("final_balance", 0),
"transactions": data.get("txs", []),
}
Step 3: Map Fund Flow and Identify Clusters
Trace outputs from the ransom wallet to downstream addresses:
Fund Flow Analysis:
━━━━━━━━━━━━━━━━━━
Victim Payment ──► Ransom Wallet ──► Consolidation Wallet
├─► Mixer/Tumbler Service
├─► Exchange Deposit Address
└─► Peel Chain (sequential small outputs)
Key indicators:
- Consolidation: Multiple ransom payments aggregated into one wallet
- Peel chains: Sequential transactions with diminishing outputs
- Mixer usage: Funds sent to known mixer addresses (Wasabi, Samourai, ChipMixer)
- Exchange cashout: Deposits to known exchange wallets (Binance, Kraken hot wallets)
Step 4: Cross-Reference with Known Wallet Databases
Check addresses against known ransomware infrastructure:
# Check WalletExplorer for entity identification
def check_wallet_explorer(address):
url = f"https://www.walletexplorer.com/api/1/address?address={address}&caller=research"
resp = requests.get(url, timeout=30)
data = resp.json()
return {
"wallet_id": data.get("wallet_id"),
"label": data.get("label", "Unknown"),
"is_exchange": data.get("is_exchange", False),
}
Step 5: Generate Attribution Report
Compile findings into a structured intelligence report:
RANSOMWARE WALLET ANALYSIS REPORT
====================================
Ransom Address: bc1q...xyz
Family Attribution: LockBit 3.0 (based on ransom note format)
Total Received: 4.25 BTC ($178,500 at time of payment)
Total Sent: 4.25 BTC (wallet fully drained)
Number of Payments: 3 (likely 3 separate victims)
FUND FLOW:
Payment 1: 1.5 BTC → Consolidation wallet → Binance deposit
Payment 2: 1.0 BTC → Wasabi Mixer → Unknown
Payment 3: 1.75 BTC → Peel chain (12 hops) → OKX deposit
CLUSTER ANALYSIS:
Related wallets: 47 addresses identified in same cluster
Total cluster volume: 156.3 BTC ($6.5M USD)
First activity: 2024-01-15
Last activity: 2024-09-22
Verification
- Confirm wallet address format is valid before querying APIs
- Cross-reference transaction timestamps with known incident timelines
- Validate cluster associations by checking common-input-ownership heuristic
- Compare findings against OFAC SDN list for sanctioned addresses
- Verify exchange attribution against multiple sources (WalletExplorer, OXT, Chainalysis)
Key Concepts
| Term | Definition |
|---|---|
| UTXO | Unspent Transaction Output; the fundamental unit of Bitcoin that tracks ownership through a chain of transactions |
| Cluster Analysis | Grouping multiple Bitcoin addresses believed to be controlled by the same entity using common-input-ownership and change-address heuristics |
| Peel Chain | A laundering pattern where funds are sent through many sequential transactions, each peeling off a small amount to a new address |
| CoinJoin/Mixer | Privacy techniques that combine multiple users' transactions to obscure the link between sender and receiver |
| Common Input Ownership | Heuristic that assumes all inputs to a single transaction are controlled by the same entity |
Tools & Systems
- Chainalysis Reactor: Enterprise blockchain investigation platform with entity attribution and cross-chain tracing
- WalletExplorer: Free tool that clusters Bitcoin addresses and labels known services (exchanges, mixers, markets)
- OXT.me: Advanced Bitcoin transaction visualization with UTXO graph analysis
- Blockstream.info: Open-source Bitcoin block explorer with full API access
- blockchain.com API: Free API for querying Bitcoin address balances and transaction histories
- OFAC SDN List: U.S. Treasury sanctioned address list for compliance checking
Frequently asked questions about Analyzing Ransomware Payment Wallets
Similar skills
Asset Criticality Scoring for Vulns
Prioritize vulnerabilities based on asset criticality.
Performing Alert Triage with Elastic SIEM
Streamline alert triage processes in Elastic Security.
Active Directory Vulnerability Assessment
Secure your Active Directory with comprehensive assessments.
Active Directory Investigation
Streamline your Active Directory compromise investigations.
Parsing Artifacts with Eric Zimmerman Tools
Efficiently parse Windows forensic artifacts for analysis.
Operationalizing MISP Threat Feeds
Enhance threat detection with curated MISP feeds.
