Agent skill

Analyzing Ransomware Payment Wallets

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund…

Apache-2.0Auto-check passedSecurity

Install Analyzing Ransomware Payment Wallets

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-ransomware-payment-wallets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills analyzing-ransomware-payment-wallets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/analyzing-ransomware-payment-wallets .claude/skills/analyzing-ransomware-payment-wallets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
analyzing-ransomware-payment-wallets
GitHub stars
34k
Token cost
~1.9k tokens
SKILL.md length
451 words
Files
4 (incl. scripts, references)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund…

  • Works in 5 steps: Extract Wallet Address from Ransom Note → Query Blockchain Explorer for… → Map Fund Flow and Identify Clusters → …
  • Tracing ransomware bitcoin payments
  • SKILL.md covers When to Use, Prerequisites, Workflow and Verification, plus 2 more sections
  • Runs Python scripts from its folder; reaches blockchain.info and walletexplorer.com

What it does

Analyzing Ransomware Payment Wallets is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments, performing cryptocurrency wallet forensics, or gathering blockchain threat intelligence on extortion payments.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/api-reference.md` and `scripts/agent.py`).

It sits in Security, covering Crypto and DeFi analysis and OSINT. It works with Bitcoin. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tracing ransomware bitcoin payments
  • Performing cryptocurrency wallet forensics
  • Gathering blockchain threat intelligence on extortion payments

Example prompts

  • “Use the analyzing-ransomware-payment-wallets skill to trace ransomware cryptocurrency payment flows using blockchain analysis tools such as…”
  • “/analyzing-ransomware-payment-wallets”

Requirements

  • Python 3

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Extract Wallet Address from Ransom Note
  2. Query Blockchain Explorer for Transaction History
  3. Map Fund Flow and Identify Clusters
  4. Cross-Reference with Known Wallet Databases
  5. Generate Attribution Report

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • blockchain.info
    • walletexplorer.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Analyzing Ransomware Payment Wallets loads about 1.9k tokens when it runs, and up to ~2.7k if it reads all its reference files. Until then it costs about 117 tokens; SKILL.md has 451 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 451 words, ~1,928 tokens.

Download SKILL.mdSave it as .claude/skills/analyzing-ransomware-payment-wallets/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
analyzing-ransomware-payment-wallets
description
Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution. Use when tracing ransomware bitcoin payments, performing cryptocurrency wallet forensics, or gathering blockchain threat intelligence on extortion payments.
domain
cybersecurity
subdomain
ransomware-defense
tags
ransomware, blockchain, cryptocurrency, forensics, threat-intelligence, bitcoin
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.DS-11, RS.MA-01, RC.RP-01, PR.IR-01
mitre_attack
T1657, T1486
mitre_f3.version
1.1
mitre_f3.tactics
monetization, stealth

Analyzing Ransomware Payment Wallets

When to Use

  • An organization has been hit by ransomware and the ransom note contains a Bitcoin or cryptocurrency wallet address that needs investigation
  • Law enforcement or incident responders need to trace where ransom payments flowed after the victim paid
  • Threat intelligence analysts are attributing ransomware campaigns by clustering payment infrastructure across incidents
  • Investigators need to determine if a ransomware group is reusing wallet infrastructure across multiple victims
  • Compliance or legal teams need evidence of fund flows for prosecution, sanctions enforcement, or insurance claims

Do not use this skill for live payment interception or to interact directly with ransomware operators. All analysis should be passive and read-only against public blockchain data.

Prerequisites

  • Python 3.8+ with requests, json, and hashlib libraries
  • Access to blockchain explorer APIs (blockchain.com, WalletExplorer.com, Blockstream.info)
  • Familiarity with Bitcoin transaction model (UTXOs, inputs, outputs, change addresses)
  • Understanding of common obfuscation techniques (mixers, tumblers, peel chains, cross-chain swaps)
  • Optional: Chainalysis Reactor license for enterprise-grade cluster analysis
  • Optional: OXT.me for advanced transaction graph visualization

Workflow

Step 1: Extract Wallet Address from Ransom Note

Parse the ransom note to identify the payment address(es):

Common address formats:
  Bitcoin (P2PKH):   1A1zP1eP5QGefi2DMPTfTL5SLmv7DivfNa  (starts with 1)
  Bitcoin (P2SH):    3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy  (starts with 3)
  Bitcoin (Bech32):  bc1qar0srrr7xfkvy5l643lydnw9re59gtzzwf5mdq (starts with bc1)
  Monero:            4... (95 characters, much harder to trace)
  Ethereum:          0x... (40 hex chars)
Step 2: Query Blockchain Explorer for Transaction History

Retrieve all transactions associated with the wallet:

python
import requests

def get_wallet_transactions(address):
    """Query blockchain.com API for address transactions."""
    url = f"https://blockchain.info/rawaddr/{address}"
    resp = requests.get(url, timeout=30)
    resp.raise_for_status()
    data = resp.json()
    return {
        "address": address,
        "n_tx": data.get("n_tx", 0),
        "total_received_satoshi": data.get("total_received", 0),
        "total_sent_satoshi": data.get("total_sent", 0),
        "final_balance_satoshi": data.get("final_balance", 0),
        "transactions": data.get("txs", []),
    }
Step 3: Map Fund Flow and Identify Clusters

Trace outputs from the ransom wallet to downstream addresses:

Fund Flow Analysis:
━━━━━━━━━━━━━━━━━━
Victim Payment ──► Ransom Wallet ──► Consolidation Wallet
                                  ├─► Mixer/Tumbler Service
                                  ├─► Exchange Deposit Address
                                  └─► Peel Chain (sequential small outputs)

Key indicators:
  - Consolidation: Multiple ransom payments aggregated into one wallet
  - Peel chains: Sequential transactions with diminishing outputs
  - Mixer usage: Funds sent to known mixer addresses (Wasabi, Samourai, ChipMixer)
  - Exchange cashout: Deposits to known exchange wallets (Binance, Kraken hot wallets)
Step 4: Cross-Reference with Known Wallet Databases

Check addresses against known ransomware infrastructure:

python
# Check WalletExplorer for entity identification
def check_wallet_explorer(address):
    url = f"https://www.walletexplorer.com/api/1/address?address={address}&caller=research"
    resp = requests.get(url, timeout=30)
    data = resp.json()
    return {
        "wallet_id": data.get("wallet_id"),
        "label": data.get("label", "Unknown"),
        "is_exchange": data.get("is_exchange", False),
    }
Step 5: Generate Attribution Report

Compile findings into a structured intelligence report:

RANSOMWARE WALLET ANALYSIS REPORT
====================================
Ransom Address:      bc1q...xyz
Family Attribution:  LockBit 3.0 (based on ransom note format)
Total Received:      4.25 BTC ($178,500 at time of payment)
Total Sent:          4.25 BTC (wallet fully drained)
Number of Payments:  3 (likely 3 separate victims)

FUND FLOW:
  Payment 1: 1.5 BTC → Consolidation wallet → Binance deposit
  Payment 2: 1.0 BTC → Wasabi Mixer → Unknown
  Payment 3: 1.75 BTC → Peel chain (12 hops) → OKX deposit

CLUSTER ANALYSIS:
  Related wallets: 47 addresses identified in same cluster
  Total cluster volume: 156.3 BTC ($6.5M USD)
  First activity: 2024-01-15
  Last activity: 2024-09-22

Verification

  • Confirm wallet address format is valid before querying APIs
  • Cross-reference transaction timestamps with known incident timelines
  • Validate cluster associations by checking common-input-ownership heuristic
  • Compare findings against OFAC SDN list for sanctioned addresses
  • Verify exchange attribution against multiple sources (WalletExplorer, OXT, Chainalysis)
Show full SKILL.md (166 more words)Show less

Key Concepts

TermDefinition
UTXOUnspent Transaction Output; the fundamental unit of Bitcoin that tracks ownership through a chain of transactions
Cluster AnalysisGrouping multiple Bitcoin addresses believed to be controlled by the same entity using common-input-ownership and change-address heuristics
Peel ChainA laundering pattern where funds are sent through many sequential transactions, each peeling off a small amount to a new address
CoinJoin/MixerPrivacy techniques that combine multiple users' transactions to obscure the link between sender and receiver
Common Input OwnershipHeuristic that assumes all inputs to a single transaction are controlled by the same entity

Tools & Systems

  • Chainalysis Reactor: Enterprise blockchain investigation platform with entity attribution and cross-chain tracing
  • WalletExplorer: Free tool that clusters Bitcoin addresses and labels known services (exchanges, mixers, markets)
  • OXT.me: Advanced Bitcoin transaction visualization with UTXO graph analysis
  • Blockstream.info: Open-source Bitcoin block explorer with full API access
  • blockchain.com API: Free API for querying Bitcoin address balances and transaction histories
  • OFAC SDN List: U.S. Treasury sanctioned address list for compliance checking

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in skills/analyzing-ransomware-payment-wallets of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • references/api-reference.md
  • scripts/agent.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Analyzing Ransomware Payment Wallets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Analyzing Ransomware Payment Wallets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Analyzing Ransomware Payment Wallets this skillmukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0
ApocdataApocData/ApocData-skill104—~1.9kAutomated safety check: PassApache-2.0
Okx Sentiment Trackerdex-original/okx-agent-trade-kit1101 repos~3.8kAutomated safety check: PassMIT
Academy Skillbinance/binance-skills-hub1.1k—~3.5kAutomated safety check: NotesNone
Alpha Vantageagent-skills-hub/agent-skills-hub1112 repos~1.6kAutomated safety check: PassMIT
Emblemai Crypto Walletsickn33/agentic-awesome-skills47k2 repos~669Automated safety check: PassMIT

Similar skills

  • Apocdata

    ApocData/ApocData-skill

    A-share data service with structured announcement parsing: every announcement carries an AI summary, category, importance level and sentiment, fully traceable to source.

    104 GitHub stars~1.9k tokensUpdated 24 days ago
    Business, Finance & HRAuto-check passed
  • Okx Sentiment Tracker

    dex-original/okx-agent-trade-kit

    A skill your agent uses when the user asks about: 'any crypto news', 'latest news', 'market update', 'daily briefing', 'BTC news', 'ETH news', 'news on SOL', 'search SEC ETF', 'regulation news'…

    110 GitHub starsUsed in 1 repo~3.8k tokens
    Business, Finance & HRAuto-check passed
  • Academy Skill

    binance/binance-skills-hub

    Retrieve Binance Academy's official educational content (Glossary, Courses, Learn & Earn, Articles) for AI chat.

    1.1k GitHub stars~3.5k tokensUpdated 28 days ago
    Business, Finance & HRAuto-check: notes
  • Alpha Vantage

    agent-skills-hub/agent-skills-hub

    Access real-time and historical stock market data, forex rates, cryptocurrency prices, commodities, economic indicators, and 50+ technical indicators via the Alpha Vantage API.

    111 GitHub starsUsed in 2 repos~1.6k tokens
    Business, Finance & HRAuto-check passed
  • Emblemai Crypto Wallet

    sickn33/agentic-awesome-skills

    Crypto wallet management across 7 blockchains via EmblemAI Agent Hustle API.

    47k GitHub starsUsed in 2 repos~669 tokens
    Business, Finance & HRAuto-check passed
  • Aggregating Crypto News

    jeremylongshore/tons-of-skills-marketplace

    Aggregate breaking cryptocurrency news from 50+ sources including CoinDesk, CoinTelegraph, The Block, and Decrypt.

    2.8k GitHub stars~1.2k tokensUpdated today
    Business, Finance & HRAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Analyzing Ransomware Payment Wallets

What does Analyzing Ransomware Payment Wallets do?

Traces ransomware cryptocurrency payment flows using blockchain analysis tools such as Chainalysis Reactor, WalletExplorer, and blockchain.com APIs, identifying wallet clusters and tracking fund…. Analyzing Ransomware Payment Wallets is an agent skill from mukul975/Anthropic-Cybersecurity-Skills.com APIs, identifying wallet clusters and tracking fund movement through mixers and exchanges to support law enforcement attribution.

When should I use Analyzing Ransomware Payment Wallets?

Analyzing Ransomware Payment Wallets fits situations like: tracing ransomware bitcoin payments; performing cryptocurrency wallet forensics; gathering blockchain threat intelligence on extortion payments.

How do I install Analyzing Ransomware Payment Wallets in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-ransomware-payment-wallets -a claude-code`. Or copy the skill folder (skills/analyzing-ransomware-payment-wallets in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/analyzing-ransomware-payment-wallets in your project. Claude Code loads it when a task matches its description.

How do I install Analyzing Ransomware Payment Wallets in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-ransomware-payment-wallets -a codex`. Or copy the skill folder (skills/analyzing-ransomware-payment-wallets in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/analyzing-ransomware-payment-wallets in your project. Codex loads it when a task matches its description.

Can I use Analyzing Ransomware Payment Wallets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill analyzing-ransomware-payment-wallets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/analyzing-ransomware-payment-wallets, .gemini/skills/analyzing-ransomware-payment-wallets, .github/skills/analyzing-ransomware-payment-wallets and .opencode/skills/analyzing-ransomware-payment-wallets in your project.

What does Analyzing Ransomware Payment Wallets need to run?

Going by SKILL.md and its folder, Analyzing Ransomware Payment Wallets needs Python for the scripts in its folder. Our summary lists: Python 3.

Does Analyzing Ransomware Payment Wallets access the network?

SKILL.md names 2 domains. In commands or code: blockchain.info and walletexplorer.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Analyzing Ransomware Payment Wallets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Analyzing Ransomware Payment Wallets use?

Analyzing Ransomware Payment Wallets is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Analyzing Ransomware Payment Wallets use?

About 1.9k tokens (SKILL.md is roughly 7.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 765 tokens, read only when the agent opens those files.

What are the alternatives to Analyzing Ransomware Payment Wallets?

Skills that share tags, products or a category with Analyzing Ransomware Payment Wallets: Apocdata (ApocData/ApocData-skill, 104 stars), Okx Sentiment Tracker (dex-original/okx-agent-trade-kit, 110 stars), Academy Skill (binance/binance-skills-hub, 1.1k stars) and Alpha Vantage (agent-skills-hub/agent-skills-hub, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Analyzing Ransomware Payment Wallets?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,993 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.