Elastic Security Labs - nightMARE
This directory contains the nightMARE (Malware Analysis & Reverse Engineering) library. nightMARE is a central module that will allow for an efficient and logical approach to automating various reverse engineering functions.
The nightMARE library is born from the need to refactor our code base into reusable bricks. We want to concentrate logics and dependencies into a single library in order to speed up tool developement for members of the Elastic Security Labs team.
By open sourcing our library to the community we hope that it'll contribute to our battle against threats.
Please note that this library is still young and under developement. Pull requests are welcome.
Example usage: https://www.elastic.co/security-labs/unpacking-icedid
Malware modules
| Module | Description |
|---|---|
nightmare.malware.blister |
Implement BLISTER algorithms |
nightmare.malware.ghostpulse |
Implement GHOSTPULSE algorithms |
nightmare.malware.deprecated.icedid |
Implement ICEDID algorithms (deprecated) |
nightmare.malware.latrodectus |
Implement LATRODECTUS algorithms |
nightmare.malware.lobshot |
Implement LOBSHOT algorithms |
nightmare.malware.lumma |
Implement LUMMA algorithms |
nightmare.malware.netwire |
Implement NETWIRE algorithms |
nightmare.malware.redlinestealer |
Implement REDLINESTEALER algorithms |
nightmare.malware.revstealer |
Implement REVSTEALER algorithms |
nightmare.malware.remcos |
Implement REMCOS algorithms |
nightmare.malware.smokeloader |
Implement SMOKELOADER algorithms |
nightmare.malware.stealc |
Implement STEALC algorithms |
nightmare.malware.telepuz |
Implement TELEPUZ algorithms |
nightmare.malware.vidar |
Implement VIDAR algorithms |
nightmare.malware.warmcookie |
Implement WARMCOOKIE algorithms |
nightmare.malware.xorddos |
Implement XORDDOS algorithms |
Requirements
- Python >=
3.10is required. - Rizin v0.8.1 must be installed and available in the system's PATH environment variable.
Install
pip install nightmare-lib
or
git clone https://github.com/elastic/nightMARE
python -m pip install ./nightMARE
Test
Download the corpus from here and place the archive in the tests folder to run the tests. Warning: The archive contains malware; testing should be performed in a virtual machine for safety.
py.test
How to Contribute
Contributors must sign a Contributor License Agreement before contributing code to any Elastic repositories.
License
nightMARE uses the Elastic License version 2.
Metadata
Release files for nightMARE-lib 0.19.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| nightmare_lib-0.19.0.tar.gz | 63.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| nightmare_lib-0.19.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 150.8 kB
Release files / nightmare_lib-0.19.0.tar.gz
| Download URL | nightmare_lib-0.19.0.tar.gz |
|---|---|
| Size | 63.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0b0b9837d2f5434ed7f6e6e86ea33d9b570aa8fdc8df9d39f3c1d4717f6003d9
|
|
BLAKE2b-256 checksum How to use checksums |
f040ee625aa9229f82492112655651b6c14b5909bc75d6dbe149df66bac34c65
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|
Release files / nightmare_lib-0.19.0-py3-none-any.whl
| Download URL | nightmare_lib-0.19.0-py3-none-any.whl |
|---|---|
| Size | 87.1 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
df8e22a1037551bc0d8592ffafc56d609f2acf9e5b739c58a4be3d35fc019007
|
|
BLAKE2b-256 checksum How to use checksums |
16084a4306b3e7e9a89acf4e3ba64eac0b368a56647d64a47d4bcdd2d7e5df25
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/7.0.0 CPython/3.14.6
|