Threat Theaters

🦠 Malware theater

Aggregates and analyzes malware families — loaders, stealers, RATs, and botnets — powering intrusions across the threat landscape. Drives detection engineering and IOC production.

Live indicators

0
in this theater

High severity

0
score ≥ 0.75 (top 60)

Actors tracked

2
documented

Mapped sources

0
in catalog

🏹 Threat Actors

TA505Wizard Spider

🧭 Intelligence disciplines

CYBINT →OSINT →MASINT →

📜 Malware Playbook

  1. Pull fresh samples and IOCs from MalwareBazaar, ThreatFox, and sandbox telemetry.
  2. Detonate samples in a sandbox and extract config, C2, mutexes, and dropped payloads.
  3. Classify the family via YARA, imphash, and behavioral signatures, mapping capabilities to ATT&CK.
  4. Link the sample to a family or operator through code reuse, packer, and C2 conventions.
  5. Publish IOCs, detection rules, and a capability summary to defenders.
  6. Update sinkholes and blocklists and hunt for the family across the estate.

⚡ AI Skills & Automation

🤖 Copilot brief⚡ AI SkillsResolveEnrichAuto-CollectHuntReportExport

Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).

🔄 Data Feeds & Datasets

FeedCategoryFormatStatus
DigitalSide latest URLsMalware URLstextenabled
MalwareBazaar Full (hash)Malware Hashescsvenabled
ThreatFox FullMalware Attributioncsvenabled
URLhaus text (online)Malware URLstextenabled
Maltrail malware domainsMalware Domainstextenabled
Maltrail bad_ipMalware IPstextenabled
MISP Galaxy Tools/MalwareMalware Familiesjsonenabled
Malpedia families (key)Malware Familiesjsonenabled
URLhaus FullMalware URLscsvenabled
URLhaus (tags/family)Malware URLscsvenabled
MalwareBazaar Recent (hash→family)Malware Attributioncsvenabled
ThreatFox SHA256Malware Hashestextenabled
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php