Malwarebox public intelligence surface

IIM Feeds for adversary infrastructure chains.

Published IIM chains from MANTIS, shaped for humans first: browse actor infrastructure, compare role flows, open evidence, and export the canonical JSON when you need the raw model.

community intake

Submit sourced IIM chains for review

local storage, validator, anti-spam cap and contribution board

Analysts can paste a chain directly into the public surface, pass validation and store it as a dated local JSON file for manual Malwarebox review.

source link required 1000/day global cap duplicate filter captcha local
confirmed32
likely7
tentative0
needs review12

IIM Atlas Board

Role matrix of the published feed

10 chains per page, each row opens the full chain view
chain actor conf entryredirectorstagingpayloadc2 edges published
seqrite.2026.operation-xenofiscal-sidecopy-xenorat Operation XENOFISCAL: Pashto LNK to compromised Afghan delivery host and XenoRAT C2 SideCopy confirmed 2 spearphishing ZIP archive targeting... 13 mshta.exe LOLBIN execution of remot... 3 ayhui.vmxx reconstructed shellcode ... 1 185.235.137.106 19e / 18r 2026-05-29 20:01:27
Showing 11 of 1 matching chains
Reset
Page 1 of 1. Showing 11 of 1 matching chains, 39 total.

seqrite.2026.operation-xenofiscal-sidecopy-xenorat

Operation XENOFISCAL: Pashto LNK to compromised Afghan delivery host and XenoRAT C2

confirmed

IIM chain for Seqrite Operation XENOFISCAL, published 2026-05-29. The campaign targets Afghanistan Ministry of Finance provincial officials with a spearphishing ZIP containing a Pashto malicious LNK. The LNK launches mshta.exe and retrieves obfuscated HTA/JavaScript from compromised Afghan education domain abimj.edu.af/index.php. The script reconstructs an in-memory .NET loader, downloads an Afghan Ministry of Finance decoy PDF, persists zuidrt.hta, retrieves additional payload blobs from /institute/10/ or /institute/7/, reconstructs shellcode, loads XenoRAT, and connects to hardcoded C2 IP 185.235.137.106 hosted on AS59711/HZ Hosting infrastructure.

entry entry staging staging staging staging staging
SideCopy 19 entities 18 relations 2026-05-29 20:01:27
IIM-T003 IIM-T004 IIM-T021 IIM-T024
Open chain analysis