Cover image for project: Malware Sandbox & Deobfuscator IN PROGRESS

Technical summary

Sterile detonation of PHP, JS and Python snippets with recursive in-memory deobfuscation (up to 10 layers). Shannon entropy (0–8.0), IOC extractor (IPs, URLs, dangerous functions), heuristic analysis with risk score and threat family classification (WSO, c99, r57, b374k, Weevely). MITRE ATT&CK mapping (T1027.002, T1059, T1105). AI triage (OpenRouter/Gemini/OpenAI). Intel Hub enricher (priority 45). Rose 4-tab UI with i18n.

Executed scope

  • plugin.php (53 lines): "Malware Sandbox" tab under "Security & OSINT" with shield icon, doc, Intel Hub enricher (type hash/md5/sha256, priority 45), 7 API actions (msandbox_detonate, msandbox_history, msandbox_get, msandbox_delete, msandbox_iocs, msandbox_config_get, msandbox_config_save).
  • backend.php (607 lines): lazy nx_malware_detonations and nx_malware_config table install, Shannon entropy calculation, recursive PHP deobfuscator (6 methods: eval+gzinflate+base64, eval+base64, eval+rot13+base64, chr() sequences, hex strings, concatenations), IOC extractor (IPs, URLs, dangerous functions, paths), heuristic analysis with webshell signature detection, MITRE ATT&CK mapping, AI triage via nx_ai_query(), detonation CRUD, aggregated IOC listing, Intel Hub enricher.
  • tab.php (561 lines): Alpine.js 4-tab UI (Detonator & Deobfuscator, History, Extracted IOCs, Configuration), rose theme, code editor with file drag-and-drop, report with verdict/score/entropy, IOC badges, MITRE ATT&CK tags, side-by-side original vs deobfuscated comparison, AI provider and memory limit configuration, i18n via t().
  • lang.json (256 lines): PT/EN translations for all UI keys.
  • fastr.json: 2 slash commands — /detonate <code>, /sandbox-history.
  • doc.md (38 lines): author's technical documentation (PT).
  • icon.svg: shield brand icon.

GitHub progress (issues)

Real-time panel with latest repository issues.

abertas (amostra): -- fechadas (amostra): -- base: -- ultimas issues

carregando andamento...

Real results

Sterile web malware detonation with recursive in-memory deobfuscation (base64, gzinflate, rot13, chr, hex), Shannon entropy calculation, IOC extraction, MITRE ATT&CK mapping, heuristic threat family classification (WSO, c99, r57, b374k, Weevely) and AI triage — all in a rose 4-tab UI with full i18n.

Architecture and organization

Execution and operations

The project follows reproducible execution flow with technical validation in production-like environments.

Screenshots

Talk about this project

Apply this implementation pattern in your environment and accelerate delivery with technical consistency.