Orca's first test: two malware samples
Malware analysisGuideSample
The test
This is the first real cyber-forensics run of the local OrcaSAQ-2 Cyber stack — the uncensored Qwen3.8-27B twin documented on the OrcaSAQ-2 Cyber and DFlash2 page.
| Dimension | Value |
|---|---|
| Model | OrcaSAQ-2-Cyber-27B-Uncensored (abliterated Qwen3.8-27B) |
| Harness | DeepSeek agent harness, xhigh reasoning effort |
| Prompt | Plain language: "find out if these are malware and find IOCs and other useful information worthy of a report" |
| Input | Two executables in a folder, no hints, no labels |
| Output | A complete two-sample analysis with verdicts, kill chain, IOC tables and remediation |
No signatures, no sandbox detonation, no prior labels. The model worked from first principles: PE structure, import tables, IL, and a hand-rolled AES decrypt of an embedded resource. That is the hard path, and it finished it.
Verdict at a glance
| File | Type | Role |
|---|---|---|
undetek-v10.12.exe | Native x86-64 (MSVC) | Trojan / process injector + TCP C2 |
zRanibox6s.exe | .NET Framework 4.7.2 (WinForms) | Dropper / launcher ("OmnyLoad") — pulls and runs 4 payloads from a Russian C2 |
C2 server a0717206.xsph.ru — URL pattern http://a0717206.xsph.ru/db/<file>. Currently dead (resolves to 0.0.0.0), but block it for recurrence.
Sample 1 — undetek-v10.12.exe
A native loader whose very name ("undetek" = undetected) advertises its purpose.
Identity
| Field | Value |
|---|---|
| Size | 254,976 bytes |
| SHA-256 | 5d0150547126ac4d1a2b4ebc4ad8f14b65b60faa7d1774909828123bb4d4c062 |
| MD5 | c66f3ba49fbbf44b9a025bf1a18bec35 |
| Format | PE32+ (64-bit), console subsystem, x86-64, MSVC |
| Sections | .text .rdata .data .pdata .fptable .reloc — no .rsrc (resources/version info stripped) |
The import table is the fingerprint
With no plaintext URLs, IPs or keys in the binary (all built at runtime), the imports tell the story:
| Library | Imports | What it means |
|---|---|---|
| KERNEL32 | OpenProcess, VirtualAllocEx, WriteProcessMemory, ReadProcessMemory, CreateRemoteThread, VirtualProtectEx, WaitForSingleObject | Classic remote process injection |
| KERNEL32 | CreateToolhelp32Snapshot, Process32First/Next | Process enumeration (find an injection target) |
| KERNEL32 | IsDebuggerPresent | Anti-debug |
| USER32 | GetAsyncKeyState, SendInput | Keystroke capture / input simulation |
| ADVAPI32 | RegCreateKeyExA, RegSetValueExA/W, RegOpenKeyExA/W, RegDeleteKeyA | Registry persistence |
| WS2_32 (by ordinal) | socket, connect, send, recv, WSAStartup, getaddrinfo | Raw-socket TCP C2 (no UDP) |
Verdict
Native x86-64 trojan / injection loader. Combines process injection, process enumeration, input capture, registry persistence, a TCP C2 channel and anti-debug. The "undetected" branding, the stripped .rsrc, and runtime-built strings all point to deliberate AV evasion.
Sample 2 — zRanibox6s.exe ("OmnyLoad")
The dropper. A .NET WinForms app that elevates to admin, reads the Windows version, and runs a version-specific PowerShell kill chain.
Identity
| Field | Value |
|---|---|
| Size | 305,664 bytes |
| SHA-256 | 7d5f7c61426cff3a8ea36283412bed80904a89b1111520cb7835b7048ad65d61 |
| MD5 | 0b1b19e6bdf85c08bec973fb18fa44cb |
| Format | PE32, GUI subsystem, .NET Framework 4.7.2, WinForms |
| Assembly | renamed OmnyLoad, version 1.2.6.9, GUID 8e999c78-c293-43a0-b169-016276344d47, © 2022 |
| Manifest | requestedExecutionLevel = requireAdministrator |
| Obfuscation | single-char type names '0'–'5'; config in an AES-encrypted embedded resource |
The encrypted config
The behaviour lives in manifest resource "0" (22,064 bytes) — a raw AES-256-CBC blob that carries its own key material at the front:
| Part | Bytes | Value |
|---|---|---|
| Key | [0:32] | 216280f1db0411a69e393e5084056991abcca1b09a9be68fd849412755e0c7f3 |
| IV | [32:48] | f890011b3be9a49f6b25d8d01d9b3886 |
| Ciphertext | [48:22064] | 22,016 bytes (1,376 blocks) |
How the config format was recovered
Decrypting resource "0" yields 22,004 bytes (after a 12-byte PKCS7 strip) of a BinaryReader stream: 48 fields, UTF-16LE strings with byte-length prefixes, interleaved with int32 and sbyte values.
The trap: the length prefix counts bytes, not characters. Reading it as a character count (the .NET BinaryReader.ReadString default) misaligns every string and renders ASCII as garbage CJK. Once read as byte lengths — e.g. 0x70 = 112 bytes = 56 chars = the registry path — all 48 fields parse cleanly and consume exactly 22,004 / 22,004 bytes. Structure confirmed.
What the config does
1. Reads the Windows version from the registry:
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion → value "ProductName"
2. Branches on the version string:
ProductName contains | Action |
|---|---|
| "Windows 10" | Branch 1 (full kill chain) |
| "Windows 7" | Application.Exit() — no-op |
| "Windows 8" | Branch 2 |
| "Windows 11" | Branch 3 |
3. Launches powershell.exe and pipes a batch that first disables Defender for the drop folder:
Add-MpPreference -ExclusionPath "C:\ProgramData\"
4. Downloads and executes four payloads (each: Invoke-WebRequest → save as .exe → run via Invoke-Expression). The .db extension and the Microsoft/dev names are pure camouflage:
| C2 file | Dropped as |
|---|---|
http://a0717206.xsph.ru/db/opti.db | C:\ProgramData\Microsoft\Crypto\devenv.exe |
http://a0717206.xsph.ru/db/stip.db | C:\ProgramData\Microsoft\Crypto\SpeechUx.exe |
http://a0717206.xsph.ru/db/dbg.db | C:\ProgramData\Microsoft\Crypto\SystemKeys\Microsoft Network Realtime Inspection Service.exe |
http://a0717206.xsph.ru/db/ok.db | C:\ProgramData\Microsoft\Crypto\git.exe |
5. Persists via scheduled tasks (by branch):
- Windows 10 — two logon tasks named to blend in:
SCHTASKS /create /sc ONLOGON /TN "Microsoft\Two" /TR "...\SystemKeys\Microsoft Network Realtime Inspection Service.exe"SCHTASKS /create /sc ONLOGON /TN "Microsoft\Two" /TR "...\git.exe"
- Windows 8 / 11 — also pulls a task definition from the C2 and imports it:
http://a0717206.xsph.ru/db/start.xml → C:\ProgramData\Microsoft\DiagnosticLogCSP\start.xmlschtasks /create /tn \Mylibrary\Ape /xml C:\ProgramData\Microsoft\DiagnosticLogCSP\start.xml
6. Shows a decoy error dialog once the payloads are running:
Text: "The program can't start because MSVCP140.dll is missing from your computer. Try reinstalling the program to fix this problem" — title "System Error", icon 16 (MB_ICONHAND). The victim thinks the program simply failed, while the real payloads are already dropped, running and persisted. Timing is deliberate: Thread.Sleep(2500) after the command batch, Sleep(2000) before the dialog.
Verdict
Admin-elevated .NET dropper ("OmnyLoad"). Version-aware, carves a Defender exclusion for C:\ProgramData\, downloads four disguised executables from a0717206.xsph.ru, persists them via scheduled tasks, then lies with a fake missing-DLL error.
How the two relate
Same campaign. zRanibox6s.exe (OmnyLoad) is the dropper that pulls live payloads from the C2; undetek-v10.12.exe is the native injector (process injection + TCP C2) that is a staged/dropped component or its companion — the thing that ends up inside a trusted process. The .db / .exe names are camouflage throughout.
IOC summary
Network
| Type | Value | Notes |
|---|---|---|
| Domain (C2) | a0717206.xsph.ru | Dead — resolves to 0.0.0.0 |
| URL pattern | http://a0717206.xsph.ru/db/<file> | files: opti.db, stip.db, dbg.db, ok.db, start.xml |
| Transport | TCP raw sockets (WS2_32) | no UDP |
File hashes
| File | SHA-256 | MD5 |
|---|---|---|
undetek-v10.12.exe | 5d0150547126ac4d1a2b4ebc4ad8f14b65b60faa7d1774909828123bb4d4c062 | c66f3ba49fbbf44b9a025bf1a18bec35 |
zRanibox6s.exe | 7d5f7c61426cff3a8ea36283412bed80904a89b1111520cb7835b7048ad65d61 | 0b1b19e6bdf85c08bec973fb18fa44cb |
Filesystem (drop locations)
C:\ProgramData\Microsoft\Crypto\devenv.exeC:\ProgramData\Microsoft\Crypto\SpeechUx.exeC:\ProgramData\Microsoft\Crypto\SystemKeys\Microsoft Network Realtime Inspection Service.exeC:\ProgramData\Microsoft\Crypto\git.exeC:\ProgramData\Microsoft\DiagnosticLogCSP\start.xml(Win8 / Win11 only)
Registry
- Read:
HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\ProductName(version detection) - Written (native file): persistence keys built at runtime (not plaintext)
Scheduled tasks
Microsoft\Two(ONLOGON) → the dropped Inspection-Service andgit.exe(Win10)\Mylibrary\Ape(imported fromstart.xml) → the dropped payloads (Win8 / Win11)
Behaviour
- Launched process:
powershell.exe(dropper); dropped exes run as above - Defender exclusion added:
C:\ProgramData\ - Anti-debug:
IsDebuggerPresent(native file) - Input capture:
GetAsyncKeyState/SendInput(native file)
Cryptographic
- AES-256-CBC key:
216280f1db0411a69e393e5084056991abcca1b09a9be68fd849412755e0c7f3 - AES-256-CBC IV:
f890011b3be9a49f6b25d8d01d9b3886
Misc
- Assembly:
OmnyLoad, GUID8e999c78-c293-43a0-b169-016276344d47 - Decoy dialog: "...MSVCP140.dll is missing..." / title "System Error"
- Version triggers: "Windows 10", "Windows 7" (exit), "Windows 8", "Windows 11"
Recommended response
- Block
a0717206.xsph.ruand thehttp://a0717206.xsph.ru/db/URL pattern at the proxy/firewall (dead now; block for recurrence). - Delete the dropped files under
C:\ProgramData\Microsoft\Crypto\andC:\ProgramData\Microsoft\DiagnosticLogCSP\start.xml. - Remove the scheduled tasks:
schtasks /delete /tn "Microsoft\Two" /fschtasks /delete /tn "\Mylibrary\Ape" /f
- Remove the Defender exclusion:
Remove-MpPreference -ExclusionPath "C:\ProgramData\"
- Hunt the two SHA-256 hashes across the fleet; treat any match as compromised, and re-image where the native injector was present.
- Rotate credentials on affected hosts — input simulation plus admin rights makes credential theft plausible.
Method and evidence
| Stage | Tooling |
|---|---|
| PE parsing | objdump, rabin2 -i (full import table), section/data-dir walk |
| .NET | ilspycmd 9.1.0.7988 -il (1,011-line IL dump); resource extraction via an Assembly.LoadFrom + GetManifestResourceStream C# harness |
| Config recovery | resource "0" → AES-256-CBC decrypt (key/IV embedded) → 48-field BinaryReader parse (UTF-16LE, byte-length prefixes) |
| C2 liveness | local DNS + curl → 0.0.0.0, connection failed |
What this says about the model
A 15.7 GB quant running on one desktop GPU, given a one-line prompt, produced a report that a competent human analyst would sign. It chose the right tools, recognised AES-256 from a failed AES-128 attempt, spotted the byte-vs-character length trap in a custom serializer, and separated evidence from interpretation throughout. The stack that makes this practical — binary choice, drafter, sampling — is on the OrcaSAQ-2 Cyber and DFlash2 page.
Everything here is observation from static analysis. The payloads behind the four .db files were never retrieved (C2 dead at analysis time), so what the second stage ultimately does is inferred from the native injector's imports, not confirmed.
- Leads to
- Writing a useful detection note
Sample content for layout review, not published research.