Default model (Qwen3.6-35B-A3B on ik_llama.cpp, with a 1 GiB prompt cache; iteration 1 used the 8 GiB default),
dev @ 39b07c65, default profile, mock sandbox (nothing executed). The method is exactly as in the
benchmark page and the iteration-1 score: 57 core items of
K1–K10 (K1.1 split), build items as consistency checks only, chain and later items not scored. partly (body) = the
body states part of the item or states it with the wrong purpose; partly (appendix) = the value is printed only in
Appendix A › Floss: strings. A behaviour that a string in the appendix only hints at is missed. Human sources: B Bitsight (names this hash), E Elastic,
P Proofpoint.
§5.2 capa rows "resolve function by parsing PE exports", "hash data with CRC32"; §5.1 "imports only kernel32.dll and user32.dll …, limiting its direct API surface". "By hash" never said
B Windows API resolution
K2.2 abort on failed check
missed
—
B Anti analysis
K2.3 mutex
missed
CreateMutexW only in §7 imports; runnung only in the appendix
B Mutex
K2.4 install, then persist
partly (body)
§4 step 2 "establishes persistence by creating scheduled tasks (LogonTrigger) and modifying registry Run keys". No copy step
B Persistence
K2.5 register, then command loop
partly (body)
§4 step 3 "communicates with command-and-control servers via HTTP POST requests, sending collected system data". No loop
B Communications protocol
K2.6 update_data.dat for new C2s
partly (body)
§5.8 "\"\update_data.dat\" … suggesting it may drop or execute additional payloads" — named, purpose wrong
§5.2 "capa identifies capabilities including PEB access, RC4 encryption, CRC32 hashing"; §4 step 4 reads CRC32 as obfuscation
B
K3.6 string encryption
partly (body)
§5.1 "Despite the absence of a traditional packer, the binary employs significant obfuscation … Emulated decoding routines recovered 81 strings". Scheme given as stackstrings/RC4, not a rolling XOR
§5.2 capa row "hash data using fnv"; Littlehw only in the appendix
B Group and Group ID
K4.4 two encrypted C2s
found
§5.7 "The sample contains strings indicating communication with two C2 endpoints: https://skinnyjeanso.com/live/ and https://titnovacrion.top/live/"; §5.1 "Emulated decoding routines recovered 81 strings, including URLs for command-and-control"
B C2 decryption
K5.1 Custom_update\Update_%x.dll
partly (body)
§5.8 "references a \"Custom_update\" routine" — the folder named, as a routine; Update_%x only in the appendix
B Persistence
K5.2 task Updater, COM, at logon
partly (body)
§4 "creating scheduled tasks (LogonTrigger)"; §5.3 "Scheduled Tasks (LogonTrigger)". Updater only in the appendix; COM not said; T1053.005 no longer published
B Persistence
K5.3 update_data.dat holds new C2 URLs
partly (body)
named in §5.6/§5.8, purpose "drop or execute additional payloads"
B
K6.1 HTTPS POST /live/
found
§5.2 "C2 communication is structured around HTTP POST requests to URLs such as https://skinnyjeanso.com/live/"; §5.7 channel table
B
K6.2 User-Agent
found (iteration 1: appendix)
§5.3 "User-Agent · Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1)"; §5.7 "spoofs the User-Agent as Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1)"
B
K6.3 RC4 then base64
partly (body)
§1 "obfuscating data with RC4 encryption"; §5.3 "Encryption · RC4 PRGA"; but the §5.7 channel table says "Encryption · None". Base64 not stated; key 12345 only in the appendix
B
K6.4 beacon interval
missed
—
B
K6.5 beacon format
found
§5.7 channel table quotes counter=%d&type=%d&guid=%s&os=%d&arch=%d&username=%s&group=%lu&ver=%d.%d&up=%d&direction=%s; registration additions only in the appendix
B Beacon data
K6.6 beacon types 1–5
missed
—
B
K6.7 URLS/CLEARURL/COMMAND/ERROR
partly (appendix)
only in the appendix; §5.6 says only "a 'stiller' parameter and a 'net_config_ws' parameter, likely for configuration or specific command execution"
K7 commands. partly (body): 4 (the recon set in §5.5/§5.6, not tied to a C2 command), 12 and 13
(§5.6 "references … '.exe' and '.dll' files, suggesting it may drop or execute additional payloads"; §1 rundll32),
18 (files/bp.dat named as a .dat file). missed: 2, 3 (no process list in the body this time), 14,
15 (no self-update sentence this time), 17, 19, 20.
K8 discovery: found. §5.5 lists net group "Domain Admins" /domain, nltest /domain_trusts and /all_trusts,
net view /all /domain and /all, ipconfig /all, whoami /groups, the SecurityCenter2 WMI query and net config
workstation. systeminfo is in §1; the ifconfig.me lookup is missing.
K9 IOCs. found: own hashes; /live/; the User-Agent (§5.3, §5.7). partly (body): Custom_update (as a
"routine"), update_data.dat. partly (appendix): mutex runnung, Update_%x, task Updater.
K10 ATT&CK. found: T1027 (published; RC4/stackstrings). partly: T1218.011 (T1218 only in §10.3 and §11 for
rundll32, not published). missed: T1055, T1053.005 and T1059.003 (both found in iteration 1; the static
analyst claimed T1082, T1071, T1027, T1014 and T1059.004 instead), T1070.004.
Build consistency.skinnyjeanso.com, titnovacrion.top on B's list of 47 (now in §9 and /iocs); Littlehw and
12345 still only in the appendix — consistent.
K11. The drafts are the hash/imphash YARA with the two C2 domains as strings (2 of them) and two Suricata DNS
alerts for the domains. None of the decoded host strings (UA, runnung, Custom_update) is a draft string.
Published (/iocs and §9): 1 of 8 (the sample's hashes). /iocs and §9 now also publish the two C2 domains (source
judge), which iteration 1 exported in STIX only.
Stated in the body: 5 of 8 (hashes, /live/, UA, Custom_update, update_data.dat) — iteration 1: 3.
Present anywhere including the appendix: 8 of 8.
The host-identifier section that iteration 2 added for exactly these values is missing: "report section
'host_identifiers' is missing: its answer reached the output cap of 8192 tokens and was cut off" (§13).
Reverse direction: claims no human report supports¶
Claim (quoted)
Assessment
How we know
"establishes persistence by loading a secondary DLL via rundll32.exe, a technique consistent with DLL side-loading" (§1, summary)
contradicted
B, E: persistence is the Updater task; rundll32 is how the DLL and command 13's payloads run
"modifying registry Run keys, targeting Startup and Personal shell folders"; "to place shortcuts or executables in the user's Startup directory"; judge "registry run keys"
contradicted
B, E: the task only; the Shell Folders values are E's configurable install location (K5.5)
T1014 Rootkit published ("checking for the presence of specific security products and potentially loading DLLs from non-standard locations")
contradicted
no report describes rootkit behaviour; the AV query is discovery (command 4)