typeanalysisfamilyavalancherunnerconfidencelowcreated2026-07-26updated2026-07-26dotnetpeloaderdefense-evasiondiscoverymasqueradingmitre-attckreflective-code-loading
SHA-256: 485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0

avalancherunner: 485f73af — Fourth confirmed sibling, ParticlePlayground skin, no encrypted payload

Executive Summary

Fourth confirmed sibling of the avalancherunner cluster. This sample uses a ParticlePlayground game namespace (Uzbek "Zarracha" = particle) and carries a large embedded PNG asset (~880 KB) but lacks both the Shifrlash/Deshifrlash encryption routines and the ~952 KB encrypted CLR resource blob observed in siblings 1a38a948 (May 2020) and 2d9f8c6e (Dec 2022). The anomalous Survey_Cadastral_Transect method name is present, confirming shared build pipeline. Capa still flags reflective code loading (T1620), directory creation, file existence checks, and PRNG use. No CAPE detonation (no Windows guest). Static-only analysis.

What It Is

Field Value Source
SHA-256 485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0 ^[metadata.json]
Filename (on disk) QVVr.exe ^[metadata.json:5]
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt:1]
Size 1,024,000 bytes (1.00 MB) ^[metadata.json:6] ^[rabin2-info.txt:15]
Timestamp Fri May 22 07:52:26 2026 UTC ^[pefile.txt:191]
.NET runtime .NET Framework 4.5 (v4.0.30319) ^[strings.txt:6]
Compiler Visual Studio / .NET Framework C# (SettingsSingleFileGenerator 16.10.0.0) ^[strings.txt:567]
Signed No — StrongNameSignatureRva = 0x0 ^[pefile.txt:152] ^[rabin2-info.txt:27]
Entry point mscoree.dll._CorExeMain ^[pefile.txt:255] ^[rabin2-info.txt:28]
Language C# / CIL ^[rabin2-info.txt:1]
Obfuscator None — fully unobfuscated namespaces, classes, methods ^[strings.txt]

Version-info masquerade

The VS_VERSIONINFO block claims ^[exiftool.json] ^[pefile.txt:234-243]:

  • ProductName / FileDescription: Particle Playground
  • CompanyName: Microsoft Corporation
  • InternalName / OriginalFilename: QVVr.exe
  • FileVersion / ProductVersion: 4.0.0.0

The filename QVVr.exe (unpronounceable, no semantic meaning) and the Microsoft Corporation CompanyName are low-effort masquerade. See version-info-masquerade.

How It Works

Outer shell — decoy game UI

The binary is a standard C# WinForms application with a single main form (OyinForma) and a settings form (SozlamalarForma), plus a ZarrachalarMenejer (Particle Manager) class. Class and method names are in Uzbek:

  • Zarracha — Particle
  • ZarrachalarMenejer — Particle Manager
  • Sozlamalar — Settings
  • SozlamalarJadvali — Settings Table
  • OyinForma — Game Form
  • SozlamalarForma — Settings Form
  • oyinTimeri_Tick — game timer tick
  • _FonBuferYangilash — update background buffer
  • _HolatMatnYangilash — update status text
  • PortlashQoshish — add explosion

These names are unobfuscated and visible in plain IL metadata. ^[strings.txt:27-30,79,463-465,506]

Notable anomalous method

Survey_Cadastral_Transect — same bizarre English-Uzbek hybrid method name present in all three prior siblings (1a38a948, 2d9f8c6e, f7352bc1). This is a build-pipeline fingerprint, not game logic. ^[strings.txt:506] ^[r2:sym.Survey_Cadastral_Transect]

Embedded asset — PNG in .text

A valid 1280×720 PNG image (~880 KB) is embedded at file offset 0x2C90F inside the .text section. It is a standard PNG with IHDR/gAMA/pHYs/IDAT/IEND chunks; binwalk confirms zlib-compressed pixel data. ^[binwalk.txt] Unlike siblings 1a38a948 and 2d9f8c6e, there is no encrypted CLR resource blob alongside the PNG. The image appears to be a genuine game background asset.

Absent: encryption / payload routines

Not found in this sample (contrast with siblings 1a38a948 and 2d9f8c6e):

  • Shifrlash / Deshifrlash — encrypt / decrypt
  • ObfKalit — obfuscation key
  • XavfsizHisoblagich — security calculator (cipher class)
  • Any large encrypted CLR resource blob (>10 KB)

This sample is the second "stripped" variant after f7352bc1 (May 2026), which also lacked encryption routines and the payload blob.

Reflective loading indicator

Capa still flags:

  • load .NET assembly ^[capa.txt:38]
  • invoke .NET assembly method (2 matches) ^[capa.txt:36]
  • access .NET resource ^[capa.txt:32]

The presence of these flags without an encrypted payload suggests the sample may load additional assemblies at runtime via Assembly.Load or Activator.CreateInstance from the local file system or from the embedded .resources streams (ParticlePlayground.OyinForma.resources, ParticlePlayground.SozlamalarForma.resources, ParticlePlayground.Properties.Resources.resources). ^[strings.txt:463-465]

Capabilities flagged

Capability Evidence
generate random numbers in .NET Capa PRNG flag ^[capa.txt:31]
reference analysis tools strings Capa anti-analysis flag ^[capa.txt:30]
create directory Capa directory creation ^[capa.txt:33]
check if directory exists Capa file-system existence check ^[capa.txt:34]
check if file exists Capa file-system existence check ^[capa.txt:35]

Build / RE

Toolchain & Language

.NET Framework 4.5 PE32, compiled with Visual Studio / C#. Three-section layout: .text (~1,021 KB), .rsrc (~1.5 KB), .reloc (~512 bytes) ^[pefile.txt] ^[rabin2-info.txt]. No packing, no native packer stub, no ConfuserEx, SmartAssembly, Xenocode, or other obfuscator.

Anti-Analysis

None observed. No debug checks, no VM detection, no anti-disassembly, no TLS callbacks. The binary is fully unobfuscated and analyst-friendly. The only "anti-analysis" signal is Capa's generic reference analysis tools strings flag, which in .NET often triggers on innocuous System.Diagnostics references.

Code Quality

Standard C# WinForms code generated by Visual Studio designer. Uses strongly-typed DataSet (SozlamalarJadvali) with DataTable/DataRow patterns, standard System.Drawing for game rendering (FillEllipse, Graphics), and System.Windows.Forms.Timer for the game loop. No custom native interop, no P/Invoke, no unsafe blocks.

Signing

Unsigned. No Authenticode certificate, no timestamp counter-signature. ^[pefile.txt:152] ^[rabin2-info.txt:27]

Embedded Resources

  • CLR .resources: Three standard .resources files for WinForms localization (OyinForma, SozlamalarForma, Properties.Resources) ^[strings.txt:463-465]
  • RT_MANIFEST: Standard UAC asInvoker manifest ^[pefile.txt]
  • VS_VERSIONINFO: Masquerade fields as noted above
  • PNG image: 1280×720 background asset in .text section
  • No encrypted payload: No CKT-sized blob, no DBzt-sized fragment

Deploy / ATT&CK

Ground truth: No CAPE detonation present (PE skipped — no Windows guest). All TTPs below are inferred from static evidence.

ATT&CK Tactic Technique Evidence
Defense Evasion T1620 — Reflective Code Loading Capa flags load .NET assembly + invoke .NET assembly method ^[capa.txt:36-38]
Discovery T1083 — File and Directory Discovery Capa check if file exists + check if directory exists ^[capa.txt:34-35]
Defense Evasion T1036 — Masquerading Particle Playground / Microsoft Corporation / QVVr.exe version-info contradictions ^[exiftool.json]
Defense Evasion T1027 — Obfuscated Files or Information (Partial) — outer binary masquerades as game; no encrypted payload in this variant

Persistence / C2 / Lateral Movement

No persistence mechanisms observed (no registry keys, no schtasks strings, no startup folder references, no service creation) ^[strings.txt] ^[floss.txt].

No network indicators (no HTTP, TCP, UDP, DNS, SMTP, socket, or System.Net strings) ^[strings.txt] ^[floss.txt].

No process injection, hollowing, or remote-thread strings ^[strings.txt] ^[floss.txt].

No lateral-movement capabilities observed statically.

Attribution

  • Language: UI strings and class names in Uzbek (Zarracha, Sozlamalar, Oyin, Portlash, Yangilash, Holat) ^[strings.txt].
  • Code reuse: Same Survey_Cadastral_Transect anomalous method name, same .NET Framework 4.5 target, same unobfuscated build quality, same capa reflective-loading signature as all three prior siblings.
  • Build delta: May 2026 timestamp (2 days after sibling f7352bc1's May 21 timestamp). New namespace ParticlePlayground replaces AvalancheRunner and BombaZarasizlantiruvchi. No encrypted payload, no cipher routines — the simplest variant yet.

Comparative Notes (Sibling Cluster)

Attribute 1a38a948 (May 2020) 2d9f8c6e (Dec 2022) f7352bc1 (May 2026) 485f73af (May 2026)
Namespace AvalancheRunner AvalancheRunner BombaZarasizlantiruvchi ParticlePlayground
Game theme Avalanche / rocks Avalanche / rocks Bomb defusal Particle playground
Encrypted blob ~952 KB CLR resource ~952 KB CLR resource Absent Absent
Cipher routines Shifrlash/Deshifrlash Shifrlash/Deshifrlash Absent Absent
PNG asset None observed None observed None observed ~880 KB in .text
Internal name hHRu.exe LHUS.exe rFks.exe QVVr.exe
CompanyName Antigravity (blank) PDF FILE PREVIEWER... Microsoft Corporation
FileVersion 1.0.0.0 0.0.0.0 1.0.0.0 4.0.0.0
Survey_Cadastral_Transect Yes Yes Yes Yes

Verdict

Low-confidence malicious family label (avalancherunner) maintained. This is the fourth confirmed sibling and the second "stripped" variant (no encrypted payload, no cipher routines). The outer binary is a functional C# WinForms game with Uzbek UI and a large embedded PNG asset. The shared Survey_Cadastral_Transect build fingerprint, the reflective-loading capa flags, and the masquerade version info justify keeping it in the cluster, but this sample presents the lowest malicious surface of any sibling observed to date. It may be a development build, a test compile, or a variant where the payload loader was intentionally removed.

Related

  • entities/avalancherunner.md — Family overview
  • /intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html — First sibling (May 2020)
  • /intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html — Second sibling (Dec 2022)
  • /intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html — Third sibling (May 2026)