485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0avalancherunner: 485f73af — Fourth confirmed sibling, ParticlePlayground skin, no encrypted payload
Executive Summary
Fourth confirmed sibling of the avalancherunner cluster. This sample uses a ParticlePlayground game namespace (Uzbek "Zarracha" = particle) and carries a large embedded PNG asset (~880 KB) but lacks both the Shifrlash/Deshifrlash encryption routines and the ~952 KB encrypted CLR resource blob observed in siblings 1a38a948 (May 2020) and 2d9f8c6e (Dec 2022). The anomalous Survey_Cadastral_Transect method name is present, confirming shared build pipeline. Capa still flags reflective code loading (T1620), directory creation, file existence checks, and PRNG use. No CAPE detonation (no Windows guest). Static-only analysis.
What It Is
| Field | Value | Source |
|---|---|---|
| SHA-256 | 485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0 |
^[metadata.json] |
| Filename (on disk) | QVVr.exe |
^[metadata.json:5] |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections | ^[file.txt:1] |
| Size | 1,024,000 bytes (1.00 MB) | ^[metadata.json:6] ^[rabin2-info.txt:15] |
| Timestamp | Fri May 22 07:52:26 2026 UTC | ^[pefile.txt:191] |
| .NET runtime | .NET Framework 4.5 (v4.0.30319) | ^[strings.txt:6] |
| Compiler | Visual Studio / .NET Framework C# (SettingsSingleFileGenerator 16.10.0.0) | ^[strings.txt:567] |
| Signed | No — StrongNameSignatureRva = 0x0 | ^[pefile.txt:152] ^[rabin2-info.txt:27] |
| Entry point | mscoree.dll._CorExeMain |
^[pefile.txt:255] ^[rabin2-info.txt:28] |
| Language | C# / CIL | ^[rabin2-info.txt:1] |
| Obfuscator | None — fully unobfuscated namespaces, classes, methods | ^[strings.txt] |
Version-info masquerade
The VS_VERSIONINFO block claims ^[exiftool.json] ^[pefile.txt:234-243]:
- ProductName / FileDescription:
Particle Playground - CompanyName:
Microsoft Corporation - InternalName / OriginalFilename:
QVVr.exe - FileVersion / ProductVersion:
4.0.0.0
The filename QVVr.exe (unpronounceable, no semantic meaning) and the Microsoft Corporation CompanyName are low-effort masquerade. See version-info-masquerade.
How It Works
Outer shell — decoy game UI
The binary is a standard C# WinForms application with a single main form (OyinForma) and a settings form (SozlamalarForma), plus a ZarrachalarMenejer (Particle Manager) class. Class and method names are in Uzbek:
Zarracha— ParticleZarrachalarMenejer— Particle ManagerSozlamalar— SettingsSozlamalarJadvali— Settings TableOyinForma— Game FormSozlamalarForma— Settings FormoyinTimeri_Tick— game timer tick_FonBuferYangilash— update background buffer_HolatMatnYangilash— update status textPortlashQoshish— add explosion
These names are unobfuscated and visible in plain IL metadata. ^[strings.txt:27-30,79,463-465,506]
Notable anomalous method
Survey_Cadastral_Transect — same bizarre English-Uzbek hybrid method name present in all three prior siblings (1a38a948, 2d9f8c6e, f7352bc1). This is a build-pipeline fingerprint, not game logic. ^[strings.txt:506] ^[r2:sym.Survey_Cadastral_Transect]
Embedded asset — PNG in .text
A valid 1280×720 PNG image (~880 KB) is embedded at file offset 0x2C90F inside the .text section. It is a standard PNG with IHDR/gAMA/pHYs/IDAT/IEND chunks; binwalk confirms zlib-compressed pixel data. ^[binwalk.txt] Unlike siblings 1a38a948 and 2d9f8c6e, there is no encrypted CLR resource blob alongside the PNG. The image appears to be a genuine game background asset.
Absent: encryption / payload routines
Not found in this sample (contrast with siblings 1a38a948 and 2d9f8c6e):
Shifrlash/Deshifrlash— encrypt / decryptObfKalit— obfuscation keyXavfsizHisoblagich— security calculator (cipher class)- Any large encrypted CLR resource blob (>10 KB)
This sample is the second "stripped" variant after f7352bc1 (May 2026), which also lacked encryption routines and the payload blob.
Reflective loading indicator
Capa still flags:
load .NET assembly^[capa.txt:38]invoke .NET assembly method(2 matches) ^[capa.txt:36]access .NET resource^[capa.txt:32]
The presence of these flags without an encrypted payload suggests the sample may load additional assemblies at runtime via Assembly.Load or Activator.CreateInstance from the local file system or from the embedded .resources streams (ParticlePlayground.OyinForma.resources, ParticlePlayground.SozlamalarForma.resources, ParticlePlayground.Properties.Resources.resources). ^[strings.txt:463-465]
Capabilities flagged
| Capability | Evidence |
|---|---|
generate random numbers in .NET |
Capa PRNG flag ^[capa.txt:31] |
reference analysis tools strings |
Capa anti-analysis flag ^[capa.txt:30] |
create directory |
Capa directory creation ^[capa.txt:33] |
check if directory exists |
Capa file-system existence check ^[capa.txt:34] |
check if file exists |
Capa file-system existence check ^[capa.txt:35] |
Build / RE
Toolchain & Language
.NET Framework 4.5 PE32, compiled with Visual Studio / C#. Three-section layout: .text (~1,021 KB), .rsrc (~1.5 KB), .reloc (~512 bytes) ^[pefile.txt] ^[rabin2-info.txt]. No packing, no native packer stub, no ConfuserEx, SmartAssembly, Xenocode, or other obfuscator.
Anti-Analysis
None observed. No debug checks, no VM detection, no anti-disassembly, no TLS callbacks. The binary is fully unobfuscated and analyst-friendly. The only "anti-analysis" signal is Capa's generic reference analysis tools strings flag, which in .NET often triggers on innocuous System.Diagnostics references.
Code Quality
Standard C# WinForms code generated by Visual Studio designer. Uses strongly-typed DataSet (SozlamalarJadvali) with DataTable/DataRow patterns, standard System.Drawing for game rendering (FillEllipse, Graphics), and System.Windows.Forms.Timer for the game loop. No custom native interop, no P/Invoke, no unsafe blocks.
Signing
Unsigned. No Authenticode certificate, no timestamp counter-signature. ^[pefile.txt:152] ^[rabin2-info.txt:27]
Embedded Resources
- CLR
.resources: Three standard.resourcesfiles for WinForms localization (OyinForma,SozlamalarForma,Properties.Resources) ^[strings.txt:463-465] - RT_MANIFEST: Standard UAC
asInvokermanifest ^[pefile.txt] - VS_VERSIONINFO: Masquerade fields as noted above
- PNG image: 1280×720 background asset in
.textsection - No encrypted payload: No
CKT-sized blob, noDBzt-sized fragment
Deploy / ATT&CK
Ground truth: No CAPE detonation present (PE skipped — no Windows guest). All TTPs below are inferred from static evidence.
| ATT&CK Tactic | Technique | Evidence |
|---|---|---|
| Defense Evasion | T1620 — Reflective Code Loading | Capa flags load .NET assembly + invoke .NET assembly method ^[capa.txt:36-38] |
| Discovery | T1083 — File and Directory Discovery | Capa check if file exists + check if directory exists ^[capa.txt:34-35] |
| Defense Evasion | T1036 — Masquerading | Particle Playground / Microsoft Corporation / QVVr.exe version-info contradictions ^[exiftool.json] |
| Defense Evasion | T1027 — Obfuscated Files or Information | (Partial) — outer binary masquerades as game; no encrypted payload in this variant |
Persistence / C2 / Lateral Movement
No persistence mechanisms observed (no registry keys, no schtasks strings, no startup folder references, no service creation) ^[strings.txt] ^[floss.txt].
No network indicators (no HTTP, TCP, UDP, DNS, SMTP, socket, or System.Net strings) ^[strings.txt] ^[floss.txt].
No process injection, hollowing, or remote-thread strings ^[strings.txt] ^[floss.txt].
No lateral-movement capabilities observed statically.
Attribution
- Language: UI strings and class names in Uzbek (
Zarracha,Sozlamalar,Oyin,Portlash,Yangilash,Holat) ^[strings.txt]. - Code reuse: Same
Survey_Cadastral_Transectanomalous method name, same .NET Framework 4.5 target, same unobfuscated build quality, same capa reflective-loading signature as all three prior siblings. - Build delta: May 2026 timestamp (2 days after sibling
f7352bc1's May 21 timestamp). New namespaceParticlePlaygroundreplacesAvalancheRunnerandBombaZarasizlantiruvchi. No encrypted payload, no cipher routines — the simplest variant yet.
Comparative Notes (Sibling Cluster)
| Attribute | 1a38a948 (May 2020) |
2d9f8c6e (Dec 2022) |
f7352bc1 (May 2026) |
485f73af (May 2026) |
|---|---|---|---|---|
| Namespace | AvalancheRunner |
AvalancheRunner |
BombaZarasizlantiruvchi |
ParticlePlayground |
| Game theme | Avalanche / rocks | Avalanche / rocks | Bomb defusal | Particle playground |
| Encrypted blob | ~952 KB CLR resource | ~952 KB CLR resource | Absent | Absent |
| Cipher routines | Shifrlash/Deshifrlash |
Shifrlash/Deshifrlash |
Absent | Absent |
| PNG asset | None observed | None observed | None observed | ~880 KB in .text |
| Internal name | hHRu.exe |
LHUS.exe |
rFks.exe |
QVVr.exe |
| CompanyName | Antigravity |
(blank) | PDF FILE PREVIEWER... |
Microsoft Corporation |
| FileVersion | 1.0.0.0 |
0.0.0.0 |
1.0.0.0 |
4.0.0.0 |
Survey_Cadastral_Transect |
Yes | Yes | Yes | Yes |
Verdict
Low-confidence malicious family label (avalancherunner) maintained. This is the fourth confirmed sibling and the second "stripped" variant (no encrypted payload, no cipher routines). The outer binary is a functional C# WinForms game with Uzbek UI and a large embedded PNG asset. The shared Survey_Cadastral_Transect build fingerprint, the reflective-loading capa flags, and the masquerade version info justify keeping it in the cluster, but this sample presents the lowest malicious surface of any sibling observed to date. It may be a development build, a test compile, or a variant where the payload loader was intentionally removed.
Related
- entities/avalancherunner.md — Family overview
- /intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html — First sibling (May 2020)
- /intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html — Second sibling (Dec 2022)
- /intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html — Third sibling (May 2026)