typeanalysisfamilyavalancherunnerconfidencehighcreated2026-07-31updated2026-07-31dotnetloadermasqueradingdefense-evasionmitre-attckdebug-build-capa-fp
SHA-256: 580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6

avalancherunner: 580095fa — CardBattle Uzbek TCG skin, quotation-form lure

Executive Summary

Seventh confirmed sibling in the AvalancheRunner .NET Framework 4.5 cluster. Presents as a fully functional Uzbek-language trading-card-game WinForms application (CardBattle) but is distributed under the business-document filename MV_GREAT_AMITY_QUOTATION_FORMS.exe. No encrypted payload blob, no network surface, no persistence, and no cipher routines — a stripped social-engineering masquerade variant matching siblings a5ebbaa4, f7352bc1, and 485f73af. The OpenCTI formbook co-label is a false positive. ^[file.txt] ^[strings.txt:68]

What It Is

Attribute Observation
SHA-256 580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6
File name (lure) MV_GREAT_AMITY_QUOTATION_FORMS.exe — RFQ/quotation social engineering
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Size 1,087,488 bytes (1.04 MB)
Timestamp 2026-05-26 06:44:43 UTC ^[pefile.txt:34]
Compiler .NET Framework 4.5 (v4.0.30319), Visual Studio 2019–2022 linker v48.0 ^[rabin2-info.txt]
Language / runtime C# / CIL (MSIL) — full unobfuscated metadata recoverable from #Strings
Obfuscator None ^[strings.txt]
Packer None — standard .text/.rsrc/.reloc layout, .text entropy 7.78 (expected for compiled CIL) ^[pefile.txt:92]
Signed No ^[rabin2-info.txt:27]
Entry point mscoree.dll!_CorExeMain via CLR COM descriptor at RVA 0x2008 ^[pefile.txt:183]

Version-info masquerade claims "Card Battler TCG Mini Game in Uzbek" / CardBattle / yFzH.exe / Copyright 2026 — contradicting the quotation-form lure filename. ^[exiftool.json:36-44]

Family ascription is high-confidence based on:

  • Recurring Anneal_Crucible_Batch compiler-generated method name ^[strings.txt:7,18,26,31,39,44,47,49,52,54,56,57,58,60,280]
  • Recurring transectAllowance field name ^[strings.txt:186]
  • CardBattle namespace and CardBattle.Properties.Resources CLR resource class ^[strings.txt:68,207,514]
  • Uzbek-language UI strings: UyinchiHP, DushmanHP, Mudofaa, Tanga, JangOynasiniYangilash, NavbatniUynash ^[strings.txt:70-101]
  • Full WinForms game surface: BattleForm, CollectionForm, DeckBuilderForm ^[strings.txt:421-423]
  • No System.Net references, no WebClient, no Socket, no HttpWebRequest ^[strings.txt]
  • Debug-build attributes (DebuggerNonUserCodeAttribute, DebuggableAttribute, DebuggerBrowsableAttribute) causing capa false positives — same pattern as all AvalancheRunner siblings ^[strings.txt:245-247]

This sample is not Formbook. Formbook in this corpus is an AutoIt-compiled dropper with shellcode bootstrap, stride-3 hex obfuscation, and GetTickCount timing gate. See formbook for the real family. ^[entities/formbook.md]

How It Works

The binary is a complete, unobfuscated .NET Framework WinForms application. No dynamic execution analysis is available (CAPE skipped — no Windows guest), but static inspection reveals a fully functional TCG deck-builder and battle simulator:

  • Deck building: DastaQurishniOchish, DastagaKartaQoshish, DastaniSaqlash ^[strings.txt:295,298,289]
  • Card collection: KoleksiyaMenejeri, KartaKoleksiyasiData, YangilashKolleksiya ^[strings.txt:365,107,121]
  • Battle engine: JangBoshlashgaTayyorlash, KartaUynash, NavbatniUynash, TekshirishUyinYakuni ^[strings.txt:291,292,293,359]
  • Game state: HP/mana bars (UyinchiHP, DushmanHP, MaksMana, JoriyMana), defense (Mudofaa), currency (Tanga) ^[strings.txt:70-101]

No malicious behavior observed statically. No encrypted CLR resource blob (unlike siblings 1a38a948, 2d9f8c6e, 64e2d169). The .rsrc section contains only the standard VS_VERSIONINFO and an RT_MANIFEST XML document. ^[binwalk.txt] ^[pefile.txt:99-117]

The threat is purely social-engineering masquerade: a victim expecting a quotation/RFQ document double-clicks what appears to be a .exe file (Windows hides extensions by default), and instead launches a card game. Whether the game is a genuine decoy or a stripped payload loader missing its inner stage is indeterminate from static analysis alone; the absence of encrypted resources and cipher routines suggests the former.

Decompiled Behavior

No Ghidra decompilation required — the binary is fully unobfuscated .NET with all type names, method names, and field names present in #Strings metadata. Radare2 confirms lang: cil, stripped: false, static: false, subsys: dotnet. ^[rabin2-info.txt]

Notable control-flow patterns from strings:

  • Entry point: Program.Main → BattleForm / CollectionForm / DeckBuilderForm instantiation ^[strings.txt:412,421-423]
  • Event handlers: btnJangBoshlash_Click, btnYakunlash_Click, btnSaqlash_Click, btnDasta_Click, btnKolleksiya_Click ^[strings.txt:383-391]
  • Data layer: KartaKoleksiyasiData, DastaKartalariDataTable, UyinchiMaLumotlariDataTable — typed DataSet/DataTable classes ^[strings.txt:107,198,199,363]
  • Resource manager: CardBattle.Properties.Resources with standard ResourceManager/CultureInfo pattern ^[strings.txt:488,470,514]

No P/Invoke imports, no DllImport attributes, no unsafe code blocks. The entire API surface is managed BCL (System.Drawing, System.Windows.Forms, System.Data, System.Resources).

C2 Infrastructure

None recovered. No hardcoded URLs, IPs, domains, mutex names, named pipes, or registry keys. No System.Net namespace references. If a C2 exists, it is runtime-resolved from an external config not embedded in this binary — but the stripped nature of the sample makes this unlikely.

Interesting Tidbits

  • Uzbek TCG skin: This is the second trading-card-game variant in the cluster (after sibling a5ebbaa4's CardBattle skin). Deck-building, card-draw, mana/HP bars, battle journal (JangJurnali) — a surprisingly complete game surface for malware. ^[strings.txt:332-334]
  • "Anneal_Crucible_Batch" compiler artefact: The same compiler-generated closure-method name appears in all seven AvalancheRunner siblings spanning 2020–2026. This is almost certainly a Roslyn compiler artefact from a specific async/await or lambda pattern reused across the builder's codebase, not a deliberate watermark. ^[strings.txt:280]
  • Quotation-form lure: Previous siblings used Bank_Payment_Advice, TT01650Q logistics tracking, documents.exe, and z1EDG0012026051400140040_1669_pdf.bat. This sample adds RFQ/quotation (QUOTATION_FORMS) to the social-engineering repertoire. ^[triage.json:5]
  • Debug build capa false positives: DebuggerNonUserCodeAttribute + DebuggableAttribute trigger capa reference analysis tools strings, generate random numbers in .NET, and ATT&CK T1083 / T1620. This is a known false-positive pattern documented at debug-build-capa-false-positives. ^[capa.txt] ^[strings.txt:245-247]
  • No ConfuserEx, no SmartAssembly, no Xenocode: Fully readable IL. The builder does not invest in .NET obfuscation — the evasion is purely filename + version-info masquerade.

How To Mess With It (Homelab Replication)

Goal: Build a .NET Framework 4.5 WinForms app with comparable capa fingerprint and version-info masquerade, then verify the false-positive pattern.

  1. Toolchain: Visual Studio 2019 or 2022, .NET Framework 4.5 target, C# WinForms project.
  2. Code: Create a simple WinForms app with:
    • DebuggerNonUserCodeAttribute on generated designer code (Visual Studio adds this by default in Debug builds)
    • DebuggableAttribute in AssemblyInfo.cs ([assembly: Debuggable(DebuggableAttribute.DebuggingModes.Default | DebuggableAttribute.DebuggingModes.DisableOptimizations)])
    • A Random instance calling Next() — capa will flag generate random numbers in .NET
    • File.Exists() check — capa will flag check if file exists → T1083
  3. Version info: Set FileDescription, ProductName, Comments, InternalName to benign-sounding game or utility names. Contradict with a business-document filename at distribution time.
  4. Build: Compile in Debug configuration (not Release). This is the critical step that produces the capa false positives.
  5. Verification:
    capa reproducer.exe
    
    Expect hits: compiled to the .NET platform, generate random numbers in .NET, check if file exists, reference analysis tools strings, access .NET resource. Compare to this sample's capa.txt — same false-positive fingerprint.
  6. What you learn: How capa's heuristic rule set can be fooled by legitimate debug-build attributes, and why debug-build .NET binaries require human triage before threat inference.

Deployable Signatures

YARA Rule

rule AvalancheRunner_Stripped_Masquerade {
    meta:
        description = "AvalancheRunner .NET game-masquerade cluster — stripped variant (no encrypted payload)"
        author = "Titus / PacketPursuit"
        date = "2026-07-31"
        confidence = "high"
        family = "avalancherunner"
        reference = "/intel/analyses/580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6.html"
    strings:
        $anneal = "Anneal_Crucible_Batch" ascii wide
        $transect = "transectAllowance" ascii wide
        $cardbattle = "CardBattle" ascii wide
        $uzbek1 = "UyinchiHP" ascii wide
        $uzbek2 = "DushmanHP" ascii wide
        $uzbek3 = "Mudofaa" ascii wide
        $uzbek4 = "Tanga" ascii wide
        $dotnet = "v4.0.30319" ascii wide
        $mscoree = "mscoree.dll" ascii
    condition:
        uint16(0) == 0x5A4D and
        pe.characteristics & pe.EXECUTABLE_IMAGE and
        pe.subsystem == pe.SUBSYSTEM_WINDOWS_GUI and
        $dotnet and
        $mscoree and
        (
            ($anneal and $transect) or
            ($cardbattle and any of ($uzbek*))
        ) and
        filesize < 3MB
}

Sigma Rule

title: AvalancheRunner Masquerade Execution
description: Detects execution of AvalancheRunner .NET game-masquerade binaries distributed under business-document filenames
status: experimental
logsource:
    category: process_creation
    product: windows
detection:
    selection_filename:
        CommandLine|contains:
            - 'QUOTATION'
            - 'PURCHASE_ORDER'
            - 'Bank_Payment_Advice'
            - 'TT01650Q'
            - 'INVOICE'
            - 'RFQ'
            - 'documents.exe'
    selection_vi_product:
        Product: 'CardBattle'
    selection_vi_description:
        Description|contains: 'TCG Mini Game in Uzbek'
    selection_vi_bomba:
        Product: 'BombaZarasizlantiruvchi'
    selection_vi_particle:
        Product: 'ParticlePlayground'
    selection_vi_ava:
        Description|contains: 'AvalancheRunner'
    condition: selection_filename or any of selection_vi_*
falsepositives:
    - Legitimate game developer distributing under business filenames (unlikely)
level: medium

IOC List

Type Value Note
SHA-256 580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6 This sample
Filename MV_GREAT_AMITY_QUOTATION_FORMS.exe RFQ lure
VersionInfo ProductName CardBattle Game masquerade
VersionInfo FileDescription CardBattle Game masquerade
VersionInfo Comments Card Battler TCG Mini Game in Uzbek Game masquerade
VersionInfo InternalName yFzH.exe Randomized per sample
PE Timestamp 2026-05-26 06:44:43 UTC Build time

Behavioral Fingerprint Statement

This binary is a .NET Framework 4.5 PE32 compiled in Debug configuration, presenting as a complete Uzbek-language trading-card-game WinForms application with deck-building, card collection, and battle mechanics. It is distributed under business-document filenames (quotation, purchase order, bank payment advice, logistics tracking) to exploit social engineering. The binary contains no packing, no obfuscation, no encrypted payload resources, no network API imports, and no persistence mechanisms. Capa static analysis produces false positives for ATT&CK T1083 and T1620 due to DebuggableAttribute and DebuggerNonUserCodeAttribute compiler artefacts. Detection should focus on version-info / filename contradiction rather than runtime behavior.

Detection Signatures

Capability ATT&CK Source
File and Directory Discovery T1083 capa check if file exists — false positive from debug build ^[capa.txt:15]
Reflective Code Loading T1620 capa load .NET assembly / invoke .NET assembly method — false positive from debug build ^[capa.txt:28-34]
Masquerading T1036.005 Version info claims game, filename claims business document ^[exiftool.json:36-44]
Generate Pseudo-random Sequence — capa generate random numbers in .NET — benign Random.Next() usage ^[capa.txt:29]

References

  • Artifact ID: 0b1afd0b-b179-435e-85f6-2912749e4cc7 ^[metadata.json]
  • Source: OpenCTI / MalwareBazaar (triage label formbook — false positive)
  • Sibling analyses:
    • 1a38a948 — May 2020, Bank_Payment_Advice20396.exe, encrypted payload present ^[/intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html]
    • 2d9f8c6e — Dec 2022, LHUS.exe, encrypted payload present ^[/intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html]
    • f7352bc1 — May 2026, z1EDG0012026051400140040_1669_pdf.bat, stripped ^[/intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html]
    • 485f73af — May 2026, QVVr.exe, stripped, ParticlePlayground skin ^[/intel/analyses/485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0.html]
    • 64e2d169 — May 2026, TT01650Q0986854CNAMX.exe, encrypted payload restored ^[/intel/analyses/64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a.html]
    • a5ebbaa4 — May 2026, documents.exe, stripped, CardBattle TCG skin ^[/intel/analyses/a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc.html]
  • Related wiki pages: avalancherunner, formbook, debug-build-capa-false-positives, version-info-masquerade, social-engineering-filename-lure

Provenance

Static analysis of <sample 580095fa81f7.bin> using:

  • file (PE32 .NET), exiftool (version info), pefile (headers + sections + imports + resources + relocations)
  • strings (2171 recoverable strings from #Strings metadata and CIL)
  • floss (failed — .NET binary, no stack strings to decode)
  • capa v7.0.0 static analysis (false positives documented)
  • binwalk (PNG + zlib + XML in .rsrc, no encrypted overlay)
  • radare2 rabin2 -I (CIL / dotnet / unstripped / no packing / unsigned)
  • ssdeep (24576 block size, no close hash match to prior siblings)
  • Manual string inspection for AvalancheRunner fingerprint verification

CAPE detonation skipped — no Windows guest available. Dynamic behavior is unobserved.