580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6avalancherunner: 580095fa — CardBattle Uzbek TCG skin, quotation-form lure
Executive Summary
Seventh confirmed sibling in the AvalancheRunner .NET Framework 4.5 cluster. Presents as a fully functional Uzbek-language trading-card-game WinForms application (CardBattle) but is distributed under the business-document filename MV_GREAT_AMITY_QUOTATION_FORMS.exe. No encrypted payload blob, no network surface, no persistence, and no cipher routines — a stripped social-engineering masquerade variant matching siblings a5ebbaa4, f7352bc1, and 485f73af. The OpenCTI formbook co-label is a false positive. ^[file.txt] ^[strings.txt:68]
What It Is
| Attribute | Observation |
|---|---|
| SHA-256 | 580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6 |
| File name (lure) | MV_GREAT_AMITY_QUOTATION_FORMS.exe — RFQ/quotation social engineering |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Size | 1,087,488 bytes (1.04 MB) |
| Timestamp | 2026-05-26 06:44:43 UTC ^[pefile.txt:34] |
| Compiler | .NET Framework 4.5 (v4.0.30319), Visual Studio 2019–2022 linker v48.0 ^[rabin2-info.txt] |
| Language / runtime | C# / CIL (MSIL) — full unobfuscated metadata recoverable from #Strings |
| Obfuscator | None ^[strings.txt] |
| Packer | None — standard .text/.rsrc/.reloc layout, .text entropy 7.78 (expected for compiled CIL) ^[pefile.txt:92] |
| Signed | No ^[rabin2-info.txt:27] |
| Entry point | mscoree.dll!_CorExeMain via CLR COM descriptor at RVA 0x2008 ^[pefile.txt:183] |
Version-info masquerade claims "Card Battler TCG Mini Game in Uzbek" / CardBattle / yFzH.exe / Copyright 2026 — contradicting the quotation-form lure filename. ^[exiftool.json:36-44]
Family ascription is high-confidence based on:
- Recurring
Anneal_Crucible_Batchcompiler-generated method name ^[strings.txt:7,18,26,31,39,44,47,49,52,54,56,57,58,60,280] - Recurring
transectAllowancefield name ^[strings.txt:186] CardBattlenamespace andCardBattle.Properties.ResourcesCLR resource class ^[strings.txt:68,207,514]- Uzbek-language UI strings:
UyinchiHP,DushmanHP,Mudofaa,Tanga,JangOynasiniYangilash,NavbatniUynash^[strings.txt:70-101] - Full WinForms game surface:
BattleForm,CollectionForm,DeckBuilderForm^[strings.txt:421-423] - No
System.Netreferences, noWebClient, noSocket, noHttpWebRequest^[strings.txt] - Debug-build attributes (
DebuggerNonUserCodeAttribute,DebuggableAttribute,DebuggerBrowsableAttribute) causing capa false positives — same pattern as all AvalancheRunner siblings ^[strings.txt:245-247]
This sample is not Formbook. Formbook in this corpus is an AutoIt-compiled dropper with shellcode bootstrap, stride-3 hex obfuscation, and GetTickCount timing gate. See formbook for the real family. ^[entities/formbook.md]
How It Works
The binary is a complete, unobfuscated .NET Framework WinForms application. No dynamic execution analysis is available (CAPE skipped — no Windows guest), but static inspection reveals a fully functional TCG deck-builder and battle simulator:
- Deck building:
DastaQurishniOchish,DastagaKartaQoshish,DastaniSaqlash^[strings.txt:295,298,289] - Card collection:
KoleksiyaMenejeri,KartaKoleksiyasiData,YangilashKolleksiya^[strings.txt:365,107,121] - Battle engine:
JangBoshlashgaTayyorlash,KartaUynash,NavbatniUynash,TekshirishUyinYakuni^[strings.txt:291,292,293,359] - Game state: HP/mana bars (
UyinchiHP,DushmanHP,MaksMana,JoriyMana), defense (Mudofaa), currency (Tanga) ^[strings.txt:70-101]
No malicious behavior observed statically. No encrypted CLR resource blob (unlike siblings 1a38a948, 2d9f8c6e, 64e2d169). The .rsrc section contains only the standard VS_VERSIONINFO and an RT_MANIFEST XML document. ^[binwalk.txt] ^[pefile.txt:99-117]
The threat is purely social-engineering masquerade: a victim expecting a quotation/RFQ document double-clicks what appears to be a .exe file (Windows hides extensions by default), and instead launches a card game. Whether the game is a genuine decoy or a stripped payload loader missing its inner stage is indeterminate from static analysis alone; the absence of encrypted resources and cipher routines suggests the former.
Decompiled Behavior
No Ghidra decompilation required — the binary is fully unobfuscated .NET with all type names, method names, and field names present in #Strings metadata. Radare2 confirms lang: cil, stripped: false, static: false, subsys: dotnet. ^[rabin2-info.txt]
Notable control-flow patterns from strings:
- Entry point:
Program.Main→BattleForm/CollectionForm/DeckBuilderForminstantiation ^[strings.txt:412,421-423] - Event handlers:
btnJangBoshlash_Click,btnYakunlash_Click,btnSaqlash_Click,btnDasta_Click,btnKolleksiya_Click^[strings.txt:383-391] - Data layer:
KartaKoleksiyasiData,DastaKartalariDataTable,UyinchiMaLumotlariDataTable— typed DataSet/DataTable classes ^[strings.txt:107,198,199,363] - Resource manager:
CardBattle.Properties.Resourceswith standardResourceManager/CultureInfopattern ^[strings.txt:488,470,514]
No P/Invoke imports, no DllImport attributes, no unsafe code blocks. The entire API surface is managed BCL (System.Drawing, System.Windows.Forms, System.Data, System.Resources).
C2 Infrastructure
None recovered. No hardcoded URLs, IPs, domains, mutex names, named pipes, or registry keys. No System.Net namespace references. If a C2 exists, it is runtime-resolved from an external config not embedded in this binary — but the stripped nature of the sample makes this unlikely.
Interesting Tidbits
- Uzbek TCG skin: This is the second trading-card-game variant in the cluster (after sibling
a5ebbaa4'sCardBattleskin). Deck-building, card-draw, mana/HP bars, battle journal (JangJurnali) — a surprisingly complete game surface for malware. ^[strings.txt:332-334] - "Anneal_Crucible_Batch" compiler artefact: The same compiler-generated closure-method name appears in all seven AvalancheRunner siblings spanning 2020–2026. This is almost certainly a Roslyn compiler artefact from a specific async/await or lambda pattern reused across the builder's codebase, not a deliberate watermark. ^[strings.txt:280]
- Quotation-form lure: Previous siblings used
Bank_Payment_Advice,TT01650Qlogistics tracking,documents.exe, andz1EDG0012026051400140040_1669_pdf.bat. This sample adds RFQ/quotation (QUOTATION_FORMS) to the social-engineering repertoire. ^[triage.json:5] - Debug build capa false positives:
DebuggerNonUserCodeAttribute+DebuggableAttributetrigger capareference analysis tools strings,generate random numbers in .NET, and ATT&CK T1083 / T1620. This is a known false-positive pattern documented at debug-build-capa-false-positives. ^[capa.txt] ^[strings.txt:245-247] - No ConfuserEx, no SmartAssembly, no Xenocode: Fully readable IL. The builder does not invest in .NET obfuscation — the evasion is purely filename + version-info masquerade.
How To Mess With It (Homelab Replication)
Goal: Build a .NET Framework 4.5 WinForms app with comparable capa fingerprint and version-info masquerade, then verify the false-positive pattern.
- Toolchain: Visual Studio 2019 or 2022, .NET Framework 4.5 target, C# WinForms project.
- Code: Create a simple WinForms app with:
DebuggerNonUserCodeAttributeon generated designer code (Visual Studio adds this by default in Debug builds)DebuggableAttributein AssemblyInfo.cs ([assembly: Debuggable(DebuggableAttribute.DebuggingModes.Default | DebuggableAttribute.DebuggingModes.DisableOptimizations)])- A
Randominstance callingNext()— capa will flaggenerate random numbers in .NET File.Exists()check — capa will flagcheck if file exists→ T1083
- Version info: Set
FileDescription,ProductName,Comments,InternalNameto benign-sounding game or utility names. Contradict with a business-document filename at distribution time. - Build: Compile in Debug configuration (not Release). This is the critical step that produces the capa false positives.
- Verification:
Expect hits:capa reproducer.execompiled to the .NET platform,generate random numbers in .NET,check if file exists,reference analysis tools strings,access .NET resource. Compare to this sample'scapa.txt— same false-positive fingerprint. - What you learn: How capa's heuristic rule set can be fooled by legitimate debug-build attributes, and why debug-build .NET binaries require human triage before threat inference.
Deployable Signatures
YARA Rule
rule AvalancheRunner_Stripped_Masquerade {
meta:
description = "AvalancheRunner .NET game-masquerade cluster — stripped variant (no encrypted payload)"
author = "Titus / PacketPursuit"
date = "2026-07-31"
confidence = "high"
family = "avalancherunner"
reference = "/intel/analyses/580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6.html"
strings:
$anneal = "Anneal_Crucible_Batch" ascii wide
$transect = "transectAllowance" ascii wide
$cardbattle = "CardBattle" ascii wide
$uzbek1 = "UyinchiHP" ascii wide
$uzbek2 = "DushmanHP" ascii wide
$uzbek3 = "Mudofaa" ascii wide
$uzbek4 = "Tanga" ascii wide
$dotnet = "v4.0.30319" ascii wide
$mscoree = "mscoree.dll" ascii
condition:
uint16(0) == 0x5A4D and
pe.characteristics & pe.EXECUTABLE_IMAGE and
pe.subsystem == pe.SUBSYSTEM_WINDOWS_GUI and
$dotnet and
$mscoree and
(
($anneal and $transect) or
($cardbattle and any of ($uzbek*))
) and
filesize < 3MB
}
Sigma Rule
title: AvalancheRunner Masquerade Execution
description: Detects execution of AvalancheRunner .NET game-masquerade binaries distributed under business-document filenames
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_filename:
CommandLine|contains:
- 'QUOTATION'
- 'PURCHASE_ORDER'
- 'Bank_Payment_Advice'
- 'TT01650Q'
- 'INVOICE'
- 'RFQ'
- 'documents.exe'
selection_vi_product:
Product: 'CardBattle'
selection_vi_description:
Description|contains: 'TCG Mini Game in Uzbek'
selection_vi_bomba:
Product: 'BombaZarasizlantiruvchi'
selection_vi_particle:
Product: 'ParticlePlayground'
selection_vi_ava:
Description|contains: 'AvalancheRunner'
condition: selection_filename or any of selection_vi_*
falsepositives:
- Legitimate game developer distributing under business filenames (unlikely)
level: medium
IOC List
| Type | Value | Note |
|---|---|---|
| SHA-256 | 580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6 |
This sample |
| Filename | MV_GREAT_AMITY_QUOTATION_FORMS.exe |
RFQ lure |
| VersionInfo ProductName | CardBattle |
Game masquerade |
| VersionInfo FileDescription | CardBattle |
Game masquerade |
| VersionInfo Comments | Card Battler TCG Mini Game in Uzbek |
Game masquerade |
| VersionInfo InternalName | yFzH.exe |
Randomized per sample |
| PE Timestamp | 2026-05-26 06:44:43 UTC |
Build time |
Behavioral Fingerprint Statement
This binary is a .NET Framework 4.5 PE32 compiled in Debug configuration, presenting as a complete Uzbek-language trading-card-game WinForms application with deck-building, card collection, and battle mechanics. It is distributed under business-document filenames (quotation, purchase order, bank payment advice, logistics tracking) to exploit social engineering. The binary contains no packing, no obfuscation, no encrypted payload resources, no network API imports, and no persistence mechanisms. Capa static analysis produces false positives for ATT&CK T1083 and T1620 due to DebuggableAttribute and DebuggerNonUserCodeAttribute compiler artefacts. Detection should focus on version-info / filename contradiction rather than runtime behavior.
Detection Signatures
| Capability | ATT&CK | Source |
|---|---|---|
| File and Directory Discovery | T1083 | capa check if file exists — false positive from debug build ^[capa.txt:15] |
| Reflective Code Loading | T1620 | capa load .NET assembly / invoke .NET assembly method — false positive from debug build ^[capa.txt:28-34] |
| Masquerading | T1036.005 | Version info claims game, filename claims business document ^[exiftool.json:36-44] |
| Generate Pseudo-random Sequence | — | capa generate random numbers in .NET — benign Random.Next() usage ^[capa.txt:29] |
References
- Artifact ID:
0b1afd0b-b179-435e-85f6-2912749e4cc7^[metadata.json] - Source: OpenCTI / MalwareBazaar (triage label
formbook— false positive) - Sibling analyses:
1a38a948— May 2020,Bank_Payment_Advice20396.exe, encrypted payload present ^[/intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html]2d9f8c6e— Dec 2022,LHUS.exe, encrypted payload present ^[/intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html]f7352bc1— May 2026,z1EDG0012026051400140040_1669_pdf.bat, stripped ^[/intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html]485f73af— May 2026,QVVr.exe, stripped, ParticlePlayground skin ^[/intel/analyses/485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0.html]64e2d169— May 2026,TT01650Q0986854CNAMX.exe, encrypted payload restored ^[/intel/analyses/64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a.html]a5ebbaa4— May 2026,documents.exe, stripped, CardBattle TCG skin ^[/intel/analyses/a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc.html]
- Related wiki pages: avalancherunner, formbook, debug-build-capa-false-positives, version-info-masquerade, social-engineering-filename-lure
Provenance
Static analysis of <sample 580095fa81f7.bin> using:
file(PE32 .NET),exiftool(version info),pefile(headers + sections + imports + resources + relocations)strings(2171 recoverable strings from #Strings metadata and CIL)floss(failed — .NET binary, no stack strings to decode)capav7.0.0 static analysis (false positives documented)binwalk(PNG + zlib + XML in .rsrc, no encrypted overlay)radare2rabin2 -I(CIL / dotnet / unstripped / no packing / unsigned)ssdeep(24576 block size, no close hash match to prior siblings)- Manual string inspection for AvalancheRunner fingerprint verification
CAPE detonation skipped — no Windows guest available. Dynamic behavior is unobserved.