typeanalysisfamilyavalancherunnerconfidencemediumcreated2026-08-25updated2026-08-25dotnetmasqueradingevasionmitre-attckdebug-build-capa-fpdouble-extension-masquerade
SHA-256: 5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74

avalancherunner: 5b4f596d — DWG+RFQ .bat-extension masquerade, CardBattle TCG skin

Executive Summary

Eighth confirmed sibling in the AvalancheRunner .NET Framework 4.5 cluster. Presents as a fully functional Uzbek-language trading-card-game WinForms application (CardBattle) but is distributed under a DWG-drawing + RFQ-filename lure ending in .bat while actually being a PE32 .NET executable. No encrypted payload blob, no network surface, no persistence, and no cipher routines — a stripped social-engineering masquerade variant matching siblings a5ebbaa4, 580095fa, f7352bc1, and 485f73af. Static-only analysis (CAPE skipped — no Windows guest). ^[file.txt] ^[strings.txt:263]

What It Is

Attribute Observation
SHA-256 5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74
File name (lure) DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat — DWG drawing + RFQ social engineering, .bat extension masquerade ^[triage.json:5]
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Size 1,102,336 bytes (~1.08 MB) ^[triage.json:12]
Timestamp 2026-05-26 04:29:08 UTC ^[pefile.txt:34]
Compiler .NET Framework 4.5 (v4.0.30319), Visual Studio linker v48.0 ^[rabin2-info.txt]
Language / runtime C# / CIL (MSIL) — full unobfuscated metadata recoverable from #Strings
Obfuscator None ^[strings.txt]
Packer None — standard .text/.rsrc/.reloc layout, .text entropy 7.79 (expected for compiled CIL + embedded PNG assets) ^[pefile.txt:92]
Signed No ^[rabin2-info.txt:27]
Entry point mscoree.dll!_CorExeMain via CLR COM descriptor at RVA 0x2008 ^[pefile.txt:183]

Version-info masquerade claims empty product/description/copyright fields with internal name bfgQ.exe and assembly version 0.0.0.0 — contradicting the engineering-document lure filename. ^[exiftool.json:36-44]

Family ascription is high-confidence based on:

  • Recurring Anneal_Crucible_Batch compiler-generated method name (15 occurrences) ^[strings.txt:7,18,26,31,39,44,47,49,52,54,56,57,58,60,280]
  • Recurring transectAllowance field name ^[strings.txt:185]
  • CardBattle namespace and CardBattle.Properties.Resources CLR resource class ^[strings.txt:67,207,514]
  • Uzbek-language UI strings: UyinchiHP, DushmanHP, Mudofaa, Tanga, JangOynasiniYangilash, NavbatniUynash ^[strings.txt:70-101]
  • Full WinForms game surface: BattleForm, CollectionForm, DeckBuilderForm ^[strings.txt:421-423]
  • No System.Net references, no WebClient, no Socket, no HttpWebRequest ^[strings.txt]
  • Hardcoded 64-character hex string AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C (same exact string in siblings a5ebbaa4 and 64e2d169) ^[strings.txt:63]
  • Debug-build attributes (DebuggerNonUserCodeAttribute, DebuggableAttribute, DebuggerBrowsableAttribute) causing capa false positives — same pattern as all AvalancheRunner siblings ^[strings.txt:244-246]

This sample is not Formbook. Formbook in this corpus is an AutoIt-compiled dropper with shellcode bootstrap. See formbook for the real family. ^[entities/formbook.md]

How It Works

The binary is a complete, unobfuscated .NET Framework WinForms application. No dynamic execution analysis is available (CAPE skipped — no Windows guest), but static inspection reveals a fully functional TCG deck-builder and battle simulator:

  • Deck building: DastaQurishniOchish, DastagaKartaQoshish, DastaniSaqlash ^[strings.txt:295,298,289]
  • Card collection: KoleksiyaMenejeri, KartaKoleksiyasiData, YangilashKolleksiya ^[strings.txt:365,107,121]
  • Battle engine: JangBoshlashgaTayyorlash, KartaUynash, NavbatniUynash, TekshirishUyinYakuni ^[strings.txt:291,292,293,359]
  • Game state: HP/mana bars (UyinchiHP, DushmanHP, MaksMana, JoriyMana), defense (Mudofaa), currency (Tanga) ^[strings.txt:70-101]

No malicious behavior observed statically. No encrypted CLR resource blob (unlike siblings 1a38a948, 2d9f8c6e, 64e2d169). The .rsrc section contains only the standard VS_VERSIONINFO and an RT_MANIFEST XML document. ^[binwalk.txt] ^[pefile.txt:99-117]

The threat is purely social-engineering masquerade: a victim expecting a DWG engineering drawing or RFQ document double-clicks what appears to be a .bat file, and instead launches a card game. The .bat extension in the filename while the file is actually a PE executable is a double-extension-masquerade variant — Explorer may show the .bat icon or name while the file header is MZ/PE. ^[triage.json:5] ^[file.txt]

Decompiled Behavior

No Ghidra decompilation required — the binary is fully unobfuscated .NET with all type names, method names, and field names present in #Strings metadata. Radare2 confirms lang: cil, stripped: false, static: false, subsys: dotnet. ^[rabin2-info.txt]

Notable control-flow patterns from strings:

  • Entry point: Program.Main → BattleForm / CollectionForm / DeckBuilderForm instantiation ^[strings.txt:412,421-423]
  • Event handlers: btnJangBoshlash_Click, btnYakunlash_Click, btnSaqlash_Click, btnDasta_Click, btnKolleksiya_Click ^[strings.txt:383-391]
  • Data layer: KartaKoleksiyasiData, DastaKartalariDataTable, UyinchiMaLumotlariDataTable — typed DataSet/DataTable classes ^[strings.txt:107,198,199,363]
  • Resource manager: CardBattle.Properties.Resources with standard ResourceManager/CultureInfo pattern ^[strings.txt:488,470,514]

No P/Invoke imports, no DllImport attributes, no unsafe code blocks. The entire API surface is managed BCL (System.Drawing, System.Windows.Forms, System.Data, System.Resources).

C2 Infrastructure

None recovered. No hardcoded URLs, IPs, domains, mutex names, named pipes, or registry keys. No System.Net namespace references. If a C2 exists, it is runtime-resolved from an external config not embedded in this binary — but the stripped nature of the sample makes this unlikely.

Interesting Tidbits

  • .bat extension PE masquerade: This is the first AvalancheRunner sibling to carry a .bat extension in its distribution filename while actually being a PE32 .NET executable. The filename DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat combines AutoCAD drawing (DWG), engineering firm name (MENTORTECH), RFQ context, and a tracking code — then appends .bat as the apparent extension. This is a double-extension / wrong-extension masquerade distinct from the .exe lures used by prior siblings. ^[triage.json:5]
  • Build-time proximity to 580095fa: Compiled at 04:29:08 UTC, roughly 2 hours 15 minutes before sibling 580095fa (06:44:43 UTC) on the same day (2026-05-26). Both are stripped CardBattle variants with no encrypted payload, suggesting a batch build from the same builder template. ^[pefile.txt:34]
  • Size growth trend: Sibling sizes across the cluster: a5ebbaa4 860 KB → 580095fa 1,047 KB → 5b4f596d 1,075 KB. The growth tracks additional embedded PNG/bitmap game assets. Binwalk extracts a PC bitmap (183×182×32) at 0xFCEA and a PNG (650×698 RGBA) at 0x3062B. ^[binwalk.txt]
  • No Survey_Cadastral_Transect method: Unlike payload-bearing siblings 1a38a948, 2d9f8c6e, and 64e2d169, this stripped variant does not contain the anomalous cadastral-survey method name. This confirms Survey_Cadastral_Transect is linked to the encrypted payload orchestration path, not the bare game shell. ^[strings.txt]
  • Hardcoded 64-char hex string: Same AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C observed in a5ebbaa4 and 64e2d169. Cross-corpus search confirms it also appears in MassLogger and Formbook samples — likely an obfuscator watermark or builder artefact, not a cluster-unique identifier. ^[strings.txt:63] ^[concepts/embedded-sha256-integrity-hash.md]
  • No ConfuserEx, no SmartAssembly, no Xenocode: Fully readable IL. The builder does not invest in .NET obfuscation — the evasion is purely filename + version-info masquerade.

How To Mess With It (Homelab Replication)

Goal: Build a .NET Framework 4.5 WinForms app with comparable capa fingerprint and version-info masquerade, then verify the false-positive pattern.

  1. Toolchain: Visual Studio 2019 or 2022, .NET Framework 4.5 target, C# WinForms project.
  2. Code: Create a simple WinForms app with:
    • DebuggerNonUserCodeAttribute on generated designer code (Visual Studio adds this by default in Debug builds)
    • DebuggableAttribute in AssemblyInfo.cs
    • A Random instance calling Next() — capa will flag generate random numbers in .NET
    • File.Exists() check — capa will flag check if file exists → T1083
  3. Version info: Set FileDescription, ProductName, Comments, InternalName to benign-sounding game or utility names. Contradict with a business-document filename at distribution time.
  4. Build: Compile in Debug configuration (not Release). This is the critical step that produces the capa false positives.
  5. Verification:
    capa reproducer.exe
    
    Expect hits: compiled to the .NET platform, generate random numbers in .NET, check if file exists, reference analysis tools strings, access .NET resource. Compare to this sample's capa.txt — same false-positive fingerprint.

What you learn: How capa's heuristic rule set can be fooled by legitimate debug-build attributes, and why debug-build .NET binaries require human triage before threat inference.

Deployable Signatures

YARA Rule

rule AvalancheRunner_5b4f596d_DWG_RFQ_Bat_Masquerade
{
    meta:
        description = "AvalancheRunner .NET game-masquerade cluster — DWG+RFQ .bat-extension lure variant"
        author      = "pp-hermes"
        date        = "2026-08-25"
        sha256      = "5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74"
        family      = "avalancherunner"

    strings:
        $ns1 = "CardBattle.UI" ascii wide
        $ns2 = "CardBattle.Baza" ascii wide
        $ns3 = "CardBattle.Formalar" ascii wide
        $ns4 = "CardBattle.Klasslar" ascii wide
        $ui1 = "UyinchiHP" ascii wide
        $ui2 = "DushmanHP" ascii wide
        $ui3 = "JangOynasiniYangilash" ascii wide
        $ui4 = "DastaKartalariniChizish" ascii wide
        $anom = "Anneal_Crucible_Batch" ascii wide
        $transect = "transectAllowance" ascii wide
        $hash = "AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C" ascii wide
        $dotnet = "v4.0.30319" ascii wide
        $mscoree = "mscoree.dll" ascii

    condition:
        uint16(0) == 0x5A4D and
        $dotnet and
        $mscoree and
        $anom and
        $transect and
        2 of ($ns*) and
        2 of ($ui*) and
        filesize < 3MB
}

Sigma Rule

title: AvalancheRunner DWG+RFQ .bat Masquerade Execution
description: Detects execution of AvalancheRunner .NET game-masquerade binaries distributed under DWG drawing or RFQ filenames with .bat extension
status: experimental
logsource:
    category: process_creation
    product: windows
detection:
    selection_filename:
        CommandLine|contains:
            - 'DWG-'
            - 'MENTORTECH'
            - 'Quotation'
            - 'QUOTATION'
            - 'PURCHASE_ORDER'
            - 'Bank_Payment_Advice'
            - 'TT01650Q'
            - 'INVOICE'
            - 'RFQ'
            - 'documents.exe'
    selection_vi_product:
        Product: 'CardBattle'
    selection_vi_bomba:
        Product: 'BombaZarasizlantiruvchi'
    selection_vi_particle:
        Product: 'ParticlePlayground'
    selection_vi_ava:
        Description|contains: 'AvalancheRunner'
    condition: selection_filename or any of selection_vi_*
falsepositives:
    - Legitimate game developer distributing under business filenames (unlikely)
level: medium

IOC List

Type Value Note
SHA-256 5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74 This sample
Filename DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat DWG+RFQ lure with .bat extension
VersionInfo InternalName bfgQ.exe Randomized 4-char internal name
PE Timestamp 2026-05-26 04:29:08 UTC Build time
Hex string AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C Hardcoded artefact (non-unique)

Behavioral Fingerprint Statement

This binary is a .NET Framework 4.5 PE32 compiled in Debug configuration, presenting as a complete Uzbek-language trading-card-game WinForms application with deck-building, card collection, and battle mechanics. It is distributed under a DWG-engineering-drawing + RFQ filename ending in .bat while actually being a PE executable — a double-extension masquerade. The binary contains no packing, no obfuscation, no encrypted payload resources, no network API imports, and no persistence mechanisms. Capa static analysis produces false positives for ATT&CK T1083 and T1620 due to DebuggableAttribute and DebuggerNonUserCodeAttribute compiler artefacts. Detection should focus on version-info / filename / extension contradiction rather than runtime behavior.

Detection Signatures

Capability ATT&CK Source
File and Directory Discovery T1083 capa check if file exists — false positive from debug build ^[capa.txt:15]
Reflective Code Loading T1620 capa load .NET assembly / invoke .NET assembly method — false positive from debug build ^[capa.txt:28-34]
Masquerading T1036.005 Version info claims game, filename claims DWG/RFQ document, extension claims .bat ^[exiftool.json:36-44] ^[triage.json:5]
Generate Pseudo-random Sequence — capa generate random numbers in .NET — benign Random.Next() usage ^[capa.txt:29]

References

  • Artifact ID: e1fc221e-def8-4678-8e96-740473fe7ef2 ^[metadata.json]
  • Source: MalwareBazaar via OpenCTI connector (labels: exe, malware-bazaar)
  • Sibling analyses:
    • 1a38a948 — May 2020, Bank_Payment_Advice20396.exe, encrypted payload present ^[/intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html]
    • 2d9f8c6e — Dec 2022, LHUS.exe, encrypted payload present ^[/intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html]
    • f7352bc1 — May 2026, z1EDG0012026051400140040_1669_pdf.bat, stripped ^[/intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html]
    • 485f73af — May 2026, QVVr.exe, stripped, ParticlePlayground skin ^[/intel/analyses/485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0.html]
    • 64e2d169 — May 2026, TT01650Q0986854CNAMX.exe, encrypted payload restored ^[/intel/analyses/64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a.html]
    • a5ebbaa4 — May 2026, documents.exe, stripped, CardBattle TCG skin ^[/intel/analyses/a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc.html]
    • 580095fa — May 2026, MV_GREAT_AMITY_QUOTATION_FORMS.exe, stripped, CardBattle TCG skin ^[/intel/analyses/580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6.html]
  • Related wiki pages: avalancherunner, formbook, debug-build-capa-false-positives, version-info-masquerade, social-engineering-filename-lure, double-extension-masquerade, embedded-sha256-integrity-hash

Provenance

Analysis derived from static artifacts generated by the triage pipeline on 2026-05-29 and deep-dive tooling on 2026-08-25. File type from file v5.45. PE headers from pefile Python module. Strings from strings (GNU binutils). Capa v9.1.0 static analysis. Binwalk v2.3.4 for embedded file carving. Radare2 rabin2 -I for binary header summary. No CAPE detonation available (no Windows guest). No Ghidra decompilation — managed .NET assembly analyzed via IL metadata extraction.