5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74avalancherunner: 5b4f596d — DWG+RFQ .bat-extension masquerade, CardBattle TCG skin
Executive Summary
Eighth confirmed sibling in the AvalancheRunner .NET Framework 4.5 cluster. Presents as a fully functional Uzbek-language trading-card-game WinForms application (CardBattle) but is distributed under a DWG-drawing + RFQ-filename lure ending in .bat while actually being a PE32 .NET executable. No encrypted payload blob, no network surface, no persistence, and no cipher routines — a stripped social-engineering masquerade variant matching siblings a5ebbaa4, 580095fa, f7352bc1, and 485f73af. Static-only analysis (CAPE skipped — no Windows guest). ^[file.txt] ^[strings.txt:263]
What It Is
| Attribute | Observation |
|---|---|
| SHA-256 | 5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74 |
| File name (lure) | DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat — DWG drawing + RFQ social engineering, .bat extension masquerade ^[triage.json:5] |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Size | 1,102,336 bytes (~1.08 MB) ^[triage.json:12] |
| Timestamp | 2026-05-26 04:29:08 UTC ^[pefile.txt:34] |
| Compiler | .NET Framework 4.5 (v4.0.30319), Visual Studio linker v48.0 ^[rabin2-info.txt] |
| Language / runtime | C# / CIL (MSIL) — full unobfuscated metadata recoverable from #Strings |
| Obfuscator | None ^[strings.txt] |
| Packer | None — standard .text/.rsrc/.reloc layout, .text entropy 7.79 (expected for compiled CIL + embedded PNG assets) ^[pefile.txt:92] |
| Signed | No ^[rabin2-info.txt:27] |
| Entry point | mscoree.dll!_CorExeMain via CLR COM descriptor at RVA 0x2008 ^[pefile.txt:183] |
Version-info masquerade claims empty product/description/copyright fields with internal name bfgQ.exe and assembly version 0.0.0.0 — contradicting the engineering-document lure filename. ^[exiftool.json:36-44]
Family ascription is high-confidence based on:
- Recurring
Anneal_Crucible_Batchcompiler-generated method name (15 occurrences) ^[strings.txt:7,18,26,31,39,44,47,49,52,54,56,57,58,60,280] - Recurring
transectAllowancefield name ^[strings.txt:185] CardBattlenamespace andCardBattle.Properties.ResourcesCLR resource class ^[strings.txt:67,207,514]- Uzbek-language UI strings:
UyinchiHP,DushmanHP,Mudofaa,Tanga,JangOynasiniYangilash,NavbatniUynash^[strings.txt:70-101] - Full WinForms game surface:
BattleForm,CollectionForm,DeckBuilderForm^[strings.txt:421-423] - No
System.Netreferences, noWebClient, noSocket, noHttpWebRequest^[strings.txt] - Hardcoded 64-character hex string
AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C(same exact string in siblingsa5ebbaa4and64e2d169) ^[strings.txt:63] - Debug-build attributes (
DebuggerNonUserCodeAttribute,DebuggableAttribute,DebuggerBrowsableAttribute) causing capa false positives — same pattern as all AvalancheRunner siblings ^[strings.txt:244-246]
This sample is not Formbook. Formbook in this corpus is an AutoIt-compiled dropper with shellcode bootstrap. See formbook for the real family. ^[entities/formbook.md]
How It Works
The binary is a complete, unobfuscated .NET Framework WinForms application. No dynamic execution analysis is available (CAPE skipped — no Windows guest), but static inspection reveals a fully functional TCG deck-builder and battle simulator:
- Deck building:
DastaQurishniOchish,DastagaKartaQoshish,DastaniSaqlash^[strings.txt:295,298,289] - Card collection:
KoleksiyaMenejeri,KartaKoleksiyasiData,YangilashKolleksiya^[strings.txt:365,107,121] - Battle engine:
JangBoshlashgaTayyorlash,KartaUynash,NavbatniUynash,TekshirishUyinYakuni^[strings.txt:291,292,293,359] - Game state: HP/mana bars (
UyinchiHP,DushmanHP,MaksMana,JoriyMana), defense (Mudofaa), currency (Tanga) ^[strings.txt:70-101]
No malicious behavior observed statically. No encrypted CLR resource blob (unlike siblings 1a38a948, 2d9f8c6e, 64e2d169). The .rsrc section contains only the standard VS_VERSIONINFO and an RT_MANIFEST XML document. ^[binwalk.txt] ^[pefile.txt:99-117]
The threat is purely social-engineering masquerade: a victim expecting a DWG engineering drawing or RFQ document double-clicks what appears to be a .bat file, and instead launches a card game. The .bat extension in the filename while the file is actually a PE executable is a double-extension-masquerade variant — Explorer may show the .bat icon or name while the file header is MZ/PE. ^[triage.json:5] ^[file.txt]
Decompiled Behavior
No Ghidra decompilation required — the binary is fully unobfuscated .NET with all type names, method names, and field names present in #Strings metadata. Radare2 confirms lang: cil, stripped: false, static: false, subsys: dotnet. ^[rabin2-info.txt]
Notable control-flow patterns from strings:
- Entry point:
Program.Main→BattleForm/CollectionForm/DeckBuilderForminstantiation ^[strings.txt:412,421-423] - Event handlers:
btnJangBoshlash_Click,btnYakunlash_Click,btnSaqlash_Click,btnDasta_Click,btnKolleksiya_Click^[strings.txt:383-391] - Data layer:
KartaKoleksiyasiData,DastaKartalariDataTable,UyinchiMaLumotlariDataTable— typed DataSet/DataTable classes ^[strings.txt:107,198,199,363] - Resource manager:
CardBattle.Properties.Resourceswith standardResourceManager/CultureInfopattern ^[strings.txt:488,470,514]
No P/Invoke imports, no DllImport attributes, no unsafe code blocks. The entire API surface is managed BCL (System.Drawing, System.Windows.Forms, System.Data, System.Resources).
C2 Infrastructure
None recovered. No hardcoded URLs, IPs, domains, mutex names, named pipes, or registry keys. No System.Net namespace references. If a C2 exists, it is runtime-resolved from an external config not embedded in this binary — but the stripped nature of the sample makes this unlikely.
Interesting Tidbits
.batextension PE masquerade: This is the first AvalancheRunner sibling to carry a.batextension in its distribution filename while actually being a PE32 .NET executable. The filenameDWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.batcombines AutoCAD drawing (DWG), engineering firm name (MENTORTECH), RFQ context, and a tracking code — then appends.batas the apparent extension. This is a double-extension / wrong-extension masquerade distinct from the.exelures used by prior siblings. ^[triage.json:5]- Build-time proximity to 580095fa: Compiled at 04:29:08 UTC, roughly 2 hours 15 minutes before sibling
580095fa(06:44:43 UTC) on the same day (2026-05-26). Both are stripped CardBattle variants with no encrypted payload, suggesting a batch build from the same builder template. ^[pefile.txt:34] - Size growth trend: Sibling sizes across the cluster:
a5ebbaa4860 KB →580095fa1,047 KB →5b4f596d1,075 KB. The growth tracks additional embedded PNG/bitmap game assets. Binwalk extracts a PC bitmap (183×182×32) at 0xFCEA and a PNG (650×698 RGBA) at 0x3062B. ^[binwalk.txt] - No
Survey_Cadastral_Transectmethod: Unlike payload-bearing siblings1a38a948,2d9f8c6e, and64e2d169, this stripped variant does not contain the anomalous cadastral-survey method name. This confirmsSurvey_Cadastral_Transectis linked to the encrypted payload orchestration path, not the bare game shell. ^[strings.txt] - Hardcoded 64-char hex string: Same
AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068Cobserved ina5ebbaa4and64e2d169. Cross-corpus search confirms it also appears in MassLogger and Formbook samples — likely an obfuscator watermark or builder artefact, not a cluster-unique identifier. ^[strings.txt:63] ^[concepts/embedded-sha256-integrity-hash.md] - No ConfuserEx, no SmartAssembly, no Xenocode: Fully readable IL. The builder does not invest in .NET obfuscation — the evasion is purely filename + version-info masquerade.
How To Mess With It (Homelab Replication)
Goal: Build a .NET Framework 4.5 WinForms app with comparable capa fingerprint and version-info masquerade, then verify the false-positive pattern.
- Toolchain: Visual Studio 2019 or 2022, .NET Framework 4.5 target, C# WinForms project.
- Code: Create a simple WinForms app with:
DebuggerNonUserCodeAttributeon generated designer code (Visual Studio adds this by default in Debug builds)DebuggableAttributein AssemblyInfo.cs- A
Randominstance callingNext()— capa will flaggenerate random numbers in .NET File.Exists()check — capa will flagcheck if file exists→ T1083
- Version info: Set
FileDescription,ProductName,Comments,InternalNameto benign-sounding game or utility names. Contradict with a business-document filename at distribution time. - Build: Compile in Debug configuration (not Release). This is the critical step that produces the capa false positives.
- Verification:
Expect hits:capa reproducer.execompiled to the .NET platform,generate random numbers in .NET,check if file exists,reference analysis tools strings,access .NET resource. Compare to this sample'scapa.txt— same false-positive fingerprint.
What you learn: How capa's heuristic rule set can be fooled by legitimate debug-build attributes, and why debug-build .NET binaries require human triage before threat inference.
Deployable Signatures
YARA Rule
rule AvalancheRunner_5b4f596d_DWG_RFQ_Bat_Masquerade
{
meta:
description = "AvalancheRunner .NET game-masquerade cluster — DWG+RFQ .bat-extension lure variant"
author = "pp-hermes"
date = "2026-08-25"
sha256 = "5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74"
family = "avalancherunner"
strings:
$ns1 = "CardBattle.UI" ascii wide
$ns2 = "CardBattle.Baza" ascii wide
$ns3 = "CardBattle.Formalar" ascii wide
$ns4 = "CardBattle.Klasslar" ascii wide
$ui1 = "UyinchiHP" ascii wide
$ui2 = "DushmanHP" ascii wide
$ui3 = "JangOynasiniYangilash" ascii wide
$ui4 = "DastaKartalariniChizish" ascii wide
$anom = "Anneal_Crucible_Batch" ascii wide
$transect = "transectAllowance" ascii wide
$hash = "AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C" ascii wide
$dotnet = "v4.0.30319" ascii wide
$mscoree = "mscoree.dll" ascii
condition:
uint16(0) == 0x5A4D and
$dotnet and
$mscoree and
$anom and
$transect and
2 of ($ns*) and
2 of ($ui*) and
filesize < 3MB
}
Sigma Rule
title: AvalancheRunner DWG+RFQ .bat Masquerade Execution
description: Detects execution of AvalancheRunner .NET game-masquerade binaries distributed under DWG drawing or RFQ filenames with .bat extension
status: experimental
logsource:
category: process_creation
product: windows
detection:
selection_filename:
CommandLine|contains:
- 'DWG-'
- 'MENTORTECH'
- 'Quotation'
- 'QUOTATION'
- 'PURCHASE_ORDER'
- 'Bank_Payment_Advice'
- 'TT01650Q'
- 'INVOICE'
- 'RFQ'
- 'documents.exe'
selection_vi_product:
Product: 'CardBattle'
selection_vi_bomba:
Product: 'BombaZarasizlantiruvchi'
selection_vi_particle:
Product: 'ParticlePlayground'
selection_vi_ava:
Description|contains: 'AvalancheRunner'
condition: selection_filename or any of selection_vi_*
falsepositives:
- Legitimate game developer distributing under business filenames (unlikely)
level: medium
IOC List
| Type | Value | Note |
|---|---|---|
| SHA-256 | 5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74 |
This sample |
| Filename | DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat |
DWG+RFQ lure with .bat extension |
| VersionInfo InternalName | bfgQ.exe |
Randomized 4-char internal name |
| PE Timestamp | 2026-05-26 04:29:08 UTC |
Build time |
| Hex string | AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C |
Hardcoded artefact (non-unique) |
Behavioral Fingerprint Statement
This binary is a .NET Framework 4.5 PE32 compiled in Debug configuration, presenting as a complete Uzbek-language trading-card-game WinForms application with deck-building, card collection, and battle mechanics. It is distributed under a DWG-engineering-drawing + RFQ filename ending in .bat while actually being a PE executable — a double-extension masquerade. The binary contains no packing, no obfuscation, no encrypted payload resources, no network API imports, and no persistence mechanisms. Capa static analysis produces false positives for ATT&CK T1083 and T1620 due to DebuggableAttribute and DebuggerNonUserCodeAttribute compiler artefacts. Detection should focus on version-info / filename / extension contradiction rather than runtime behavior.
Detection Signatures
| Capability | ATT&CK | Source |
|---|---|---|
| File and Directory Discovery | T1083 | capa check if file exists — false positive from debug build ^[capa.txt:15] |
| Reflective Code Loading | T1620 | capa load .NET assembly / invoke .NET assembly method — false positive from debug build ^[capa.txt:28-34] |
| Masquerading | T1036.005 | Version info claims game, filename claims DWG/RFQ document, extension claims .bat ^[exiftool.json:36-44] ^[triage.json:5] |
| Generate Pseudo-random Sequence | — | capa generate random numbers in .NET — benign Random.Next() usage ^[capa.txt:29] |
References
- Artifact ID:
e1fc221e-def8-4678-8e96-740473fe7ef2^[metadata.json] - Source: MalwareBazaar via OpenCTI connector (labels:
exe,malware-bazaar) - Sibling analyses:
1a38a948— May 2020,Bank_Payment_Advice20396.exe, encrypted payload present ^[/intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html]2d9f8c6e— Dec 2022,LHUS.exe, encrypted payload present ^[/intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html]f7352bc1— May 2026,z1EDG0012026051400140040_1669_pdf.bat, stripped ^[/intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html]485f73af— May 2026,QVVr.exe, stripped, ParticlePlayground skin ^[/intel/analyses/485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0.html]64e2d169— May 2026,TT01650Q0986854CNAMX.exe, encrypted payload restored ^[/intel/analyses/64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a.html]a5ebbaa4— May 2026,documents.exe, stripped, CardBattle TCG skin ^[/intel/analyses/a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc.html]580095fa— May 2026,MV_GREAT_AMITY_QUOTATION_FORMS.exe, stripped, CardBattle TCG skin ^[/intel/analyses/580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6.html]
- Related wiki pages: avalancherunner, formbook, debug-build-capa-false-positives, version-info-masquerade, social-engineering-filename-lure, double-extension-masquerade, embedded-sha256-integrity-hash
Provenance
Analysis derived from static artifacts generated by the triage pipeline on 2026-05-29 and deep-dive tooling on 2026-08-25. File type from file v5.45. PE headers from pefile Python module. Strings from strings (GNU binutils). Capa v9.1.0 static analysis. Binwalk v2.3.4 for embedded file carving. Radare2 rabin2 -I for binary header summary. No CAPE detonation available (no Windows guest). No Ghidra decompilation — managed .NET assembly analyzed via IL metadata extraction.