64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6aavalancherunner: 64e2d169 — TT01650Q tracking-code lure, encrypted payload restored, hardcoded SHA-256 hash
Executive Summary
Fifth confirmed sibling in the AvalancheRunner cluster. A .NET Framework 4.5 WinForms PE32 masquerading as an Uzbek-language arcade game (AvalancheRunner), distributed under a logistics-tracking filename (TT01650Q0986854CNAMX.exe). Unlike the two most recent siblings (f7352bc1, 485f73af), this sample restores the encrypted CLR resource payload and the Shifrlash/Deshifrlash cipher routines that were absent in the 2026 no-payload variants. Also carries a hardcoded 64-character hex string resembling a SHA-256 hash — purpose unconfirmed. OpenCTI co-labels this sample formbook; that attribution is a false positive based on social-engineering filename overlap.
Static-only analysis (CAPE skipped — no Windows guest). No network or persistence APIs recovered.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a |
| Filename | TT01650Q0986854CNAMX.exe |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Size | 1,021,952 bytes (~998 KB) |
| Compile time | Fri May 22 16:04:20 2026 UTC ^[pefile.txt:34] ^[exiftool.json:15] |
| .NET runtime | v4.0.30319 → .NET Framework 4.5 ^[strings.txt:7] |
| Generator | System.Resources.Tools.StronglyTypedResourceBuilder / Microsoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator v16.10.0.0 ^[strings.txt:561-563] |
| Internal name | iFbN.exe ^[exiftool.json:40] |
| Signing | Unsigned ^[pefile.txt] |
| Packing / obfuscation | None — fully unobfuscated IL metadata ^[capa.txt] |
| Import surface | Single import: mscoree.dll._CorExeMain ^[pefile.txt:255] |
| OpenCTI label | formbook (false-positive co-label; see below) ^[metadata.json:8] |
How It Works
Cluster delta — payload restored
The AvalancheRunner cluster has four prior siblings spanning 2020–2026:
| Sibling | Date | Payload | Cipher |
|---|---|---|---|
1a38a948 |
May 2020 | ~952 KB encrypted CLR resource blob | Shifrlash/Deshifrlash + ObfKalit |
2d9f8c6e |
Dec 2022 | ~952 KB encrypted CLR resource blob | Same cipher |
f7352bc1 |
May 2026 | None — stripped to bare game | Absent |
485f73af |
May 2026 | None — stripped to bare game + PNG asset | Absent |
64e2d169 |
May 2026 | Encrypted CLR resource blob restored | Shifrlash/Deshifrlash + ObfKalit restored |
This sample proves the encrypted payload variant is still alive in May 2026, alongside the stripped decoy-only builds. The builder or repackager appears to toggle payload inclusion at compile time.
Embedded resources
Three CLR .resources files are embedded:
AvalancheRunner.NatijaFormasi.resources— results/high-score form UI resources ^[strings.txt:443]AvalancheRunner.OyinFormasi.resources— game form UI resources ^[strings.txt:444]AvalancheRunner.Properties.Resources.resources— property resources, includingCKTandWZPUbitmap getters ^[strings.txt:445] ^[strings.txt:340] ^[strings.txt:571-573]
System.Drawing.Bitmap references (lines 569–573) indicate image assets are stored as embedded resources, not external files. The CKT and WZPU getters suggest at least two named bitmap resources.
Cipher routines
Four managed cipher methods are present in the AvalancheRunner.XavfsizHisoblagich (SecurityCalculator) class:
Shifrlash— encrypt routine ^[strings.txt:214] ^[r2:0x00405154]Deshifrlash— decrypt routine ^[strings.txt:215] ^[r2:0x00405194]ShifrlashSatr— encrypt string ^[strings.txt:433] ^[r2:0x00405248]DeshifrlashSatr— decrypt string ^[strings.txt:434] ^[r2:0x004052b5]
The ObfKalit (ObfuscationKey) property ^[strings.txt:495] ^[r2 exports] is the hardcoded key material for these routines. The exact algorithm is not recoverable from strings alone; it is likely a simple XOR or substitution cipher given the "Shifrlash" (Uzbek for "encryption") naming convention in prior siblings.
Hardcoded SHA-256-like string
Line 32 of strings.txt contains a 64-character uppercase hex string:
C3BD7E9AB552CACF3C151F2672CBDEE2B5C935DD163CCC021BDE3ABDFC5F969A
This does not match the sample's own SHA-256. A corpus search returned no matching sibling. It matches the embedded-sha256-integrity-hash pattern observed in other .NET Framework PE32 samples (e.g., 3c9f96db, e04d46ff, 0d3d6bb9). Purpose unknown — candidate explanations: companion-payload integrity check, license watermark, or developer artefact. ^[strings.txt:32] ^[concepts/embedded-sha256-integrity-hash.md]
The formbook false positive
OpenCTI tags this sample formbook ^[metadata.json:8] ^[triage.json:19]. The real Formbook family in this corpus (a4cb4c76, 3424a53f) is an AutoIt-compiled dropper with shellcode bootstrap, stride-3 hex obfuscation, and GetTickCount timing gates — a completely different build stack. The only overlap is social-engineering: both use business-document or tracking-code filenames. This sample is not Formbook.
Decompiled Behavior
Radare2 CIL analysis finds 435 functions and 159 exports. The entry point is standard .NET mscoree.dll._CorExeMain ^[pefile.txt:255]. Notable exported methods include:
AvalancheRunner.Program.Mainat0x00402246— standard WinForms entryAvalancheRunner.OyinFormasi.Survey_Cadastral_Transectat0x00402328— the anomalous cadastral-survey method name that recurs across all five siblings ^[r2:0x00402328]AvalancheRunner.XavfsizHisoblagich.Shifrlashat0x00405154— encryption routine ^[r2:0x00405154]AvalancheRunner.XavfsizHisoblagich.Deshifrlashat0x00405194— decryption routine ^[r2:0x00405194]
The Survey_Cadastral_Transect decompilation is heavily obfuscated by radare2's CIL backend (stack-machine pseudo-code with unresolved 0x2b00000N tokens), but the presence of the method and its delegate chain confirms it is not dead code. Prior siblings show this method is linked to payload orchestration.
No P/Invoke imports, no System.Runtime.InteropServices native calls, and no Assembly.Load(byte[]) or Delegate.CreateDelegate strings are recovered — suggesting the reflective loading (if any) is performed through standard .NET resource stream APIs rather than raw memory manipulation.
C2 Infrastructure
None recovered. No System.Net, WebClient, HttpWebRequest, Socket, SmtpClient, Mail, Dns, TcpClient, or UdpClient strings are present ^[strings.txt search].
If a second-stage payload exists inside the encrypted CLR resource blob, its C2 would only be observable dynamically. CAPE was unavailable for this sample.
Interesting Tidbits
- TT01650Q tracking-code lure — the filename mimics a DHL/UPS-style airway-bill or container tracking code (
TT01650Q0986854CNAMX), a known social-engineering pattern in the AutoIt and JS dropper clusters. This is the first AvalancheRunner sibling to use a pure tracking-code lure (previous siblings usedBank_Payment_Advice,z1EDG0012026051400140040_1669_pdf, orQVVr.exe). - May 2026 timestamp, fresh build — compiled just four days before the triage run (May 22 vs May 26), indicating active repackaging.
- Internal name
iFbN.exe— gibberish 4-character internal name, consistent with the random-name pattern seen in siblings (hHRu.exe,LHUS.exe,rFks.exe,QVVr.exe). - Empty VS_VERSIONINFO — CompanyName, FileDescription, LegalCopyright, ProductName are all blank ^[exiftool.json:36-44]. This is a regression from sibling
485f73afwhich had aMicrosoft Corporationmasquerade. - Debug build artefacts —
DebuggableAttribute,DebuggerNonUserCodeAttribute,DebuggerBrowsableAttributepresent ^[strings.txt:164-166]. These trigger capa T1620/T1083 false positives (see debug-build-capa-false-positives). - Bitmap asset carriers —
System.Drawing.Bitmapreferences andCKT/WZPUgetters suggest game background images are embedded as resources. Thebinwalk.txtshows a PNG image at offset0x20E47(649×697, 8-bit RGBA) ^[binwalk.txt:7] and a PC bitmap at0x9ADE(154×154×32) ^[binwalk.txt:6].
How To Mess With It (Homelab Replication)
Goal: reproduce a .NET Framework 4.5 WinForms binary with comparable capa fingerprint and embedded resource payload hiding.
- Toolchain: Visual Studio 2019/2022, C# WinForms project targeting .NET Framework 4.5.
- Project: Create a simple arcade game (e.g., falling-object dodger) with Uzbek UI strings.
- Resources: Add a second-stage PE or DLL as an embedded
.resourcesfile underProperties.Resources. - Cipher: Implement a trivial XOR or Caesar cipher in a
XavfsizHisoblagichclass withShifrlash/Deshifrlashmethods. - Payload trigger: Wire the
Survey_Cadastral_Transectmethod (or any anomalous-name method) to decrypt the resource and reflectively load it viaAssembly.Load(). - Build: Compile in Debug configuration to reproduce the capa false-positive fingerprint.
- Verification: Run
capa <repro.exe>— should hit T1140 (Base64 decode), T1027 (obfuscation), T1620 (reflective loading), and T1083 (file exists) with 8–10 namespace matches.
What you'll learn: how commodity .NET loaders hide payloads inside benign game masquerades, and how capa over-reports on Debug-build .NET binaries.
Deployable Signatures
YARA rule
rule AvalancheRunner_64e2d169 {
meta:
description = "AvalancheRunner .NET game-masquerade loader with encrypted CLR resource payload"
author = "PacketPursuit"
date = "2026-07-28"
sha256 = "64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a"
family = "avalancherunner"
strings:
$namespace = "AvalancheRunner" ascii wide
$survey = "Survey_Cadastral_Transect" ascii wide
$shifrlash = "Shifrlash" ascii wide
$deshifrlash = "Deshifrlash" ascii wide
$obfkalit = "ObfKalit" ascii wide
$class1 = "AvalancheRunner.XavfsizHisoblagich" ascii wide
$class2 = "AvalancheRunner.OyinFormasi" ascii wide
$class3 = "AvalancheRunner.NatijaFormasi" ascii wide
$ckt = "get_CKT" ascii wide
$wzpu = "get_WZPU" ascii wide
$net45 = ".NETFramework,Version=v4.5" ascii wide
condition:
uint16(0) == 0x5A4D and
$namespace and
$survey and
($shifrlash or $deshifrlash) and
$obfkalit and
$net45 and
filesize < 2MB
}
Behavioral fingerprint statement
This binary is a .NET Framework 4.5 PE32 WinForms executable presenting an Uzbek-language arcade game (AvalancheRunner). It embeds CLR resources (AvalancheRunner.Properties.Resources) containing bitmap assets and an encrypted payload blob. At runtime, it decrypts the payload via XavfsizHisoblagich.Shifrlash/Deshifrlash routines keyed by ObfKalit. No network APIs are imported statically; any C2 behavior would reside in the decrypted second stage. The binary carries an empty VS_VERSIONINFO block and a hardcoded 64-character hex string of unknown purpose. It is typically distributed under logistics-tracking or banking-document filenames.
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA-256 | 64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a |
This sample |
| SHA-256 | C3BD7E9AB552CACF3C151F2672CBDEE2B5C935DD163CCC021BDE3ABDFC5F969A |
Embedded 64-char hex string; purpose unknown ^[strings.txt:32] |
| Filename | TT01650Q0986854CNAMX.exe |
Logistics-tracking-code lure |
| Internal name | iFbN.exe |
4-character random internal name |
| .NET namespace | AvalancheRunner |
Product / namespace identifier |
| Method name | Survey_Cadastral_Transect |
Anomalous cadastral-survey method (all siblings) |
| Class name | XavfsizHisoblagich |
"SecurityCalculator" in Uzbek; cipher container |
| Property name | ObfKalit |
Obfuscation key |
| Compile time | 2026-05-22 16:04:20 UTC |
PE timestamp |
Detection Signatures
| ATT&CK Tactic | Technique | Evidence | Confidence |
|---|---|---|---|
| Defense Evasion | T1140 — Deobfuscate/Decode Files or Information | Base64 decode + custom Shifrlash/Deshifrlash cipher routines |
Medium (static) |
| Defense Evasion | T1027 — Obfuscated Files or Information | Encrypted CLR resource blob hides second-stage payload | Medium (static) |
| Defense Evasion | T1620 — Reflective Code Loading | Capa flags load .NET assembly + invoke .NET assembly method + access .NET resource |
Low (capa false-positive risk on Debug .NET) |
| Defense Evasion | T1036 — Masquerading | Game version info / UI contradicts logistics-tracking filename | High |
| Discovery | T1083 — File and Directory Discovery | Capa check if file exists |
Low (benign DataSet serialization side effect) |
Note on T1620/T1083: These capa hits are primarily driven by DebuggableAttribute, DebuggerNonUserCodeAttribute, and standard .NET resource loading. They are not reliable behavioral indicators for this sample in isolation. See debug-build-capa-false-positives for the corpus-wide pattern.
References
- Artifact ID:
b847a548-cc1c-4c4d-af96-8884e49e4dee^[metadata.json:2] - OpenCTI label:
formbook(false positive) ^[metadata.json:8] - MalwareBazaar source:
malware-bazaar^[metadata.json:11] - CAPE status: skipped — no Windows guest available ^[dynamic-analysis.md:3]
- Related wiki pages:
- avalancherunner — cluster entity page
- embedded-sha256-integrity-hash — concept page for hardcoded hash strings
- debug-build-capa-false-positives — capa false-positive pattern on Debug .NET
- version-info-masquerade — VS_VERSIONINFO abuse concept
- formbook — actual Formbook family (AutoIt dropper), not this sample
- unclassified-dotnet-game — deprecated umbrella label; superseded by AvalancheRunner entity
Provenance
Analysis based on static artefacts only (no CAPE detonation). Tools:
file— PE32 .NET assembly classification ^[file.txt]pefile— PE header parsing, section entropy, import table ^[pefile.txt]exiftool— version info, internal name, timestamp ^[exiftool.json]strings— IL metadata string extraction ^[strings.txt]floss— attempted decoded-string extraction (failed due to CLI argument error; no recovered strings) ^[floss.txt]capa— capability detection (static mode, .NET ruleset) ^[capa.txt]binwalk— embedded file carving ^[binwalk.txt]radare2— CIL function listing and decompilation ^[rabin2-info.txt] ^[r2 exports/decompile]- Custom
stringsgreps for network, persistence, and process-spawn API enumeration.