typeanalysisfamilyavalancherunnerconfidencemediumdotnetmalware-familyloaderdefense-evasionmasqueradingmitre-attckreflective-code-loadingembedded-sha256-integrity-hash
SHA-256: 64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a

avalancherunner: 64e2d169 — TT01650Q tracking-code lure, encrypted payload restored, hardcoded SHA-256 hash

Executive Summary

Fifth confirmed sibling in the AvalancheRunner cluster. A .NET Framework 4.5 WinForms PE32 masquerading as an Uzbek-language arcade game (AvalancheRunner), distributed under a logistics-tracking filename (TT01650Q0986854CNAMX.exe). Unlike the two most recent siblings (f7352bc1, 485f73af), this sample restores the encrypted CLR resource payload and the Shifrlash/Deshifrlash cipher routines that were absent in the 2026 no-payload variants. Also carries a hardcoded 64-character hex string resembling a SHA-256 hash — purpose unconfirmed. OpenCTI co-labels this sample formbook; that attribution is a false positive based on social-engineering filename overlap.

Static-only analysis (CAPE skipped — no Windows guest). No network or persistence APIs recovered.

What It Is

Field Value
SHA-256 64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a
Filename TT01650Q0986854CNAMX.exe
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Size 1,021,952 bytes (~998 KB)
Compile time Fri May 22 16:04:20 2026 UTC ^[pefile.txt:34] ^[exiftool.json:15]
.NET runtime v4.0.30319 → .NET Framework 4.5 ^[strings.txt:7]
Generator System.Resources.Tools.StronglyTypedResourceBuilder / Microsoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator v16.10.0.0 ^[strings.txt:561-563]
Internal name iFbN.exe ^[exiftool.json:40]
Signing Unsigned ^[pefile.txt]
Packing / obfuscation None — fully unobfuscated IL metadata ^[capa.txt]
Import surface Single import: mscoree.dll._CorExeMain ^[pefile.txt:255]
OpenCTI label formbook (false-positive co-label; see below) ^[metadata.json:8]

How It Works

Cluster delta — payload restored

The AvalancheRunner cluster has four prior siblings spanning 2020–2026:

Sibling Date Payload Cipher
1a38a948 May 2020 ~952 KB encrypted CLR resource blob Shifrlash/Deshifrlash + ObfKalit
2d9f8c6e Dec 2022 ~952 KB encrypted CLR resource blob Same cipher
f7352bc1 May 2026 None — stripped to bare game Absent
485f73af May 2026 None — stripped to bare game + PNG asset Absent
64e2d169 May 2026 Encrypted CLR resource blob restored Shifrlash/Deshifrlash + ObfKalit restored

This sample proves the encrypted payload variant is still alive in May 2026, alongside the stripped decoy-only builds. The builder or repackager appears to toggle payload inclusion at compile time.

Embedded resources

Three CLR .resources files are embedded:

  • AvalancheRunner.NatijaFormasi.resources — results/high-score form UI resources ^[strings.txt:443]
  • AvalancheRunner.OyinFormasi.resources — game form UI resources ^[strings.txt:444]
  • AvalancheRunner.Properties.Resources.resources — property resources, including CKT and WZPU bitmap getters ^[strings.txt:445] ^[strings.txt:340] ^[strings.txt:571-573]

System.Drawing.Bitmap references (lines 569–573) indicate image assets are stored as embedded resources, not external files. The CKT and WZPU getters suggest at least two named bitmap resources.

Cipher routines

Four managed cipher methods are present in the AvalancheRunner.XavfsizHisoblagich (SecurityCalculator) class:

  • Shifrlash — encrypt routine ^[strings.txt:214] ^[r2:0x00405154]
  • Deshifrlash — decrypt routine ^[strings.txt:215] ^[r2:0x00405194]
  • ShifrlashSatr — encrypt string ^[strings.txt:433] ^[r2:0x00405248]
  • DeshifrlashSatr — decrypt string ^[strings.txt:434] ^[r2:0x004052b5]

The ObfKalit (ObfuscationKey) property ^[strings.txt:495] ^[r2 exports] is the hardcoded key material for these routines. The exact algorithm is not recoverable from strings alone; it is likely a simple XOR or substitution cipher given the "Shifrlash" (Uzbek for "encryption") naming convention in prior siblings.

Hardcoded SHA-256-like string

Line 32 of strings.txt contains a 64-character uppercase hex string:

C3BD7E9AB552CACF3C151F2672CBDEE2B5C935DD163CCC021BDE3ABDFC5F969A

This does not match the sample's own SHA-256. A corpus search returned no matching sibling. It matches the embedded-sha256-integrity-hash pattern observed in other .NET Framework PE32 samples (e.g., 3c9f96db, e04d46ff, 0d3d6bb9). Purpose unknown — candidate explanations: companion-payload integrity check, license watermark, or developer artefact. ^[strings.txt:32] ^[concepts/embedded-sha256-integrity-hash.md]

The formbook false positive

OpenCTI tags this sample formbook ^[metadata.json:8] ^[triage.json:19]. The real Formbook family in this corpus (a4cb4c76, 3424a53f) is an AutoIt-compiled dropper with shellcode bootstrap, stride-3 hex obfuscation, and GetTickCount timing gates — a completely different build stack. The only overlap is social-engineering: both use business-document or tracking-code filenames. This sample is not Formbook.

Decompiled Behavior

Radare2 CIL analysis finds 435 functions and 159 exports. The entry point is standard .NET mscoree.dll._CorExeMain ^[pefile.txt:255]. Notable exported methods include:

  • AvalancheRunner.Program.Main at 0x00402246 — standard WinForms entry
  • AvalancheRunner.OyinFormasi.Survey_Cadastral_Transect at 0x00402328 — the anomalous cadastral-survey method name that recurs across all five siblings ^[r2:0x00402328]
  • AvalancheRunner.XavfsizHisoblagich.Shifrlash at 0x00405154 — encryption routine ^[r2:0x00405154]
  • AvalancheRunner.XavfsizHisoblagich.Deshifrlash at 0x00405194 — decryption routine ^[r2:0x00405194]

The Survey_Cadastral_Transect decompilation is heavily obfuscated by radare2's CIL backend (stack-machine pseudo-code with unresolved 0x2b00000N tokens), but the presence of the method and its delegate chain confirms it is not dead code. Prior siblings show this method is linked to payload orchestration.

No P/Invoke imports, no System.Runtime.InteropServices native calls, and no Assembly.Load(byte[]) or Delegate.CreateDelegate strings are recovered — suggesting the reflective loading (if any) is performed through standard .NET resource stream APIs rather than raw memory manipulation.

C2 Infrastructure

None recovered. No System.Net, WebClient, HttpWebRequest, Socket, SmtpClient, Mail, Dns, TcpClient, or UdpClient strings are present ^[strings.txt search].

If a second-stage payload exists inside the encrypted CLR resource blob, its C2 would only be observable dynamically. CAPE was unavailable for this sample.

Interesting Tidbits

  • TT01650Q tracking-code lure — the filename mimics a DHL/UPS-style airway-bill or container tracking code (TT01650Q0986854CNAMX), a known social-engineering pattern in the AutoIt and JS dropper clusters. This is the first AvalancheRunner sibling to use a pure tracking-code lure (previous siblings used Bank_Payment_Advice, z1EDG0012026051400140040_1669_pdf, or QVVr.exe).
  • May 2026 timestamp, fresh build — compiled just four days before the triage run (May 22 vs May 26), indicating active repackaging.
  • Internal name iFbN.exe — gibberish 4-character internal name, consistent with the random-name pattern seen in siblings (hHRu.exe, LHUS.exe, rFks.exe, QVVr.exe).
  • Empty VS_VERSIONINFO — CompanyName, FileDescription, LegalCopyright, ProductName are all blank ^[exiftool.json:36-44]. This is a regression from sibling 485f73af which had a Microsoft Corporation masquerade.
  • Debug build artefacts — DebuggableAttribute, DebuggerNonUserCodeAttribute, DebuggerBrowsableAttribute present ^[strings.txt:164-166]. These trigger capa T1620/T1083 false positives (see debug-build-capa-false-positives).
  • Bitmap asset carriers — System.Drawing.Bitmap references and CKT/WZPU getters suggest game background images are embedded as resources. The binwalk.txt shows a PNG image at offset 0x20E47 (649×697, 8-bit RGBA) ^[binwalk.txt:7] and a PC bitmap at 0x9ADE (154×154×32) ^[binwalk.txt:6].

How To Mess With It (Homelab Replication)

Goal: reproduce a .NET Framework 4.5 WinForms binary with comparable capa fingerprint and embedded resource payload hiding.

  1. Toolchain: Visual Studio 2019/2022, C# WinForms project targeting .NET Framework 4.5.
  2. Project: Create a simple arcade game (e.g., falling-object dodger) with Uzbek UI strings.
  3. Resources: Add a second-stage PE or DLL as an embedded .resources file under Properties.Resources.
  4. Cipher: Implement a trivial XOR or Caesar cipher in a XavfsizHisoblagich class with Shifrlash/Deshifrlash methods.
  5. Payload trigger: Wire the Survey_Cadastral_Transect method (or any anomalous-name method) to decrypt the resource and reflectively load it via Assembly.Load().
  6. Build: Compile in Debug configuration to reproduce the capa false-positive fingerprint.
  7. Verification: Run capa <repro.exe> — should hit T1140 (Base64 decode), T1027 (obfuscation), T1620 (reflective loading), and T1083 (file exists) with 8–10 namespace matches.

What you'll learn: how commodity .NET loaders hide payloads inside benign game masquerades, and how capa over-reports on Debug-build .NET binaries.

Deployable Signatures

YARA rule

rule AvalancheRunner_64e2d169 {
    meta:
        description = "AvalancheRunner .NET game-masquerade loader with encrypted CLR resource payload"
        author = "PacketPursuit"
        date = "2026-07-28"
        sha256 = "64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a"
        family = "avalancherunner"
    strings:
        $namespace = "AvalancheRunner" ascii wide
        $survey = "Survey_Cadastral_Transect" ascii wide
        $shifrlash = "Shifrlash" ascii wide
        $deshifrlash = "Deshifrlash" ascii wide
        $obfkalit = "ObfKalit" ascii wide
        $class1 = "AvalancheRunner.XavfsizHisoblagich" ascii wide
        $class2 = "AvalancheRunner.OyinFormasi" ascii wide
        $class3 = "AvalancheRunner.NatijaFormasi" ascii wide
        $ckt = "get_CKT" ascii wide
        $wzpu = "get_WZPU" ascii wide
        $net45 = ".NETFramework,Version=v4.5" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        $namespace and
        $survey and
        ($shifrlash or $deshifrlash) and
        $obfkalit and
        $net45 and
        filesize < 2MB
}

Behavioral fingerprint statement

This binary is a .NET Framework 4.5 PE32 WinForms executable presenting an Uzbek-language arcade game (AvalancheRunner). It embeds CLR resources (AvalancheRunner.Properties.Resources) containing bitmap assets and an encrypted payload blob. At runtime, it decrypts the payload via XavfsizHisoblagich.Shifrlash/Deshifrlash routines keyed by ObfKalit. No network APIs are imported statically; any C2 behavior would reside in the decrypted second stage. The binary carries an empty VS_VERSIONINFO block and a hardcoded 64-character hex string of unknown purpose. It is typically distributed under logistics-tracking or banking-document filenames.

IOC list

Type Value Notes
SHA-256 64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a This sample
SHA-256 C3BD7E9AB552CACF3C151F2672CBDEE2B5C935DD163CCC021BDE3ABDFC5F969A Embedded 64-char hex string; purpose unknown ^[strings.txt:32]
Filename TT01650Q0986854CNAMX.exe Logistics-tracking-code lure
Internal name iFbN.exe 4-character random internal name
.NET namespace AvalancheRunner Product / namespace identifier
Method name Survey_Cadastral_Transect Anomalous cadastral-survey method (all siblings)
Class name XavfsizHisoblagich "SecurityCalculator" in Uzbek; cipher container
Property name ObfKalit Obfuscation key
Compile time 2026-05-22 16:04:20 UTC PE timestamp

Detection Signatures

ATT&CK Tactic Technique Evidence Confidence
Defense Evasion T1140 — Deobfuscate/Decode Files or Information Base64 decode + custom Shifrlash/Deshifrlash cipher routines Medium (static)
Defense Evasion T1027 — Obfuscated Files or Information Encrypted CLR resource blob hides second-stage payload Medium (static)
Defense Evasion T1620 — Reflective Code Loading Capa flags load .NET assembly + invoke .NET assembly method + access .NET resource Low (capa false-positive risk on Debug .NET)
Defense Evasion T1036 — Masquerading Game version info / UI contradicts logistics-tracking filename High
Discovery T1083 — File and Directory Discovery Capa check if file exists Low (benign DataSet serialization side effect)

Note on T1620/T1083: These capa hits are primarily driven by DebuggableAttribute, DebuggerNonUserCodeAttribute, and standard .NET resource loading. They are not reliable behavioral indicators for this sample in isolation. See debug-build-capa-false-positives for the corpus-wide pattern.

References

  • Artifact ID: b847a548-cc1c-4c4d-af96-8884e49e4dee ^[metadata.json:2]
  • OpenCTI label: formbook (false positive) ^[metadata.json:8]
  • MalwareBazaar source: malware-bazaar ^[metadata.json:11]
  • CAPE status: skipped — no Windows guest available ^[dynamic-analysis.md:3]
  • Related wiki pages:

Provenance

Analysis based on static artefacts only (no CAPE detonation). Tools:

  • file — PE32 .NET assembly classification ^[file.txt]
  • pefile — PE header parsing, section entropy, import table ^[pefile.txt]
  • exiftool — version info, internal name, timestamp ^[exiftool.json]
  • strings — IL metadata string extraction ^[strings.txt]
  • floss — attempted decoded-string extraction (failed due to CLI argument error; no recovered strings) ^[floss.txt]
  • capa — capability detection (static mode, .NET ruleset) ^[capa.txt]
  • binwalk — embedded file carving ^[binwalk.txt]
  • radare2 — CIL function listing and decompilation ^[rabin2-info.txt] ^[r2 exports/decompile]
  • Custom strings greps for network, persistence, and process-spawn API enumeration.