a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91ccavalancherunner: a5ebbaa4 — CardBattle Uzbek TCG skin, no encrypted payload
Executive Summary
PE32 .NET Framework 4.5 WinForms executable presenting as a Trading Card Game (CardBattle) with full Uzbek-language UI. Distributed under the filename documents.exe — a social-engineering masquerade. Sixth confirmed sibling in the AvalancheRunner cluster. No encrypted CLR payload, no network APIs, no persistence. Static-only analysis (CAPE skipped — no Windows guest).
What It Is
| Field | Value |
|---|---|
| SHA-256 | a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc |
| Filename (triage) | documents.exe ^[triage.json] |
| Internal name | ZJEd.exe ^[strings.txt:264] |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Size | 860,160 bytes (840 KB) ^[triage.json] |
| Timestamp | 2026-05-26 09:57:31 UTC ^[pefile.txt:34] |
| .NET runtime | v4.0.30319 (.NET Framework 4.5) ^[strings.txt:4] |
| Entry | mscoree.dll._CorExeMain ^[pefile.txt:255] |
| Signed | Unsigned ^[rabin2-info.txt:27] |
| Sections | .text (847,360 bytes, entropy 7.69), .rsrc (11,776 bytes, entropy 3.51), .reloc (512 bytes, entropy 0.08) ^[pefile.txt:78-137] |
Build stack: Standard C# / .NET Framework 4.5 compiled with Visual Studio / MSBuild. No obfuscator, no packer, no anti-analysis. High .text entropy driven by embedded PNG and bitmap game assets. ^[binwalk.txt] ^[pefile.txt:92]
Family ascription: AvalancheRunner cluster sibling. Shared fingerprints: .NET 4.5 unobfuscated IL, Uzbek-language WinForms UI, game-masquerade + document-filename social engineering, embedded PNG assets, absence of network APIs. Anneal_Crucible_Batch anomalous method name present but non-unique — also observed in MassLogger and Formbook samples, likely an obfuscator artifact. ^[strings.txt:7]
How It Works
This sample is a stripped AvalancheRunner variant — the game shell without the encrypted second-stage payload observed in siblings 1a38a948, 2d9f8c6e, and 64e2d169. The threat is purely social-engineering: a victim downloads documents.exe expecting a document, receives a card game instead. The game runs normally, displaying Uzbek-language UI (UyinchiHP = player HP, DushmanHP = enemy HP, JangOynasiniYangilash = update battle screen, etc.). ^[strings.txt:71] ^[strings.txt:77] ^[strings.txt:284]
No malicious runtime behavior is observable statically:
- No
System.Net,WebClient,HttpWebRequest,Socket,SmtpClient, orProcess.Startreferences ^[strings.txt] - No P/Invoke, no
DllImport, no native API bridging ^[strings.txt] - No registry writes, no scheduled tasks, no startup-folder copies ^[strings.txt]
- No
Shifrlash/Deshifrlashcipher routines (present in payload-bearing siblings) ^[strings.txt]
Embedded assets extracted by binwalk: ^[binwalk.txt]
- PNG image, 584×632, RGBA (game background/card art) at offset 0xFD3A
- PC bitmap, 183×182×32 (icon or small asset) at offset 0xAE651
- XML application manifest at offset 0xD1A47
The .rsrc section contains only standard RT_ICON, RT_GROUP_ICON, RT_VERSION, and RT_MANIFEST entries — no encrypted payload blob. ^[pefile.txt:257-393]
Decompiled Behavior
No Ghidra decompilation performed — this is a managed .NET assembly best analyzed with ILSpy/dnSpy. The unobfuscated IL metadata is fully recoverable from strings. Key namespaces: CardBattle, CardBattle.UI, CardBattle.Baza, CardBattle.Formalar, CardBattle.Klasslar. Key forms: BattleForm, CollectionForm, DeckBuilderForm. ^[strings.txt:207] ^[strings.txt:421-423]
Notable methods include Anneal_Crucible_Batch (anomalous English compound name among otherwise Uzbek identifiers) and ComputeStringHash. ^[strings.txt:7] ^[strings.txt:281]
C2 Infrastructure
None observed. No C2 URLs, IPs, domains, mutexes, named pipes, or registry keys recovered statically. The binary has zero network surface.
Interesting Tidbits
- Uzbek TCG, not arcade: Previous AvalancheRunner siblings were
AvalancheRunner(arcade),BombaZarasizlantiruvchi(bomb defusal), andParticlePlayground(particle sandbox). This is the first TCG skin in the cluster —CardBattlewith deck-building, collection management, and battle mechanics. ^[strings.txt:67] ^[strings.txt:121] Anneal_Crucible_Batchis not a unique fingerprint: Cross-corpus grep confirms this string appears in at least six unrelated samples including MassLogger (3cc6a6ee) and Formbook (580095fa). It is likely an artifact of a common .NET obfuscator or build template, not a cluster-specific identifier. ^[strings.txt:7]- Hardcoded 64-char hex string:
AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068Cappears at line 63. Same exact string found in MassLogger and Formbook samples. Purpose unknown — possibly an obfuscator watermark, a companion-payload integrity hash, or a development artifact. ^[strings.txt:63] - Capa false positives:
reference analysis tools strings(B0013.001) andT1083are triggered by standard .NET Debug attributes (DebuggerNonUserCodeAttribute,DebuggableAttribute). Documented false-positive pattern for Debug-configuration .NET binaries. ^[capa.txt] ^[debug-build-capa-false-positives] documents.exelure: The filename is generic and urgent — a classic social-engineering dropper name, yet the payload is a benign game. This suggests the file may have been the decoy/frontend of a two-stage delivery (game runs while a separate component executes), or simply a mislabelled upload.
How To Mess With It (Homelab Replication)
Goal: Reproduce a .NET WinForms game with comparable capa fingerprint to demonstrate Debug-build false positives and high-entropy .text from embedded assets.
Toolchain: Visual Studio 2022 Community, C# Windows Forms App (.NET Framework 4.5 target).
Steps:
- Create a new Windows Forms App in VS 2022, target .NET Framework 4.5.
- Add a
Panel,PictureBox, andProgressBarto the form. Set names to non-English identifiers (e.g.,panelArena,barUyinchiHP). - Embed a PNG image as a resource (Properties → Resources → Add Existing File).
- Build in Debug configuration.
- Verify capa output: should hit
compiled to the .NET platform,access .NET resource,check if file exists,generate random numbers in .NET, and the false-positivereference analysis tools strings/T1083.
What you'll learn: How benign .NET Debug builds trigger capa ATT&CK mappings that can drown real detections in noise.
Deployable Signatures
YARA Rule
rule AvalancheRunner_CardBattle_Uzbek_TCG
{
meta:
description = "AvalancheRunner cluster .NET Uzbek card game masquerade"
author = "pp-hermes"
date = "2026-07-30"
sha256 = "a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc"
family = "avalancherunner"
strings:
$ns1 = "CardBattle.UI" ascii wide
$ns2 = "CardBattle.Baza" ascii wide
$ns3 = "CardBattle.Formalar" ascii wide
$ns4 = "CardBattle.Klasslar" ascii wide
$ui1 = "UyinchiHP" ascii wide
$ui2 = "DushmanHP" ascii wide
$ui3 = "JangOynasiniYangilash" ascii wide
$ui4 = "DastaKartalariniChizish" ascii wide
$anom = "Anneal_Crucible_Batch" ascii wide
$hash = "AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C" ascii wide
condition:
uint16(0) == 0x5A4D and
3 of ($ns*) and
2 of ($ui*) and
$anom
}
Behavioral Hunt Query (Sigma)
title: .NET Game Masquerading as Document
status: experimental
logsource:
product: windows
category: file_event
selection:
- Filename|endswith:
- '.exe'
- Filename|contains:
- 'document'
- 'invoice'
- 'payment'
- 'purchase'
- 'shipping'
- 'tracking'
- PE_ProductName|contains:
- 'CardBattle'
- 'AvalancheRunner'
- 'BombaZarasizlantiruvchi'
- 'ParticlePlayground'
- PE_OriginalFileName|endswith:
- '.exe'
- PE_InternalName|re:
- '^[A-Z][a-z]{2}\.exe$'
- '^[A-Z]{4}\.exe$'
condition: selection
falsepositives:
- Legitimate games renamed by users
level: medium
IOC List
| Indicator | Type | Note |
|---|---|---|
a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc |
SHA-256 | This sample |
ZJEd.exe |
Internal name | CardBattle build |
CardBattle |
ProductName | Version info masquerade |
documents.exe |
Filename | Social-engineering lure |
AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C |
Hex string | Hardcoded artifact (non-unique) |
Behavioral Fingerprint
This binary is a .NET Framework 4.5 PE32 with unobfuscated IL metadata, a WinForms GUI presenting as an Uzbek-language card game (CardBattle), embedded PNG and bitmap assets in .text, standard .rsrc containing only icon/version/manifest resources, and zero network or persistence APIs. The filename (documents.exe) contradicts the game content. No encrypted payload, no reflective loading, no P/Invoke. Capa flags T1083 and B0013.001 as benign Debug-build false positives.
Detection Signatures
| ATT&CK Tactic | Technique | Evidence | Confidence |
|---|---|---|---|
| Defense Evasion | T1036 — Masquerading | Filename documents.exe vs product CardBattle |
High |
| Discovery | T1083 — File and Directory Discovery | Capa check if file exists |
Low (Debug false positive) |
| Defense Evasion | B0013.001 — Analysis Tool Discovery: Process detection | Capa reference analysis tools strings |
Low (Debug false positive) |
References
- Artifact ID:
3f6b73e9-40ea-4c27-809c-80675e85e933^[metadata.json] - Source: MalwareBazaar via OpenCTI connector
- AvalancheRunner entity: avalancherunner
- Debug-build capa false positives: debug-build-capa-false-positives
- Version-info masquerade concept: version-info-masquerade
- Social-engineering filename pattern: social-engineering-filename-lure
Provenance
Analysis derived from static artifacts generated by the triage pipeline on 2026-05-26 and deep-dive tooling on 2026-07-30. File type from file v5.45. PE headers from pefile Python module. Strings from strings (GNU binutils). Capa v9.1.0 static analysis. Binwalk v2.3.4 for embedded file carving. Radare2 rabin2 -I for binary header summary. No CAPE detonation available (no Windows guest). No Ghidra decompilation — managed .NET assembly analyzed via IL metadata extraction.