typeanalysisfamilyavalancherunnerconfidencemediumcreated2026-07-30updated2026-07-30dotnetmasqueradingevasionmitre-attck
SHA-256: a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc

avalancherunner: a5ebbaa4 — CardBattle Uzbek TCG skin, no encrypted payload

Executive Summary

PE32 .NET Framework 4.5 WinForms executable presenting as a Trading Card Game (CardBattle) with full Uzbek-language UI. Distributed under the filename documents.exe — a social-engineering masquerade. Sixth confirmed sibling in the AvalancheRunner cluster. No encrypted CLR payload, no network APIs, no persistence. Static-only analysis (CAPE skipped — no Windows guest).

What It Is

Field Value
SHA-256 a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc
Filename (triage) documents.exe ^[triage.json]
Internal name ZJEd.exe ^[strings.txt:264]
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Size 860,160 bytes (840 KB) ^[triage.json]
Timestamp 2026-05-26 09:57:31 UTC ^[pefile.txt:34]
.NET runtime v4.0.30319 (.NET Framework 4.5) ^[strings.txt:4]
Entry mscoree.dll._CorExeMain ^[pefile.txt:255]
Signed Unsigned ^[rabin2-info.txt:27]
Sections .text (847,360 bytes, entropy 7.69), .rsrc (11,776 bytes, entropy 3.51), .reloc (512 bytes, entropy 0.08) ^[pefile.txt:78-137]

Build stack: Standard C# / .NET Framework 4.5 compiled with Visual Studio / MSBuild. No obfuscator, no packer, no anti-analysis. High .text entropy driven by embedded PNG and bitmap game assets. ^[binwalk.txt] ^[pefile.txt:92]

Family ascription: AvalancheRunner cluster sibling. Shared fingerprints: .NET 4.5 unobfuscated IL, Uzbek-language WinForms UI, game-masquerade + document-filename social engineering, embedded PNG assets, absence of network APIs. Anneal_Crucible_Batch anomalous method name present but non-unique — also observed in MassLogger and Formbook samples, likely an obfuscator artifact. ^[strings.txt:7]

How It Works

This sample is a stripped AvalancheRunner variant — the game shell without the encrypted second-stage payload observed in siblings 1a38a948, 2d9f8c6e, and 64e2d169. The threat is purely social-engineering: a victim downloads documents.exe expecting a document, receives a card game instead. The game runs normally, displaying Uzbek-language UI (UyinchiHP = player HP, DushmanHP = enemy HP, JangOynasiniYangilash = update battle screen, etc.). ^[strings.txt:71] ^[strings.txt:77] ^[strings.txt:284]

No malicious runtime behavior is observable statically:

  • No System.Net, WebClient, HttpWebRequest, Socket, SmtpClient, or Process.Start references ^[strings.txt]
  • No P/Invoke, no DllImport, no native API bridging ^[strings.txt]
  • No registry writes, no scheduled tasks, no startup-folder copies ^[strings.txt]
  • No Shifrlash/Deshifrlash cipher routines (present in payload-bearing siblings) ^[strings.txt]

Embedded assets extracted by binwalk: ^[binwalk.txt]

  • PNG image, 584×632, RGBA (game background/card art) at offset 0xFD3A
  • PC bitmap, 183×182×32 (icon or small asset) at offset 0xAE651
  • XML application manifest at offset 0xD1A47

The .rsrc section contains only standard RT_ICON, RT_GROUP_ICON, RT_VERSION, and RT_MANIFEST entries — no encrypted payload blob. ^[pefile.txt:257-393]

Decompiled Behavior

No Ghidra decompilation performed — this is a managed .NET assembly best analyzed with ILSpy/dnSpy. The unobfuscated IL metadata is fully recoverable from strings. Key namespaces: CardBattle, CardBattle.UI, CardBattle.Baza, CardBattle.Formalar, CardBattle.Klasslar. Key forms: BattleForm, CollectionForm, DeckBuilderForm. ^[strings.txt:207] ^[strings.txt:421-423]

Notable methods include Anneal_Crucible_Batch (anomalous English compound name among otherwise Uzbek identifiers) and ComputeStringHash. ^[strings.txt:7] ^[strings.txt:281]

C2 Infrastructure

None observed. No C2 URLs, IPs, domains, mutexes, named pipes, or registry keys recovered statically. The binary has zero network surface.

Interesting Tidbits

  • Uzbek TCG, not arcade: Previous AvalancheRunner siblings were AvalancheRunner (arcade), BombaZarasizlantiruvchi (bomb defusal), and ParticlePlayground (particle sandbox). This is the first TCG skin in the cluster — CardBattle with deck-building, collection management, and battle mechanics. ^[strings.txt:67] ^[strings.txt:121]
  • Anneal_Crucible_Batch is not a unique fingerprint: Cross-corpus grep confirms this string appears in at least six unrelated samples including MassLogger (3cc6a6ee) and Formbook (580095fa). It is likely an artifact of a common .NET obfuscator or build template, not a cluster-specific identifier. ^[strings.txt:7]
  • Hardcoded 64-char hex string: AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C appears at line 63. Same exact string found in MassLogger and Formbook samples. Purpose unknown — possibly an obfuscator watermark, a companion-payload integrity hash, or a development artifact. ^[strings.txt:63]
  • Capa false positives: reference analysis tools strings (B0013.001) and T1083 are triggered by standard .NET Debug attributes (DebuggerNonUserCodeAttribute, DebuggableAttribute). Documented false-positive pattern for Debug-configuration .NET binaries. ^[capa.txt] ^[debug-build-capa-false-positives]
  • documents.exe lure: The filename is generic and urgent — a classic social-engineering dropper name, yet the payload is a benign game. This suggests the file may have been the decoy/frontend of a two-stage delivery (game runs while a separate component executes), or simply a mislabelled upload.

How To Mess With It (Homelab Replication)

Goal: Reproduce a .NET WinForms game with comparable capa fingerprint to demonstrate Debug-build false positives and high-entropy .text from embedded assets.

Toolchain: Visual Studio 2022 Community, C# Windows Forms App (.NET Framework 4.5 target).

Steps:

  1. Create a new Windows Forms App in VS 2022, target .NET Framework 4.5.
  2. Add a Panel, PictureBox, and ProgressBar to the form. Set names to non-English identifiers (e.g., panelArena, barUyinchiHP).
  3. Embed a PNG image as a resource (Properties → Resources → Add Existing File).
  4. Build in Debug configuration.
  5. Verify capa output: should hit compiled to the .NET platform, access .NET resource, check if file exists, generate random numbers in .NET, and the false-positive reference analysis tools strings / T1083.

What you'll learn: How benign .NET Debug builds trigger capa ATT&CK mappings that can drown real detections in noise.

Deployable Signatures

YARA Rule

rule AvalancheRunner_CardBattle_Uzbek_TCG
{
    meta:
        description = "AvalancheRunner cluster .NET Uzbek card game masquerade"
        author      = "pp-hermes"
        date        = "2026-07-30"
        sha256      = "a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc"
        family      = "avalancherunner"

    strings:
        $ns1 = "CardBattle.UI" ascii wide
        $ns2 = "CardBattle.Baza" ascii wide
        $ns3 = "CardBattle.Formalar" ascii wide
        $ns4 = "CardBattle.Klasslar" ascii wide
        $ui1 = "UyinchiHP" ascii wide
        $ui2 = "DushmanHP" ascii wide
        $ui3 = "JangOynasiniYangilash" ascii wide
        $ui4 = "DastaKartalariniChizish" ascii wide
        $anom = "Anneal_Crucible_Batch" ascii wide
        $hash = "AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C" ascii wide

    condition:
        uint16(0) == 0x5A4D and
        3 of ($ns*) and
        2 of ($ui*) and
        $anom
}

Behavioral Hunt Query (Sigma)

title: .NET Game Masquerading as Document
status: experimental
logsource:
  product: windows
  category: file_event
selection:
  - Filename|endswith:
      - '.exe'
  - Filename|contains:
      - 'document'
      - 'invoice'
      - 'payment'
      - 'purchase'
      - 'shipping'
      - 'tracking'
  - PE_ProductName|contains:
      - 'CardBattle'
      - 'AvalancheRunner'
      - 'BombaZarasizlantiruvchi'
      - 'ParticlePlayground'
  - PE_OriginalFileName|endswith:
      - '.exe'
  - PE_InternalName|re:
      - '^[A-Z][a-z]{2}\.exe$'
      - '^[A-Z]{4}\.exe$'
condition: selection
falsepositives:
  - Legitimate games renamed by users
level: medium

IOC List

Indicator Type Note
a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc SHA-256 This sample
ZJEd.exe Internal name CardBattle build
CardBattle ProductName Version info masquerade
documents.exe Filename Social-engineering lure
AFBCD70341CA57DFE91E4E4E0295EF3889427D1C696EEBFBEEF861D95C25068C Hex string Hardcoded artifact (non-unique)

Behavioral Fingerprint

This binary is a .NET Framework 4.5 PE32 with unobfuscated IL metadata, a WinForms GUI presenting as an Uzbek-language card game (CardBattle), embedded PNG and bitmap assets in .text, standard .rsrc containing only icon/version/manifest resources, and zero network or persistence APIs. The filename (documents.exe) contradicts the game content. No encrypted payload, no reflective loading, no P/Invoke. Capa flags T1083 and B0013.001 as benign Debug-build false positives.

Detection Signatures

ATT&CK Tactic Technique Evidence Confidence
Defense Evasion T1036 — Masquerading Filename documents.exe vs product CardBattle High
Discovery T1083 — File and Directory Discovery Capa check if file exists Low (Debug false positive)
Defense Evasion B0013.001 — Analysis Tool Discovery: Process detection Capa reference analysis tools strings Low (Debug false positive)

References

Provenance

Analysis derived from static artifacts generated by the triage pipeline on 2026-05-26 and deep-dive tooling on 2026-07-30. File type from file v5.45. PE headers from pefile Python module. Strings from strings (GNU binutils). Capa v9.1.0 static analysis. Binwalk v2.3.4 for embedded file carving. Radare2 rabin2 -I for binary header summary. No CAPE detonation available (no Windows guest). No Ghidra decompilation — managed .NET assembly analyzed via IL metadata extraction.