typeentityconfidencemediumcreated2026-06-09updated2026-08-25dotnetloaderdefense-evasionmasqueradingmitre-attckreflective-code-loading

AvalancheRunner

Low-to-medium-confidence family label for a .NET Framework 4.5 PE32 binary cluster masquerading as games (AvalancheRunner, BombaZarasizlantiruvchi, ParticlePlayground, CardBattle) while functioning as potential encrypted payload loaders. Seven confirmed siblings span 2020–2026: 1a38a948 (May 2020, banking lure), 2d9f8c6e (Dec 2022, stripped version info), f7352bc1 (May 2026, bomb-defusal skin, no encrypted payload), 485f73af (May 2026, particle-playground skin, no encrypted payload), 64e2d169 (May 2026, logistics-tracking lure, encrypted payload restored), a5ebbaa4 (May 2026, CardBattle TCG skin, no encrypted payload), and 580095fa (May 2026, CardBattle Uzbek TCG skin, quotation-form lure, no encrypted payload). All share identical compiler toolchain, unobfuscated IL metadata, Uzbek-language WinForms UI, and the anomalous Survey_Cadastral_Transect method name.

Confidence elevated from low to medium with the fifth sibling confirming active, ongoing repackaging of both payload-bearing and stripped variants from the same builder.

Build Stack

Component Observation
Language C# / .NET Framework 4.5 (v4.0.30319)
Compiler Visual Studio 2019–2022 (16.10.0.0 / 17.4.4)
Obfuscator None — fully unobfuscated IL metadata
Signing Unsigned
Entry mscoree.dll._CorExeMain
Resources CLR embedded resource blob (~952 KB, PNG + zlib-compressed data) in siblings 1a38a948, 2d9f8c6e, and 64e2d169; absent in f7352bc1 and 485f73af

Variants / Aliases

  • AvalancheRunner (product name, siblings 1a38a948, 2d9f8c6e, 64e2d169)
  • BombaZarasizlantiruvchi (Uzbek "Bomb Defuser", sibling f7352bc1)
  • ParticlePlayground (Uzbek "Zarracha" = particle, sibling 485f73af)
  • hHRu.exe / LHUS.exe / rFks.exe / QVVr.exe / iFbN.exe (internal names across siblings)
  • Ko'chki Chopari O'yini (Uzbek decoy string, sibling 1a38a948)
  • TT01650Q0986854CNAMX.exe (logistics-tracking-code lure, sibling 64e2d169)
  • documents.exe (generic document lure, CardBattle TCG skin, sibling a5ebbaa4)
  • DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat (DWG drawing + RFQ lure with .bat extension masquerade, sibling 5b4f596d)

Deploy / TTPs

ATT&CK Tactic Technique Evidence
Defense Evasion T1140 — Deobfuscate/Decode Files or Information Managed Base64 decode + custom Shifrlash/Deshifrlash cipher routines (siblings 1a38a948, 2d9f8c6e, 64e2d169)
Defense Evasion T1027 — Obfuscated Files or Information Encrypted CLR resource blob hides second-stage payload (siblings 1a38a948, 2d9f8c6e, 64e2d169)
Defense Evasion T1620 — Reflective Code Loading Capa flags load .NET assembly + invoke .NET assembly method + access .NET resource (all siblings)
Discovery T1083 — File and Directory Discovery Capa check if file exists
Defense Evasion T1036 — Masquerading Version info claims game / PDF previewer / Microsoft Corporation; contradicts banking/tracking lure filename

Capabilities

  • dotnet-clr-resource-payload-hiding — ~952 KB encrypted/zlib-compressed blob inside CLR resources (siblings 1a38a948, 2d9f8c6e, 64e2d169; absent in f7352bc1 and 485f73af)
  • managed-base64-string-decoding — Capa-confirmed Base64 encode/decode in .NET
  • custom-managed-cipher-shifrlash — Encrypt/decrypt routines with hardcoded ObfKalit key (siblings 1a38a948, 2d9f8c6e, 64e2d169; absent in f7352bc1 and 485f73af)
  • reflective-dotnet-assembly-loading — Capa flags load .NET assembly and invoke .NET assembly method (all siblings)
  • version-info-masquerade — ProductName/FileDescription contradictions across all siblings
  • uzbek-language-ui-decoy — All UI strings in Uzbek (Oyin, Tosh, Yulduz, Bomba, Sim, Kod, Galaba, Zarracha, Portlash, Sozlamalar)
  • banking-filename-social-engineering — Bank_Payment_Advice20396.exe, z1EDG0012026051400140040_1669_pdf.bat
  • logistics-tracking-code-social-engineering — TT01650Q0986854CNAMX.exe (sibling 64e2d169)
  • survey-cadastral-transect-anomaly — Recurring anomalous method name across all five siblings (2020–2026)
  • no-network-api-surface — No System.Net, WebClient, Socket, or HTTP references recovered statically (all siblings)
  • png-asset-embedding — Large game background image embedded in .text section (sibling 485f73af only)
  • embedded-sha256-integrity-hash — Hardcoded 64-character hex string of unknown purpose (sibling 64e2d169)
  • tcg-cardbattle-skin — Trading Card Game skin with deck-building, collection management, and battle mechanics (siblings a5ebbaa4, 580095fa, 5b4f596d)
  • generic-document-filename-lure — documents.exe — a stripped, non-payload-bearing variant with no encrypted CLR blob (sibling a5ebbaa4)
  • dwg-rfq-bat-extension-masquerade — .bat extension in filename while actually being a PE executable, combining DWG drawing and RFQ social-engineering cues (sibling 5b4f596d)

Notable Analyses

  • /intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html — First sibling (May 2020, Bank_Payment_Advice20396.exe). Full static deep-dive. No CAPE detonation.
  • /intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html — Second sibling (Dec 2022, LHUS.exe). Stripped version info, same encrypted CLR blob.
  • /intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html — Third sibling (May 2026, z1EDG0012026051400140040_1669_pdf.bat). Bomb-defusal skin, PDF-masquerade version info, no encrypted CLR blob, no Shifrlash/Deshifrlash routines.
  • /intel/analyses/485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0.html — Fourth sibling (May 2026, QVVr.exe). ParticlePlayground skin, Microsoft Corporation masquerade, embedded PNG asset, no encrypted CLR blob, no cipher routines.
  • /intel/analyses/64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a.html — Fifth sibling (May 2026, TT01650Q0986854CNAMX.exe). Logistics-tracking-code lure, encrypted payload restored, hardcoded SHA-256-like hash string. OpenCTI false-positive formbook co-label.
  • /intel/analyses/a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc.html — Sixth sibling (May 2026, documents.exe). CardBattle Uzbek TCG skin, no encrypted CLR blob, no cipher routines, no network surface. Social-engineering masquerade only.
  • /intel/analyses/580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6.html — Seventh sibling (May 2026, MV_GREAT_AMITY_QUOTATION_FORMS.exe). CardBattle Uzbek TCG skin, quotation-form lure, no encrypted CLR blob, no cipher routines, no network surface. OpenCTI false-positive formbook co-label.
  • /intel/analyses/5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74.html — Eighth sibling (May 2026, DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat). CardBattle Uzbek TCG skin, DWG+RFQ lure with .bat extension masquerade, no encrypted CLR blob, no cipher routines, no network surface. Internal name bfgQ.exe. Static-only.

Related