AvalancheRunner
Low-to-medium-confidence family label for a .NET Framework 4.5 PE32 binary cluster masquerading as games (AvalancheRunner, BombaZarasizlantiruvchi, ParticlePlayground, CardBattle) while functioning as potential encrypted payload loaders. Seven confirmed siblings span 2020–2026: 1a38a948 (May 2020, banking lure), 2d9f8c6e (Dec 2022, stripped version info), f7352bc1 (May 2026, bomb-defusal skin, no encrypted payload), 485f73af (May 2026, particle-playground skin, no encrypted payload), 64e2d169 (May 2026, logistics-tracking lure, encrypted payload restored), a5ebbaa4 (May 2026, CardBattle TCG skin, no encrypted payload), and 580095fa (May 2026, CardBattle Uzbek TCG skin, quotation-form lure, no encrypted payload). All share identical compiler toolchain, unobfuscated IL metadata, Uzbek-language WinForms UI, and the anomalous Survey_Cadastral_Transect method name.
Confidence elevated from low to medium with the fifth sibling confirming active, ongoing repackaging of both payload-bearing and stripped variants from the same builder.
Build Stack
| Component | Observation |
|---|---|
| Language | C# / .NET Framework 4.5 (v4.0.30319) |
| Compiler | Visual Studio 2019–2022 (16.10.0.0 / 17.4.4) |
| Obfuscator | None — fully unobfuscated IL metadata |
| Signing | Unsigned |
| Entry | mscoree.dll._CorExeMain |
| Resources | CLR embedded resource blob (~952 KB, PNG + zlib-compressed data) in siblings 1a38a948, 2d9f8c6e, and 64e2d169; absent in f7352bc1 and 485f73af |
Variants / Aliases
AvalancheRunner(product name, siblings 1a38a948, 2d9f8c6e, 64e2d169)BombaZarasizlantiruvchi(Uzbek "Bomb Defuser", sibling f7352bc1)ParticlePlayground(Uzbek "Zarracha" = particle, sibling 485f73af)hHRu.exe/LHUS.exe/rFks.exe/QVVr.exe/iFbN.exe(internal names across siblings)Ko'chki Chopari O'yini(Uzbek decoy string, sibling 1a38a948)TT01650Q0986854CNAMX.exe(logistics-tracking-code lure, sibling 64e2d169)documents.exe(generic document lure, CardBattle TCG skin, sibling a5ebbaa4)DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat(DWG drawing + RFQ lure with.batextension masquerade, sibling 5b4f596d)
Deploy / TTPs
| ATT&CK Tactic | Technique | Evidence |
|---|---|---|
| Defense Evasion | T1140 — Deobfuscate/Decode Files or Information | Managed Base64 decode + custom Shifrlash/Deshifrlash cipher routines (siblings 1a38a948, 2d9f8c6e, 64e2d169) |
| Defense Evasion | T1027 — Obfuscated Files or Information | Encrypted CLR resource blob hides second-stage payload (siblings 1a38a948, 2d9f8c6e, 64e2d169) |
| Defense Evasion | T1620 — Reflective Code Loading | Capa flags load .NET assembly + invoke .NET assembly method + access .NET resource (all siblings) |
| Discovery | T1083 — File and Directory Discovery | Capa check if file exists |
| Defense Evasion | T1036 — Masquerading | Version info claims game / PDF previewer / Microsoft Corporation; contradicts banking/tracking lure filename |
Capabilities
dotnet-clr-resource-payload-hiding— ~952 KB encrypted/zlib-compressed blob inside CLR resources (siblings 1a38a948, 2d9f8c6e, 64e2d169; absent in f7352bc1 and 485f73af)managed-base64-string-decoding— Capa-confirmed Base64 encode/decode in .NETcustom-managed-cipher-shifrlash— Encrypt/decrypt routines with hardcodedObfKalitkey (siblings 1a38a948, 2d9f8c6e, 64e2d169; absent in f7352bc1 and 485f73af)reflective-dotnet-assembly-loading— Capa flagsload .NET assemblyandinvoke .NET assembly method(all siblings)version-info-masquerade— ProductName/FileDescription contradictions across all siblingsuzbek-language-ui-decoy— All UI strings in Uzbek (Oyin,Tosh,Yulduz,Bomba,Sim,Kod,Galaba,Zarracha,Portlash,Sozlamalar)banking-filename-social-engineering—Bank_Payment_Advice20396.exe,z1EDG0012026051400140040_1669_pdf.batlogistics-tracking-code-social-engineering—TT01650Q0986854CNAMX.exe(sibling 64e2d169)survey-cadastral-transect-anomaly— Recurring anomalous method name across all five siblings (2020–2026)no-network-api-surface— NoSystem.Net,WebClient,Socket, or HTTP references recovered statically (all siblings)png-asset-embedding— Large game background image embedded in.textsection (sibling 485f73af only)embedded-sha256-integrity-hash— Hardcoded 64-character hex string of unknown purpose (sibling 64e2d169)tcg-cardbattle-skin— Trading Card Game skin with deck-building, collection management, and battle mechanics (siblings a5ebbaa4, 580095fa, 5b4f596d)generic-document-filename-lure—documents.exe— a stripped, non-payload-bearing variant with no encrypted CLR blob (sibling a5ebbaa4)dwg-rfq-bat-extension-masquerade—.batextension in filename while actually being a PE executable, combining DWG drawing and RFQ social-engineering cues (sibling 5b4f596d)
Notable Analyses
- /intel/analyses/1a38a9488cb0c8b1cd817fa2c8bc854eb1a77ebc3adf94a75dbf5d8a4c5bb045.html — First sibling (May 2020,
Bank_Payment_Advice20396.exe). Full static deep-dive. No CAPE detonation. - /intel/analyses/2d9f8c6e00839f7c513c080deb360c141eded1429ccadabf16fb2a8650e8436b.html — Second sibling (Dec 2022,
LHUS.exe). Stripped version info, same encrypted CLR blob. - /intel/analyses/f7352bc1213a3464d7abb529acfdfb8a6e272e77a8e8f88236ca70192635d02d.html — Third sibling (May 2026,
z1EDG0012026051400140040_1669_pdf.bat). Bomb-defusal skin, PDF-masquerade version info, no encrypted CLR blob, noShifrlash/Deshifrlashroutines. - /intel/analyses/485f73aff7ba767b4ca18f63e1b271e0dbb603f4dbb082aa37ba9e3a72ed8aa0.html — Fourth sibling (May 2026,
QVVr.exe). ParticlePlayground skin,Microsoft Corporationmasquerade, embedded PNG asset, no encrypted CLR blob, no cipher routines. - /intel/analyses/64e2d169d90930905374a2f504cfa6a06276333533875b7a7d076cb2c472ae6a.html — Fifth sibling (May 2026,
TT01650Q0986854CNAMX.exe). Logistics-tracking-code lure, encrypted payload restored, hardcoded SHA-256-like hash string. OpenCTI false-positiveformbookco-label. - /intel/analyses/a5ebbaa4a872d243346d6782105ac90537577d63fe490065b13c8eca8bfa91cc.html — Sixth sibling (May 2026,
documents.exe). CardBattle Uzbek TCG skin, no encrypted CLR blob, no cipher routines, no network surface. Social-engineering masquerade only. - /intel/analyses/580095fa81f7b8fb14fdaa9203137f8ee9299cca68ba011e6bd285f0284bb6c6.html — Seventh sibling (May 2026,
MV_GREAT_AMITY_QUOTATION_FORMS.exe). CardBattle Uzbek TCG skin, quotation-form lure, no encrypted CLR blob, no cipher routines, no network surface. OpenCTI false-positiveformbookco-label. - /intel/analyses/5b4f596d3cf54c94c57934ccc75e31d7f5999df9abb1b77ff6f8cff007da8d74.html — Eighth sibling (May 2026,
DWG-00141842- MENTORTECH Request For the Quotation information 3001410 - 20260521 GF8017.bat). CardBattle Uzbek TCG skin, DWG+RFQ lure with.batextension masquerade, no encrypted CLR blob, no cipher routines, no network surface. Internal namebfgQ.exe. Static-only.
Related
- unclassified-dotnet-game — deprecated umbrella label; superseded by AvalancheRunner entity
- dotnet-manifest-resource-decryption — Related concept for .NET resource payload hiding
- version-info-masquerade — Shared social-engineering technique
- embedded-sha256-integrity-hash — Hardcoded hash pattern observed in sibling 64e2d169
- debug-build-capa-false-positives — Capa false-positive pattern on Debug .NET builds
- formbook — Actual Formbook family (AutoIt dropper), not related to this cluster