007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33bquasar: 007c13a2 — v1.4.1.0 stock build with steam-update.exe masquerade
Executive Summary
Stock open-source Quasar RAT client v1.4.1.0 by MaxXor, compiled for .NET Framework 4.5.2 with no obfuscation, no packing, and no anti-analysis countermeasures. Masquerades as steam-update.exe in version-info fields. Preliminary OpenCTI label quasarrat resolves to the same family. Static-only analysis (CAPE skipped — no Windows guest). Identical build fingerprint to confirmed siblings 0347df42, 00f1da32, and 0a47be72.
What It Is
| Field | Value |
|---|---|
| SHA-256 | 007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b |
| File type | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt] |
| Size | 139,776 bytes (140 KB) ^[triage.json] |
| Timestamp | 0xB58097E2 → Wed Jun 30 06:06:26 2066 UTC ^[pefile.txt:34] |
| Linker | .NET 8.0 (MajorLinkerVersion: 0x30) ^[pefile.txt:45] |
| Target framework | .NET Framework 4.5.2 (v4.0.30319, .NETFramework,Version=v4.5.2) ^[strings.txt:4], ^[strings.txt:1711] |
| Signed | No ^[rabin2-info.txt:27] |
| Overlay | None ^[rabin2-info.txt:23] |
| Entropy (text) | 5.97 — consistent with uncompressed CIL ^[pefile.txt:92] |
Version-info / masquerade: FileDescription: Quasar Client, InternalName: steam-update.exe, OriginalFilename: steam-update.exe, LegalCopyright: Copyright © MaxXor 2023, ProductName: Quasar, ProductVersion: 1.4.1 ^[pefile.txt:237-243], ^[exiftool.json:38-46]
Family ascription: Confirmed Quasar (MaxXor open-source RAT). The quasarrat preliminary label from OpenCTI is an alternate tagging of the same family. Build artefacts, namespace hierarchy, and version-info strings match the established quasar entity exactly. ^[entities/quasar.md]
How It Works
Entry point is the standard .NET PE stub (mscoree.dll._CorExeMain) ^[pefile.txt:255], handing control to the CLR which loads Quasar.Client.Program and calls Main. The binary is a stock client build from the public Quasar repository — all type names, namespaces, and string literals are unobfuscated.
Namespaces observed: Quasar.Client, Quasar.Client.Config, Quasar.Client.IO, Quasar.Client.Networking, Quasar.Client.Recovery.Browsers, Quasar.Client.Recovery.FtpClients, Quasar.Client.ReverseProxy, Quasar.Client.Logging, Quasar.Client.Helper, Quasar.Client.Utilities, Quasar.Client.User, Quasar.Client.Setup, Quasar.Client.Registry, Quasar.Common.Messages, Quasar.Common.Models, Quasar.Common.Video.Codecs, Quasar.Common.Cryptography, Quasar.Common.IO, Quasar.Common.DNS, Quasar.Common.Extensions, Quasar.Common.Helpers, Quasar.Common.Enums ^[strings.txt:passim]
Third-party libraries: protobuf-net (TCP message framing), Org.BouncyCastle.Crypto (TLS + AES-GCM), Gma.System.MouseKeyHook (global keylogger hook), System.Drawing (screenshot codec) ^[strings.txt:847], ^[strings.txt:1261], ^[strings.txt:1650]
No packing, no obfuscation, no anti-analysis: No ConfuserEx, SmartAssembly, dotfuscator, or custom crypter indicators. All strings, type names, and P/Invoke imports are in plaintext. No anti-VM, anti-debug, or timing gates detected in static analysis. ^[capa.txt], ^[strings.txt]
Decompiled Behavior
Radare2 analysis completed at level 3 and recovered 1,232 CIL functions ^[r2:analysis-log]. However, radare2's CIL backend produces IL bytecode disassembly rather than readable pseudo-C; the decompiler (pdc) is not useful for CIL. The entry-point chain is standard: _CorExeMain → CLR bootstrap → Quasar.Client.Program.Main.
Key handler classes (inferred from type names and capa matches):
KeyloggerHandler/KeyloggerService— global keyboard hook viaGma.System.MouseKeyHook^[capa.txt:collection/browser]RemoteDesktopHandler/UnsafeStreamCodec— desktop framebuffer streaming ^[capa.txt]FileManagerHandler— remote file upload/download/delete/enumeration ^[capa.txt]TaskManagerHandler— process enumeration and termination ^[capa.txt]RegistryHandler/RegistryEditor— registry read/write/delete/rename ^[capa.txt]PasswordRecoveryHandler— browser credential extraction (Chrome, Edge, Brave, Opera, Firefox, Yandex, IE, WinSCP, FileZilla, OperaGX) ^[capa.txt], ^[strings.txt:1103-1112]RemoteShellHandler—cmd.exeremote shell via redirected stdout/stderr ^[capa.txt]ReverseProxyHandler/ReverseProxyClient— SOCKS-like tunneling through the C2 socket ^[capa.txt]SystemInformationHandler— WMI + P/Invoke system fingerprinting ^[capa.txt]WebsiteVisitorHandler— hidden browser navigation ^[capa.txt]TcpConnectionsHandler—GetExtendedTcpTablenetwork connection enumeration ^[capa.txt], ^[strings.txt:435]ClientInstaller/ClientUninstaller— self-install to%APPDATA%and registry Run persistence ^[capa.txt]ClientUpdater— in-place binary update viaisUpdateflag ^[strings.txt:628]
No novel functions warrant individual decompilation — the entire surface is documented in the open-source Quasar repository.
C2 Infrastructure
Protocol: protobuf-net serialized TCP over TLS (BouncyCastle TLS wrapper). The client validates the server certificate against a hardcoded or builder-injected cert hash (ValidateServerCertificate, _serverCertificate) ^[strings.txt:625-626].
No hardcoded C2 endpoints recovered statically — host, port, and certificate are injected at build time by the Quasar builder GUI. This is consistent with all confirmed siblings in the corpus. ^[entities/quasar.md]
Network indicators observable statically:
TcpClient+SslStreamfor C2 transport ^[capa.txt]set_UserAgent/reference HTTP User-Agent string— capa hits suggest HTTP fallback or beacon User-Agent customization ^[capa.txt]set_WebProxy— proxy-aware C2 channel ^[capa.txt]get_KEEP_ALIVE_TIME/get_KEEP_ALIVE_INTERVAL— TCP keepalive tuning for long-lived C2 socket ^[strings.txt:118], ^[strings.txt:142]
Mutex: SingleInstanceMutex / ApplicationMutex — named mutex for single-instance gating ^[strings.txt:1607-1610]
Interesting Tidbits
steam-update.exemasquerade is purely cosmetic — the binary does not interact with Steam APIs or attempt Steam credential theft beyond the generic Chromium-based browser recovery.- A 64-character hex string (
7D78CB380BF5EFB7B851409CA6A875F77DECF09D19B9149DA17A3EBF674BC0F9) appears in#Stringsmetadata. Purpose unconfirmed — likely a placeholder SHA-256 used by the builder for certificate-pinning or update-package integrity, but not referenced in the open-source v1.4.1.0 code. ^[strings.txt:88] - The
isUpdateflag andClientUpdaterclass support in-place binary replacement without re-installing persistence — a stealthier upgrade path than dropping a second file. ^[strings.txt:628] ClientSetupBaseandApplicationSettingsBasesuggest the builder usesSystem.Configurationfor default settings, but the deployed client has no embedded.configresource — settings are compiled into the binary. ^[strings.txt:596-597]- FLOSS run failed with argument-parsing error (
--noflag collision) ^[floss.txt] — the tool output is useless; the sample has no stack-string obfuscation to decode.
How To Mess With It (Homelab Replication)
- Clone the Quasar repo:
git clone https://github.com/quasar/Quasar.git(or the MaxXor archive). - Open
Quasar.slnin Visual Studio 2019+. - Build the
Clientproject forRelease | AnyCPUtargeting .NET Framework 4.5.2. - In the builder GUI, set output filename to
steam-update.exe, configure a local TCP listener, and build. - Run
capaon the resulting PE — should hit the same ATT&CK tactics (Collection, Credential Access, Discovery, Execution, Persistence) and MBC behaviors (C2 Communication, HTTP/TCP Socket, Registry, Process) as this sample. - Compare
stringsoutput — the namespace tree and handler class names will be nearly identical.
What you'll learn: How a commodity open-source RAT looks when built with default settings, and why static signatures based on unobfuscated type names have high true-positive rates but low long-term value (any recompile breaks them).
Deployable Signatures
YARA rule
rule quasar_stock_v1_4_1_0
{
meta:
description = "Stock Quasar RAT client v1.4.1.0 — unobfuscated .NET build"
author = "PacketPursuit"
date = "2026-08-09"
hash = "007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b"
family = "quasar"
strings:
$ver1 = "Quasar Client" wide
$ver2 = "Quasar" wide
$ver3 = "Copyright \xa9 MaxXor 2023" wide
$ver4 = "steam-update.exe" wide
$ns1 = "Quasar.Client.Helper" ascii wide
$ns2 = "Quasar.Client.Recovery.Browsers" ascii wide
$ns3 = "Quasar.Client.ReverseProxy" ascii wide
$ns4 = "Quasar.Common.Cryptography" ascii wide
$lib1 = "Gma.System.MouseKeyHook" ascii wide
$lib2 = "Org.BouncyCastle.Crypto" ascii wide
condition:
uint16(0) == 0x5A4D and
pe.exports("_CorExeMain") and
3 of ($ver*) and
2 of ($ns*) and
any of ($lib*)
}
Sigma rule
title: Quasar RAT Stock Client Process Spawn
description: Detects child process patterns consistent with Quasar RAT remote shell and file manager execution
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: '\steam-update.exe'
- CommandLine|contains:
- 'cmd.exe /c'
- 'powershell.exe -NoP -Enc'
- ParentImage|endswith: '\steam-update.exe'
quasar_strings:
- CommandLine|contains:
- 'Quasar.Client'
- 'Quasar.Common'
condition: selection or quasar_strings
falsepositives:
- None expected; steam-update.exe is not a legitimate Windows or Steam binary path
level: high
IOC list
| Indicator | Value | Type |
|---|---|---|
| SHA-256 | 007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b |
Hash |
| MD5 | 668a2576569169db132b965366a616ed |
Hash |
| SSDeep | 3072:5VizmsUsAdsc328EOzZnsXSKqn4iLaBCVZpb2Gmk6vMfWTJ5:XXa8hzZsXSt4oHZpb280P |
Fuzzy hash |
| TLSH | — | Not present in triage output |
| Mutex | SingleInstanceMutex / ApplicationMutex |
Mutex name |
| Registry (persistence) | HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run — value name varies by builder config |
Persistence |
| File path (install) | %APPDATA%\steam-update.exe or builder-configured path |
Staging |
| Network | TCP outbound to builder-configured host:port, TLS handshake via BouncyCastle | C2 |
Behavioral fingerprint
This binary is a .NET Framework 4.5.2 PE32 GUI executable that, upon launch, creates a named mutex (SingleInstanceMutex), reads or creates its installation directory under %APPDATA%, establishes a TCP connection to a remote host over TLS (BouncyCastle SslStream), and then enters a message-processor loop awaiting protobuf-net serialized commands. It supports remote shell execution via redirected cmd.exe, desktop streaming via BitBlt/UnsafeStreamCodec, global keylogging via Gma.System.MouseKeyHook, browser credential recovery from Chromium/Firefox/IE profiles using DPAPI and SQLite, file manager operations, process enumeration/termination, registry manipulation, reverse proxy tunneling, and in-place self-update. Persistence is achieved via registry Run keys or scheduled tasks. No anti-VM, anti-debug, or packing is present.
Detection Signatures
capa → ATT&CK mapping
| capa capability | ATT&CK technique |
|---|---|
| gather chrome based browser login information | T1555.003 |
| reference SQL statements | T1213 |
| reference WMI statements | T1047 |
| get MAC address in .NET | T1016 |
| list TCP connections and listeners | T1049 |
| receive data / send data | T1071 |
| reference HTTP User-Agent string | T1071.001 |
| set HTTP User-Agent in .NET | T1071.001 |
| set web proxy in .NET | T1090 |
| create HTTP request | T1071.001 |
| create TCP socket | T1071.001 |
| decode data using Base64 in .NET | T1140 |
| encrypt data using DPAPI | T1555.003 |
| hash data via WinCrypt / SHA1 | — |
| check file extension in .NET | T1083 |
| enumerate drives | T1083 |
| copy file / create directory / delete file / move file / read file / write file | T1105 / T1070.004 / T1083 |
| enumerate gui resources / get graphical window text | T1010 |
| get disk information | T1082 |
| allocate/manipulate unmanaged memory in .NET | T1055 |
| create or open mutex | — |
| get domain information / networking interfaces / hostname | T1016 / T1082 |
| create a process with modified I/O handles | T1059.003 / T1106 |
| enumerate processes / find process by PID or name | T1057 |
| terminate process | T1057 |
| query or enumerate registry key/value | T1012 |
| set registry value / delete registry key/value | T1112 |
| get session integrity level / user name | T1033 |
| create thread / suspend thread | T1055 |
| access WMI data in .NET | T1047 |
| schedule task via schtasks | T1053.005 |
Full capa output available in capa.txt. ^[capa.txt]
References
- Quasar open-source repository (MaxXor): https://github.com/quasar/Quasar
- MalwareBazaar entry for this sample: https://bazaar.abuse.ch/sample/007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b/
- Sibling analysis:
0347df42(Quasar v1.4.1.0 stock build, March 2023) ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html] - Entity page: quasar
- Related technique: protobuf-net-asymmetric-client-rat-protocol
Provenance
Analysis based on static artifacts generated by the triage pipeline:
file.txt— file(1) outputpefile.txt— pefile Python library header dumpstrings.txt— ASCII/Unicode strings (1,792 lines)floss.txt— FLOSS attempted but failed due to CLI argument collision; no decoded strings because sample has no obfuscationcapa.txt— Mandiant capa v7 static analysis (dotnet rule set)binwalk.txt— binwalk signature scan (no embedded archives)rabin2-info.txt— radare2 binary info (rabin2 -I)exiftool.json— ExifTool PE metadatadynamic-analysis.md— CAPE detonation skipped (no Windows guest)- Radare2 analysis level 3 completed on CIL binary (1,232 functions recovered)
Report generated 2026-08-09. Static-only; no runtime confirmation available.