typeanalysisfamilyquasarconfidencehighcreated2026-08-09updated2026-08-09dotnetratmalware-familyc2persistencecollectiondiscoveryexecutiondefense-evasionmitre-attck
SHA-256: 007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b

quasar: 007c13a2 — v1.4.1.0 stock build with steam-update.exe masquerade

Executive Summary

Stock open-source Quasar RAT client v1.4.1.0 by MaxXor, compiled for .NET Framework 4.5.2 with no obfuscation, no packing, and no anti-analysis countermeasures. Masquerades as steam-update.exe in version-info fields. Preliminary OpenCTI label quasarrat resolves to the same family. Static-only analysis (CAPE skipped — no Windows guest). Identical build fingerprint to confirmed siblings 0347df42, 00f1da32, and 0a47be72.

What It Is

Field Value
SHA-256 007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b
File type PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
Size 139,776 bytes (140 KB) ^[triage.json]
Timestamp 0xB58097E2 → Wed Jun 30 06:06:26 2066 UTC ^[pefile.txt:34]
Linker .NET 8.0 (MajorLinkerVersion: 0x30) ^[pefile.txt:45]
Target framework .NET Framework 4.5.2 (v4.0.30319, .NETFramework,Version=v4.5.2) ^[strings.txt:4], ^[strings.txt:1711]
Signed No ^[rabin2-info.txt:27]
Overlay None ^[rabin2-info.txt:23]
Entropy (text) 5.97 — consistent with uncompressed CIL ^[pefile.txt:92]

Version-info / masquerade: FileDescription: Quasar Client, InternalName: steam-update.exe, OriginalFilename: steam-update.exe, LegalCopyright: Copyright © MaxXor 2023, ProductName: Quasar, ProductVersion: 1.4.1 ^[pefile.txt:237-243], ^[exiftool.json:38-46]

Family ascription: Confirmed Quasar (MaxXor open-source RAT). The quasarrat preliminary label from OpenCTI is an alternate tagging of the same family. Build artefacts, namespace hierarchy, and version-info strings match the established quasar entity exactly. ^[entities/quasar.md]

How It Works

Entry point is the standard .NET PE stub (mscoree.dll._CorExeMain) ^[pefile.txt:255], handing control to the CLR which loads Quasar.Client.Program and calls Main. The binary is a stock client build from the public Quasar repository — all type names, namespaces, and string literals are unobfuscated.

Namespaces observed: Quasar.Client, Quasar.Client.Config, Quasar.Client.IO, Quasar.Client.Networking, Quasar.Client.Recovery.Browsers, Quasar.Client.Recovery.FtpClients, Quasar.Client.ReverseProxy, Quasar.Client.Logging, Quasar.Client.Helper, Quasar.Client.Utilities, Quasar.Client.User, Quasar.Client.Setup, Quasar.Client.Registry, Quasar.Common.Messages, Quasar.Common.Models, Quasar.Common.Video.Codecs, Quasar.Common.Cryptography, Quasar.Common.IO, Quasar.Common.DNS, Quasar.Common.Extensions, Quasar.Common.Helpers, Quasar.Common.Enums ^[strings.txt:passim]

Third-party libraries: protobuf-net (TCP message framing), Org.BouncyCastle.Crypto (TLS + AES-GCM), Gma.System.MouseKeyHook (global keylogger hook), System.Drawing (screenshot codec) ^[strings.txt:847], ^[strings.txt:1261], ^[strings.txt:1650]

No packing, no obfuscation, no anti-analysis: No ConfuserEx, SmartAssembly, dotfuscator, or custom crypter indicators. All strings, type names, and P/Invoke imports are in plaintext. No anti-VM, anti-debug, or timing gates detected in static analysis. ^[capa.txt], ^[strings.txt]

Decompiled Behavior

Radare2 analysis completed at level 3 and recovered 1,232 CIL functions ^[r2:analysis-log]. However, radare2's CIL backend produces IL bytecode disassembly rather than readable pseudo-C; the decompiler (pdc) is not useful for CIL. The entry-point chain is standard: _CorExeMain → CLR bootstrap → Quasar.Client.Program.Main.

Key handler classes (inferred from type names and capa matches):

  • KeyloggerHandler / KeyloggerService — global keyboard hook via Gma.System.MouseKeyHook ^[capa.txt:collection/browser]
  • RemoteDesktopHandler / UnsafeStreamCodec — desktop framebuffer streaming ^[capa.txt]
  • FileManagerHandler — remote file upload/download/delete/enumeration ^[capa.txt]
  • TaskManagerHandler — process enumeration and termination ^[capa.txt]
  • RegistryHandler / RegistryEditor — registry read/write/delete/rename ^[capa.txt]
  • PasswordRecoveryHandler — browser credential extraction (Chrome, Edge, Brave, Opera, Firefox, Yandex, IE, WinSCP, FileZilla, OperaGX) ^[capa.txt], ^[strings.txt:1103-1112]
  • RemoteShellHandler — cmd.exe remote shell via redirected stdout/stderr ^[capa.txt]
  • ReverseProxyHandler / ReverseProxyClient — SOCKS-like tunneling through the C2 socket ^[capa.txt]
  • SystemInformationHandler — WMI + P/Invoke system fingerprinting ^[capa.txt]
  • WebsiteVisitorHandler — hidden browser navigation ^[capa.txt]
  • TcpConnectionsHandler — GetExtendedTcpTable network connection enumeration ^[capa.txt], ^[strings.txt:435]
  • ClientInstaller / ClientUninstaller — self-install to %APPDATA% and registry Run persistence ^[capa.txt]
  • ClientUpdater — in-place binary update via isUpdate flag ^[strings.txt:628]

No novel functions warrant individual decompilation — the entire surface is documented in the open-source Quasar repository.

C2 Infrastructure

Protocol: protobuf-net serialized TCP over TLS (BouncyCastle TLS wrapper). The client validates the server certificate against a hardcoded or builder-injected cert hash (ValidateServerCertificate, _serverCertificate) ^[strings.txt:625-626].

No hardcoded C2 endpoints recovered statically — host, port, and certificate are injected at build time by the Quasar builder GUI. This is consistent with all confirmed siblings in the corpus. ^[entities/quasar.md]

Network indicators observable statically:

  • TcpClient + SslStream for C2 transport ^[capa.txt]
  • set_UserAgent / reference HTTP User-Agent string — capa hits suggest HTTP fallback or beacon User-Agent customization ^[capa.txt]
  • set_WebProxy — proxy-aware C2 channel ^[capa.txt]
  • get_KEEP_ALIVE_TIME / get_KEEP_ALIVE_INTERVAL — TCP keepalive tuning for long-lived C2 socket ^[strings.txt:118], ^[strings.txt:142]

Mutex: SingleInstanceMutex / ApplicationMutex — named mutex for single-instance gating ^[strings.txt:1607-1610]

Interesting Tidbits

  • steam-update.exe masquerade is purely cosmetic — the binary does not interact with Steam APIs or attempt Steam credential theft beyond the generic Chromium-based browser recovery.
  • A 64-character hex string (7D78CB380BF5EFB7B851409CA6A875F77DECF09D19B9149DA17A3EBF674BC0F9) appears in #Strings metadata. Purpose unconfirmed — likely a placeholder SHA-256 used by the builder for certificate-pinning or update-package integrity, but not referenced in the open-source v1.4.1.0 code. ^[strings.txt:88]
  • The isUpdate flag and ClientUpdater class support in-place binary replacement without re-installing persistence — a stealthier upgrade path than dropping a second file. ^[strings.txt:628]
  • ClientSetupBase and ApplicationSettingsBase suggest the builder uses System.Configuration for default settings, but the deployed client has no embedded .config resource — settings are compiled into the binary. ^[strings.txt:596-597]
  • FLOSS run failed with argument-parsing error (--no flag collision) ^[floss.txt] — the tool output is useless; the sample has no stack-string obfuscation to decode.

How To Mess With It (Homelab Replication)

  1. Clone the Quasar repo: git clone https://github.com/quasar/Quasar.git (or the MaxXor archive).
  2. Open Quasar.sln in Visual Studio 2019+.
  3. Build the Client project for Release | AnyCPU targeting .NET Framework 4.5.2.
  4. In the builder GUI, set output filename to steam-update.exe, configure a local TCP listener, and build.
  5. Run capa on the resulting PE — should hit the same ATT&CK tactics (Collection, Credential Access, Discovery, Execution, Persistence) and MBC behaviors (C2 Communication, HTTP/TCP Socket, Registry, Process) as this sample.
  6. Compare strings output — the namespace tree and handler class names will be nearly identical.

What you'll learn: How a commodity open-source RAT looks when built with default settings, and why static signatures based on unobfuscated type names have high true-positive rates but low long-term value (any recompile breaks them).

Deployable Signatures

YARA rule

rule quasar_stock_v1_4_1_0
{
    meta:
        description = "Stock Quasar RAT client v1.4.1.0 — unobfuscated .NET build"
        author = "PacketPursuit"
        date = "2026-08-09"
        hash = "007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b"
        family = "quasar"
    strings:
        $ver1 = "Quasar Client" wide
        $ver2 = "Quasar" wide
        $ver3 = "Copyright \xa9 MaxXor 2023" wide
        $ver4 = "steam-update.exe" wide
        $ns1  = "Quasar.Client.Helper" ascii wide
        $ns2  = "Quasar.Client.Recovery.Browsers" ascii wide
        $ns3  = "Quasar.Client.ReverseProxy" ascii wide
        $ns4  = "Quasar.Common.Cryptography" ascii wide
        $lib1 = "Gma.System.MouseKeyHook" ascii wide
        $lib2 = "Org.BouncyCastle.Crypto" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        pe.exports("_CorExeMain") and
        3 of ($ver*) and
        2 of ($ns*) and
        any of ($lib*)
}

Sigma rule

title: Quasar RAT Stock Client Process Spawn
description: Detects child process patterns consistent with Quasar RAT remote shell and file manager execution
logsource:
  category: process_creation
  product: windows
detection:
  selection:
    - Image|endswith: '\steam-update.exe'
    - CommandLine|contains:
        - 'cmd.exe /c'
        - 'powershell.exe -NoP -Enc'
    - ParentImage|endswith: '\steam-update.exe'
  quasar_strings:
    - CommandLine|contains:
        - 'Quasar.Client'
        - 'Quasar.Common'
  condition: selection or quasar_strings
falsepositives:
  - None expected; steam-update.exe is not a legitimate Windows or Steam binary path
level: high

IOC list

Indicator Value Type
SHA-256 007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b Hash
MD5 668a2576569169db132b965366a616ed Hash
SSDeep 3072:5VizmsUsAdsc328EOzZnsXSKqn4iLaBCVZpb2Gmk6vMfWTJ5:XXa8hzZsXSt4oHZpb280P Fuzzy hash
TLSH — Not present in triage output
Mutex SingleInstanceMutex / ApplicationMutex Mutex name
Registry (persistence) HKCU\Software\Microsoft\Windows\CurrentVersion\Run or HKLM\...\Run — value name varies by builder config Persistence
File path (install) %APPDATA%\steam-update.exe or builder-configured path Staging
Network TCP outbound to builder-configured host:port, TLS handshake via BouncyCastle C2

Behavioral fingerprint

This binary is a .NET Framework 4.5.2 PE32 GUI executable that, upon launch, creates a named mutex (SingleInstanceMutex), reads or creates its installation directory under %APPDATA%, establishes a TCP connection to a remote host over TLS (BouncyCastle SslStream), and then enters a message-processor loop awaiting protobuf-net serialized commands. It supports remote shell execution via redirected cmd.exe, desktop streaming via BitBlt/UnsafeStreamCodec, global keylogging via Gma.System.MouseKeyHook, browser credential recovery from Chromium/Firefox/IE profiles using DPAPI and SQLite, file manager operations, process enumeration/termination, registry manipulation, reverse proxy tunneling, and in-place self-update. Persistence is achieved via registry Run keys or scheduled tasks. No anti-VM, anti-debug, or packing is present.

Detection Signatures

capa → ATT&CK mapping

capa capability ATT&CK technique
gather chrome based browser login information T1555.003
reference SQL statements T1213
reference WMI statements T1047
get MAC address in .NET T1016
list TCP connections and listeners T1049
receive data / send data T1071
reference HTTP User-Agent string T1071.001
set HTTP User-Agent in .NET T1071.001
set web proxy in .NET T1090
create HTTP request T1071.001
create TCP socket T1071.001
decode data using Base64 in .NET T1140
encrypt data using DPAPI T1555.003
hash data via WinCrypt / SHA1 —
check file extension in .NET T1083
enumerate drives T1083
copy file / create directory / delete file / move file / read file / write file T1105 / T1070.004 / T1083
enumerate gui resources / get graphical window text T1010
get disk information T1082
allocate/manipulate unmanaged memory in .NET T1055
create or open mutex —
get domain information / networking interfaces / hostname T1016 / T1082
create a process with modified I/O handles T1059.003 / T1106
enumerate processes / find process by PID or name T1057
terminate process T1057
query or enumerate registry key/value T1012
set registry value / delete registry key/value T1112
get session integrity level / user name T1033
create thread / suspend thread T1055
access WMI data in .NET T1047
schedule task via schtasks T1053.005

Full capa output available in capa.txt. ^[capa.txt]

References

  • Quasar open-source repository (MaxXor): https://github.com/quasar/Quasar
  • MalwareBazaar entry for this sample: https://bazaar.abuse.ch/sample/007c13a26d76a1281519960109bbf040ebdf5c497b00d4ffe0d0ac417cd8d33b/
  • Sibling analysis: 0347df42 (Quasar v1.4.1.0 stock build, March 2023) ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]
  • Entity page: quasar
  • Related technique: protobuf-net-asymmetric-client-rat-protocol

Provenance

Analysis based on static artifacts generated by the triage pipeline:

  • file.txt — file(1) output
  • pefile.txt — pefile Python library header dump
  • strings.txt — ASCII/Unicode strings (1,792 lines)
  • floss.txt — FLOSS attempted but failed due to CLI argument collision; no decoded strings because sample has no obfuscation
  • capa.txt — Mandiant capa v7 static analysis (dotnet rule set)
  • binwalk.txt — binwalk signature scan (no embedded archives)
  • rabin2-info.txt — radare2 binary info (rabin2 -I)
  • exiftool.json — ExifTool PE metadata
  • dynamic-analysis.md — CAPE detonation skipped (no Windows guest)
  • Radare2 analysis level 3 completed on CIL binary (1,232 functions recovered)

Report generated 2026-08-09. Static-only; no runtime confirmation available.