typeanalysisfamilyquasarconfidencehighcreated2026-08-08updated2026-08-08dotnetratmalware-familyc2persistencecollectiondefense-evasiondiscoveryexecutionmitre-attck
SHA-256: 00f1da323b1e36d3d24e3a06378dec95306971fdb7f1e1a760b079db39b96365

quasar: 00f1da32 — Third confirmed v1.4.1.0 sibling, March 2023 build

Executive Summary — A third unobfuscated build of the open-source Quasar RAT (v1.4.1.0), compiled Sun Mar 12 16:16:39 2023 UTC. Identical to confirmed siblings 0347df42 and 0a47be72 in size, embedded libraries, version resources, and capability fingerprint. Only deltas are SHA-256, ssdeep hash, and entry-point address. High-confidence family attribution. Static-only (no CAPE detonation).

What It Is

  • File: 00f1da323b1e36d3d24e3a06378dec95306971fdb7f1e1a760b079db39b96365, 3.3 MB (3,266,048 bytes) ^[file.txt]
  • Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Assembly version: 1.4.1.0 ^[pefile.txt:233] ^[exiftool.json:46]
  • Version info: FileDescription Quasar Client, ProductName Quasar, Copyright Copyright © MaxXor 2023, OriginalFilename Client.exe ^[exiftool.json:38-44]
  • Signed: No ^[rabin2-info.txt:27]
  • Packed / obfuscated: None. .text entropy 6.08. ^[pefile.txt:92]
  • Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]

Family attribution is high-confidence via Quasar.Common, Version=1.4.1.0 ^[strings.txt:100], Quasar Client version-info ^[exiftool.json:38], and identical capa capability bundle to siblings 0347df42 and 0a47be72. This is a stock build, not a fork.

How It Works

See the deep-dive on sibling 0347df42 for full module and TTP breakdown: quasar entity page and report /intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html.

Key modules confirmed present in this sibling via identical capa fingerprint and string matches:

  • Keylogging via Gma.System.MouseKeyHook v5.6.130 ^[strings.txt:99] ^[capa.txt]
  • Browser credential recovery (Chrome/Chromium-based) ^[capa.txt]
  • Remote shell (DoShellExecute) ^[capa.txt]
  • File manager with chunked upload/download ^[capa.txt]
  • Desktop / webcam capture ^[capa.txt]
  • Reverse proxy / SOCKS-like tunneling ^[capa.txt]
  • System information discovery, geo-location, process enumeration ^[capa.txt]
  • Registry manipulation and startup persistence (DoStartupItemAdd, LocalMachineRun, CurrentUserRunOnce) ^[capa.txt]
  • Scheduled task persistence (capa schedule task via schtasks, 2 matches) ^[capa.txt]
  • Self-uninstall (DoClientUninstall) ^[capa.txt]
  • BouncyCastle.Crypto v1.9.0 embedded for TLS/cert handling ^[strings.txt:97] ^[capa.txt]
  • protobuf-net v2.4.0 serialized TCP C2 framing ^[strings.txt:100] ^[capa.txt]

No hardcoded C2 host, port, or password visible in plaintext strings — injected at build time via the Quasar builder. Not recoverable statically.

Sibling Delta

Attribute 0347df42 0a47be72 00f1da32 (this)
SHA-256 prefix 0347df42 0a47be72 00f1da32
Filename nungcac.exe Client-built.exe 00f1da32… (hash as name)
Compile timestamp Sun Mar 12 16:16:39 2023 Sun Mar 12 16:16:39 2023 Sun Mar 12 16:16:39 2023
Assembly version 1.4.1.0 1.4.1.0 1.4.1.0
Size 3,266,048 bytes 3,266,048 bytes 3,266,048 bytes
Entry point 0x31e48e 0x31e49e 0x31e4ae
ssdeep 49152:zvme821/… 49152:zvme821/… (identical) 49152:DvxAd23la… (same blocksize, divergent hash)
Capabilities Identical Identical Identical

All three siblings share the same compile-to-the-second timestamp, same embedded library versions, and same unobfuscated CIL metadata. The ssdeep and entry-point differences are builder-output noise from distinct build passes or filename changes. No functional delta.

Decompiled Behavior

Not applicable — pure .NET CIL. Ghidra does not produce meaningful pseudo-C from CIL. ILSpy / dnSpy would be the correct tool. The assembly is completely unobfuscated; behaviour is recoverable directly from strings, capa, and pefile metadata. No control-flow obfuscation, no string encryption, no anti-debug, no anti-VM.

C2 Infrastructure

Not recoverable statically. C2 host/port/password injected at build time via the Quasar builder; not present as plaintext in this binary. No IP addresses, domains, or URL patterns in the string table.

Interesting Tidbits

  • Deterministic builder output: The identical timestamp and size across three independent samples strongly suggests these are three successive builds from the same builder session, each with a different output filename. The threat actor rebuilt the client multiple times in the same minute.
  • No opsec effort: Same as siblings — real project name and author left in version-info untouched.
  • FLOSS failure: Same --no flag collision as sibling 0347df42; decoded strings were unnecessary. ^[floss.txt]
  • YARA match: Only generic PE_File_Generic — no custom Quasar YARA triggered during triage. ^[yara.txt]

How To Mess With It (Homelab Replication)

Same procedure as sibling 0347df42:

  1. Clone https://github.com/quasar/Quasar.git
  2. Checkout tag v1.4.1 (or near-March-2023 commit)
  3. Build Client project in Release mode targeting .NET Framework 4.8
  4. Run capa Client.exe — expect identical capability table to this sample's capa.txt
  5. Learning outcome: Baseline for unobfuscated .NET RAT static analysis; useful for spotting obfuscated Quasar variants later.

Deployable Signatures

No new signatures required — use the existing Quasar YARA and Sigma rules from sibling 0347df42.

Detection Signatures

See sibling 0347df42 report for full capa→ATT&CK mapping. Capability fingerprint is identical.

References

  • Sibling deep-dive: /intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html
  • Sibling twin: /intel/analyses/0a47be7287819c40071eef9e3a88157647b9c79918f5975ff5ee27f7e0250abb.html
  • Entity page: quasar
  • Open-source project: https://github.com/quasar/Quasar

Provenance

  • file.txt — file(1) output
  • pefile.txt — pefile Python parser
  • exiftool.json — ExifTool PE metadata
  • rabin2-info.txt — radare2 rabin2 -I
  • strings.txt — strings(1) output
  • capa.txt — Mandiant flare-capa v7.3.0 static analysis
  • floss.txt — flare-floss (failed with argument-parsing error)
  • yara.txt — YARA generic PE match
  • binwalk.txt — binwalk embedded-artefact scan
  • dynamic-analysis.md — CAPE status (skipped, no Windows guest)