00f1da323b1e36d3d24e3a06378dec95306971fdb7f1e1a760b079db39b96365quasar: 00f1da32 — Third confirmed v1.4.1.0 sibling, March 2023 build
Executive Summary — A third unobfuscated build of the open-source Quasar RAT (v1.4.1.0), compiled Sun Mar 12 16:16:39 2023 UTC. Identical to confirmed siblings 0347df42 and 0a47be72 in size, embedded libraries, version resources, and capability fingerprint. Only deltas are SHA-256, ssdeep hash, and entry-point address. High-confidence family attribution. Static-only (no CAPE detonation).
What It Is
- File:
00f1da323b1e36d3d24e3a06378dec95306971fdb7f1e1a760b079db39b96365, 3.3 MB (3,266,048 bytes) ^[file.txt] - Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
- Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Assembly version: 1.4.1.0 ^[pefile.txt:233] ^[exiftool.json:46]
- Version info: FileDescription
Quasar Client, ProductNameQuasar, CopyrightCopyright © MaxXor 2023, OriginalFilenameClient.exe^[exiftool.json:38-44] - Signed: No ^[rabin2-info.txt:27]
- Packed / obfuscated: None. .text entropy 6.08. ^[pefile.txt:92]
- Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]
Family attribution is high-confidence via Quasar.Common, Version=1.4.1.0 ^[strings.txt:100], Quasar Client version-info ^[exiftool.json:38], and identical capa capability bundle to siblings 0347df42 and 0a47be72. This is a stock build, not a fork.
How It Works
See the deep-dive on sibling 0347df42 for full module and TTP breakdown: quasar entity page and report /intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html.
Key modules confirmed present in this sibling via identical capa fingerprint and string matches:
- Keylogging via
Gma.System.MouseKeyHookv5.6.130 ^[strings.txt:99] ^[capa.txt] - Browser credential recovery (Chrome/Chromium-based) ^[capa.txt]
- Remote shell (
DoShellExecute) ^[capa.txt] - File manager with chunked upload/download ^[capa.txt]
- Desktop / webcam capture ^[capa.txt]
- Reverse proxy / SOCKS-like tunneling ^[capa.txt]
- System information discovery, geo-location, process enumeration ^[capa.txt]
- Registry manipulation and startup persistence (
DoStartupItemAdd,LocalMachineRun,CurrentUserRunOnce) ^[capa.txt] - Scheduled task persistence (capa
schedule task via schtasks, 2 matches) ^[capa.txt] - Self-uninstall (
DoClientUninstall) ^[capa.txt] - BouncyCastle.Crypto v1.9.0 embedded for TLS/cert handling ^[strings.txt:97] ^[capa.txt]
- protobuf-net v2.4.0 serialized TCP C2 framing ^[strings.txt:100] ^[capa.txt]
No hardcoded C2 host, port, or password visible in plaintext strings — injected at build time via the Quasar builder. Not recoverable statically.
Sibling Delta
| Attribute | 0347df42 | 0a47be72 | 00f1da32 (this) |
|---|---|---|---|
| SHA-256 prefix | 0347df42 |
0a47be72 |
00f1da32 |
| Filename | nungcac.exe |
Client-built.exe |
00f1da32… (hash as name) |
| Compile timestamp | Sun Mar 12 16:16:39 2023 | Sun Mar 12 16:16:39 2023 | Sun Mar 12 16:16:39 2023 |
| Assembly version | 1.4.1.0 | 1.4.1.0 | 1.4.1.0 |
| Size | 3,266,048 bytes | 3,266,048 bytes | 3,266,048 bytes |
| Entry point | 0x31e48e |
0x31e49e |
0x31e4ae |
| ssdeep | 49152:zvme821/… |
49152:zvme821/… (identical) |
49152:DvxAd23la… (same blocksize, divergent hash) |
| Capabilities | Identical | Identical | Identical |
All three siblings share the same compile-to-the-second timestamp, same embedded library versions, and same unobfuscated CIL metadata. The ssdeep and entry-point differences are builder-output noise from distinct build passes or filename changes. No functional delta.
Decompiled Behavior
Not applicable — pure .NET CIL. Ghidra does not produce meaningful pseudo-C from CIL. ILSpy / dnSpy would be the correct tool. The assembly is completely unobfuscated; behaviour is recoverable directly from strings, capa, and pefile metadata. No control-flow obfuscation, no string encryption, no anti-debug, no anti-VM.
C2 Infrastructure
Not recoverable statically. C2 host/port/password injected at build time via the Quasar builder; not present as plaintext in this binary. No IP addresses, domains, or URL patterns in the string table.
Interesting Tidbits
- Deterministic builder output: The identical timestamp and size across three independent samples strongly suggests these are three successive builds from the same builder session, each with a different output filename. The threat actor rebuilt the client multiple times in the same minute.
- No opsec effort: Same as siblings — real project name and author left in version-info untouched.
- FLOSS failure: Same
--noflag collision as sibling0347df42; decoded strings were unnecessary. ^[floss.txt] - YARA match: Only generic
PE_File_Generic— no custom Quasar YARA triggered during triage. ^[yara.txt]
How To Mess With It (Homelab Replication)
Same procedure as sibling 0347df42:
- Clone
https://github.com/quasar/Quasar.git - Checkout tag v1.4.1 (or near-March-2023 commit)
- Build
Clientproject in Release mode targeting .NET Framework 4.8 - Run
capa Client.exe— expect identical capability table to this sample'scapa.txt - Learning outcome: Baseline for unobfuscated .NET RAT static analysis; useful for spotting obfuscated Quasar variants later.
Deployable Signatures
No new signatures required — use the existing Quasar YARA and Sigma rules from sibling 0347df42.
Detection Signatures
See sibling 0347df42 report for full capa→ATT&CK mapping. Capability fingerprint is identical.
References
- Sibling deep-dive:
/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html - Sibling twin:
/intel/analyses/0a47be7287819c40071eef9e3a88157647b9c79918f5975ff5ee27f7e0250abb.html - Entity page: quasar
- Open-source project: https://github.com/quasar/Quasar
Provenance
file.txt— file(1) outputpefile.txt— pefile Python parserexiftool.json— ExifTool PE metadatarabin2-info.txt— radare2rabin2 -Istrings.txt— strings(1) outputcapa.txt— Mandiant flare-capa v7.3.0 static analysisfloss.txt— flare-floss (failed with argument-parsing error)yara.txt— YARA generic PE matchbinwalk.txt— binwalk embedded-artefact scandynamic-analysis.md— CAPE status (skipped, no Windows guest)