typeanalysisfamilyquasarconfidencehighcreated2026-08-08updated2026-08-08dotnetratmalware-familyc2persistencecollectiondefense-evasiondiscoveryexecutionmitre-attck
SHA-256: 0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216

quasar: 0464caa1 — Quasar RAT v1.4.1.0 with Vietnamese gambling-site masquerade

Executive Summary — Confirmed sibling of the quasar v1.4.1.0 cluster (build timestamp 2023-03-12 16:16:39 UTC). Identical unobfuscated .NET Framework PE32 footprint to 0347df42, but with a re-branded VS_VERSIONINFO block naming socoLIVE, xoilac client, and 8xbet — Vietnamese gambling/live-streaming brands. No packing, no obfuscation, no CAPE detonation. Static-only.

What It Is

  • File: 0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216, 3.3 MB (3,266,048 bytes) ^[file.txt]
  • Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Assembly version: 1.4.1.0 (same as 0347df42 cluster) ^[strings.txt:98]
  • Version info (masquerade): FileDescription xoilac client, CompanyName socoLIVE, LegalCopyright/LegalTrademarks 8xbet, OriginalFilename socolive.exe, ProductName xoilac, AssemblyVersion 1.23.0.1 ^[exiftool.json:37-46] ^[pefile.txt:233-243]
  • Signed: No ^[rabin2-info.txt:27]
  • Packed / obfuscated: None. No ConfuserEx, SmartAssembly, Xenocode, or dotfuscator. .text entropy 6.08 — typical unobfuscated CIL. ^[pefile.txt:92]
  • Dynamic analysis: Skipped — no CAPE Windows guest available.

Family attribution is high-confidence: the binary carries the literal namespace Quasar.Common, Version=1.4.1.0 ^[strings.txt:101] and the identical embedded library trio (BouncyCastle.Crypto v1.9.0.0, protobuf-net v2.4.0.0, Gma.System.MouseKeyHook v5.6.130.0) ^[strings.txt:97-100] that fingerprint the Quasar cluster. The build timestamp matches the 0347df42 sibling to the second.

How It Works

This sample is a cluster sibling of 0347df42. For the full module inventory — keylogging, credential harvesting, remote shell, file manager, desktop/webcam capture, reverse proxy, system discovery, registry manipulation, persistence, and self-uninstall — see the primary deep-dive at raw/analyses/0347df428374.../report.md and the family page quasar.

Per-sample delta (this sibling):

The only meaningful deviation from the stock Quasar build is the version-info masquerade. Instead of the default Quasar Client / Copyright © MaxXor / Client.exe branding, the actor substituted Vietnamese gambling/live-streaming identifiers:

Field Stock Quasar (0347df42) This Sample (0464caa1)
FileDescription Quasar Client xoilac client
CompanyName (empty or MaxXor) socoLIVE
LegalCopyright Copyright © MaxXor 2023 8xbet
LegalTrademarks Copyright © MaxXor 2023 8xbet
OriginalFilename Client.exe socolive.exe
ProductName Quasar xoilac
AssemblyVersion 1.4.1.0 1.23.0.1

The AssemblyVersion bump to 1.23.0.1 is a cosmetic change in the VS_VERSIONINFO block; the actual .NET assembly metadata still reports Client, Version=1.4.1.0 ^[strings.txt:98], confirming the underlying binary is unmodified stock code.

No new capa capabilities were detected beyond the standard Quasar bundle (see capa.txt in 0347df42 for the identical fingerprint). ^[capa.txt]

Decompiled Behavior

Not applicable — pure .NET CIL. See 0347df42 deep-dive. ILSpy/dnSpy would be the correct tool; the assembly is unobfuscated and all behaviour is recoverable from strings and capa.

C2 Infrastructure

Not recoverable statically. Quasar builder injects C2 host/port at build time; no plaintext C2 strings in the binary. No IP addresses, domains, or URL patterns found. See 0347df42 report for identical assessment.

Interesting Tidbits

  • Gambling-site masquerade: socoLIVE, xoilac, and 8xbet are all Vietnamese gambling / live-football-streaming brands. The actor is targeting a Vietnamese-speaking audience or laundering the binary through regionally familiar branding. ^[exiftool.json:37-44]
  • AssemblyVersion mismatch: VS_VERSIONINFO says 1.23.0.1, but the .NET manifest still says 1.4.1.0. The actor edited the Win32 resource block but did not touch the assembly metadata — a lazy re-brand. ^[strings.txt:98] ^[exiftool.json:46]
  • Identical capa fingerprint: Every capability hit in this sample matches the 0347df42 sibling line-for-line (same match counts: 63 PRNG, 9 Base64 decode, 3 User-Agent, 2 mouse hooks, etc.). Confirms zero code change. ^[capa.txt]
  • No evasion: No anti-VM, anti-debug, sandbox gates, or sleep loops. Stock open-source build. ^[capa.txt]
  • FLOSS failure: Same command-line invocation error as 0347df42 (--no flag collision). Unobfuscated anyway. ^[floss.txt]

How To Mess With It (Homelab Replication)

See 0347df42 report for full replication steps — clone the Quasar repo, build the Client project, and compare capa fingerprints. The only additional step for this variant is:

  1. After building Client.exe, use a resource editor (e.g., Resource Hacker, CFF Explorer) to edit the VS_VERSIONINFO block.
  2. Replace Quasar Client → xoilac client, MaxXor → 8xbet, Client.exe → socolive.exe, etc.
  3. Bump the numeric version fields to 1.23.0.1.
  4. Re-save the PE.
  5. Run capa on the modified binary — the capability table will be identical to the original, proving that version-info masquerade does not alter runtime behaviour.

Deployable Signatures

YARA rule — Quasar cluster with gambling-site masquerade variant

rule quasar_rat_gambling_masquerade
{
    meta:
        description = "Quasar RAT v1.4.1.0 with Vietnamese gambling-site version-info masquerade"
        author = "Titus"
        date = "2026-08-08"
        sha256 = "0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216"
    strings:
        $quasar_common = "Quasar.Common, Version=1.4.1.0" ascii wide
        $pb_net = "protobuf-net, Version=2.4.0.0" ascii wide
        $bc_crypto = "BouncyCastle.Crypto, Version=1.9.0.0" ascii wide
        $mousehook = "Gma.System.MouseKeyHook, Version=5.6.130.0" ascii wide
        $masq1 = "xoilac client" wide
        $masq2 = "socoLIVE" wide
        $masq3 = "8xbet" wide
        $masq4 = "socolive.exe" wide
        $masq5 = "xoilac" wide
        $msg_doshell = "DoShellExecute" ascii wide
        $msg_startupadd = "DoStartupItemAdd" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 5MB and
        $quasar_common and
        2 of ($pb_net, $bc_crypto, $mousehook) and
        2 of ($masq*) and
        1 of ($msg_*)
}

IOC list

Type Value Notes
SHA256 0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216 This sample
Build timestamp 2023-03-12 16:16:39 UTC Shared with 0347df42 cluster
FileDescription xoilac client Masquerade brand
CompanyName socoLIVE Masquerade brand
LegalCopyright 8xbet Masquerade brand
OriginalFilename socolive.exe Masquerade filename
AssemblyVersion (Win32) 1.23.0.1 Cosmetic bump
AssemblyVersion (.NET) 1.4.1.0 Stock Quasar
Library protobuf-net, Version=2.4.0.0 Cluster fingerprint
Library BouncyCastle.Crypto, Version=1.9.0.0 Cluster fingerprint
Library Gma.System.MouseKeyHook, Version=5.6.130.0 Cluster fingerprint

Behavioral fingerprint

Identical to 0347df42: unobfuscated .NET Framework PE32 executable masquerading as a Vietnamese gambling-client application (xoilac client by socoLIVE). On execution it loads Gma.System.MouseKeyHook for global keyboard capture, initialises a protobuf-net TCP transport layer, and opens outbound TCP connections to an operator-configured C2 server. Enumerates local system (processes, drives, registry, network interfaces), logs keystrokes, captures screenshots and webcam frames, supports remote shell execution and file-manager operations. Persistence via registry Run keys or scheduled tasks. No sandbox evasion, no anti-debug, no packing — a stock open-source RAT build with only the version-info block altered.

Detection Signatures

capa → MITRE ATT&CK mapping (static-only, identical to 0347df42):

capa capability ATT&CK Technique
gather chrome based browser login information T1555.003
log keystrokes via polling T1056.001
reference WMI statements / access WMI data T1047
schedule task via schtasks T1053.005
encode/decode data using Base64 T1140 / T1027
encrypt data using DPAPI T1553.005
create TCP socket / send data / receive data —
query or enumerate registry key/value T1012
create process in .NET T1129
set registry value T1112
enumerate processes T1057
get OS version / get hostname / get MAC address T1082
get geographical location T1614
bypass Mark of the Web T1553.005

References

  • Primary cluster deep-dive: /intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html
  • Family page: quasar
  • Open-source project: https://github.com/quasar/Quasar (MaxXor)
  • Artifact ID: 2d95ff19-1f5e-4f69-bbdb-96dbc8a164d3
  • Source: OpenCTI → MalwareBazaar (quasarrat label + test label)

Provenance

  • This report synthesized from static analysis outputs in raw/analyses/0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216/:
    • file.txt, pefile.txt, exiftool.json, rabin2-info.txt — build metadata and version info
    • strings.txt — unobfuscated .NET namespace and message-type enumeration
    • capa.txt — capability detection and ATT&CK mapping (static scope)
    • binwalk.txt — embedded crypto constants from BouncyCastle
    • floss.txt — command-line invocation failure; no decoded strings needed
    • metadata.json — artifact metadata and OpenCTI labels
    • triage.json — triage routing record
  • No dynamic-analysis.md or cape-report.json — CAPE skipped (no Windows guest).
  • Tools: file v5.44, pefile 2023.2.7, ExifTool 12.76, radare2 5.9.2, capa v8.0.1, flare-floss (failed invocation), binwalk 2.3.2, yara 4.5.0