0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216quasar: 0464caa1 — Quasar RAT v1.4.1.0 with Vietnamese gambling-site masquerade
Executive Summary — Confirmed sibling of the quasar v1.4.1.0 cluster (build timestamp 2023-03-12 16:16:39 UTC). Identical unobfuscated .NET Framework PE32 footprint to 0347df42, but with a re-branded VS_VERSIONINFO block naming socoLIVE, xoilac client, and 8xbet — Vietnamese gambling/live-streaming brands. No packing, no obfuscation, no CAPE detonation. Static-only.
What It Is
- File:
0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216, 3.3 MB (3,266,048 bytes) ^[file.txt] - Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
- Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Assembly version: 1.4.1.0 (same as
0347df42cluster) ^[strings.txt:98] - Version info (masquerade): FileDescription
xoilac client, CompanyNamesocoLIVE, LegalCopyright/LegalTrademarks8xbet, OriginalFilenamesocolive.exe, ProductNamexoilac, AssemblyVersion1.23.0.1^[exiftool.json:37-46] ^[pefile.txt:233-243] - Signed: No ^[rabin2-info.txt:27]
- Packed / obfuscated: None. No ConfuserEx, SmartAssembly, Xenocode, or dotfuscator.
.textentropy 6.08 — typical unobfuscated CIL. ^[pefile.txt:92] - Dynamic analysis: Skipped — no CAPE Windows guest available.
Family attribution is high-confidence: the binary carries the literal namespace Quasar.Common, Version=1.4.1.0 ^[strings.txt:101] and the identical embedded library trio (BouncyCastle.Crypto v1.9.0.0, protobuf-net v2.4.0.0, Gma.System.MouseKeyHook v5.6.130.0) ^[strings.txt:97-100] that fingerprint the Quasar cluster. The build timestamp matches the 0347df42 sibling to the second.
How It Works
This sample is a cluster sibling of 0347df42. For the full module inventory — keylogging, credential harvesting, remote shell, file manager, desktop/webcam capture, reverse proxy, system discovery, registry manipulation, persistence, and self-uninstall — see the primary deep-dive at raw/analyses/0347df428374.../report.md and the family page quasar.
Per-sample delta (this sibling):
The only meaningful deviation from the stock Quasar build is the version-info masquerade. Instead of the default Quasar Client / Copyright © MaxXor / Client.exe branding, the actor substituted Vietnamese gambling/live-streaming identifiers:
| Field | Stock Quasar (0347df42) |
This Sample (0464caa1) |
|---|---|---|
| FileDescription | Quasar Client |
xoilac client |
| CompanyName | (empty or MaxXor) | socoLIVE |
| LegalCopyright | Copyright © MaxXor 2023 |
8xbet |
| LegalTrademarks | Copyright © MaxXor 2023 |
8xbet |
| OriginalFilename | Client.exe |
socolive.exe |
| ProductName | Quasar |
xoilac |
| AssemblyVersion | 1.4.1.0 |
1.23.0.1 |
The AssemblyVersion bump to 1.23.0.1 is a cosmetic change in the VS_VERSIONINFO block; the actual .NET assembly metadata still reports Client, Version=1.4.1.0 ^[strings.txt:98], confirming the underlying binary is unmodified stock code.
No new capa capabilities were detected beyond the standard Quasar bundle (see capa.txt in 0347df42 for the identical fingerprint). ^[capa.txt]
Decompiled Behavior
Not applicable — pure .NET CIL. See 0347df42 deep-dive. ILSpy/dnSpy would be the correct tool; the assembly is unobfuscated and all behaviour is recoverable from strings and capa.
C2 Infrastructure
Not recoverable statically. Quasar builder injects C2 host/port at build time; no plaintext C2 strings in the binary. No IP addresses, domains, or URL patterns found. See 0347df42 report for identical assessment.
Interesting Tidbits
- Gambling-site masquerade:
socoLIVE,xoilac, and8xbetare all Vietnamese gambling / live-football-streaming brands. The actor is targeting a Vietnamese-speaking audience or laundering the binary through regionally familiar branding. ^[exiftool.json:37-44] - AssemblyVersion mismatch: VS_VERSIONINFO says
1.23.0.1, but the .NET manifest still says1.4.1.0. The actor edited the Win32 resource block but did not touch the assembly metadata — a lazy re-brand. ^[strings.txt:98] ^[exiftool.json:46] - Identical capa fingerprint: Every capability hit in this sample matches the
0347df42sibling line-for-line (same match counts: 63 PRNG, 9 Base64 decode, 3 User-Agent, 2 mouse hooks, etc.). Confirms zero code change. ^[capa.txt] - No evasion: No anti-VM, anti-debug, sandbox gates, or sleep loops. Stock open-source build. ^[capa.txt]
- FLOSS failure: Same command-line invocation error as
0347df42(--noflag collision). Unobfuscated anyway. ^[floss.txt]
How To Mess With It (Homelab Replication)
See 0347df42 report for full replication steps — clone the Quasar repo, build the Client project, and compare capa fingerprints. The only additional step for this variant is:
- After building
Client.exe, use a resource editor (e.g., Resource Hacker, CFF Explorer) to edit the VS_VERSIONINFO block. - Replace
Quasar Client→xoilac client,MaxXor→8xbet,Client.exe→socolive.exe, etc. - Bump the numeric version fields to
1.23.0.1. - Re-save the PE.
- Run
capaon the modified binary — the capability table will be identical to the original, proving that version-info masquerade does not alter runtime behaviour.
Deployable Signatures
YARA rule — Quasar cluster with gambling-site masquerade variant
rule quasar_rat_gambling_masquerade
{
meta:
description = "Quasar RAT v1.4.1.0 with Vietnamese gambling-site version-info masquerade"
author = "Titus"
date = "2026-08-08"
sha256 = "0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216"
strings:
$quasar_common = "Quasar.Common, Version=1.4.1.0" ascii wide
$pb_net = "protobuf-net, Version=2.4.0.0" ascii wide
$bc_crypto = "BouncyCastle.Crypto, Version=1.9.0.0" ascii wide
$mousehook = "Gma.System.MouseKeyHook, Version=5.6.130.0" ascii wide
$masq1 = "xoilac client" wide
$masq2 = "socoLIVE" wide
$masq3 = "8xbet" wide
$masq4 = "socolive.exe" wide
$masq5 = "xoilac" wide
$msg_doshell = "DoShellExecute" ascii wide
$msg_startupadd = "DoStartupItemAdd" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 5MB and
$quasar_common and
2 of ($pb_net, $bc_crypto, $mousehook) and
2 of ($masq*) and
1 of ($msg_*)
}
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA256 | 0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216 |
This sample |
| Build timestamp | 2023-03-12 16:16:39 UTC |
Shared with 0347df42 cluster |
| FileDescription | xoilac client |
Masquerade brand |
| CompanyName | socoLIVE |
Masquerade brand |
| LegalCopyright | 8xbet |
Masquerade brand |
| OriginalFilename | socolive.exe |
Masquerade filename |
| AssemblyVersion (Win32) | 1.23.0.1 |
Cosmetic bump |
| AssemblyVersion (.NET) | 1.4.1.0 |
Stock Quasar |
| Library | protobuf-net, Version=2.4.0.0 |
Cluster fingerprint |
| Library | BouncyCastle.Crypto, Version=1.9.0.0 |
Cluster fingerprint |
| Library | Gma.System.MouseKeyHook, Version=5.6.130.0 |
Cluster fingerprint |
Behavioral fingerprint
Identical to 0347df42: unobfuscated .NET Framework PE32 executable masquerading as a Vietnamese gambling-client application (xoilac client by socoLIVE). On execution it loads Gma.System.MouseKeyHook for global keyboard capture, initialises a protobuf-net TCP transport layer, and opens outbound TCP connections to an operator-configured C2 server. Enumerates local system (processes, drives, registry, network interfaces), logs keystrokes, captures screenshots and webcam frames, supports remote shell execution and file-manager operations. Persistence via registry Run keys or scheduled tasks. No sandbox evasion, no anti-debug, no packing — a stock open-source RAT build with only the version-info block altered.
Detection Signatures
capa → MITRE ATT&CK mapping (static-only, identical to 0347df42):
| capa capability | ATT&CK Technique |
|---|---|
| gather chrome based browser login information | T1555.003 |
| log keystrokes via polling | T1056.001 |
| reference WMI statements / access WMI data | T1047 |
| schedule task via schtasks | T1053.005 |
| encode/decode data using Base64 | T1140 / T1027 |
| encrypt data using DPAPI | T1553.005 |
| create TCP socket / send data / receive data | — |
| query or enumerate registry key/value | T1012 |
| create process in .NET | T1129 |
| set registry value | T1112 |
| enumerate processes | T1057 |
| get OS version / get hostname / get MAC address | T1082 |
| get geographical location | T1614 |
| bypass Mark of the Web | T1553.005 |
References
- Primary cluster deep-dive:
/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html - Family page: quasar
- Open-source project: https://github.com/quasar/Quasar (MaxXor)
- Artifact ID:
2d95ff19-1f5e-4f69-bbdb-96dbc8a164d3 - Source: OpenCTI → MalwareBazaar (
quasarratlabel +testlabel)
Provenance
- This report synthesized from static analysis outputs in
raw/analyses/0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216/:file.txt,pefile.txt,exiftool.json,rabin2-info.txt— build metadata and version infostrings.txt— unobfuscated .NET namespace and message-type enumerationcapa.txt— capability detection and ATT&CK mapping (static scope)binwalk.txt— embedded crypto constants from BouncyCastlefloss.txt— command-line invocation failure; no decoded strings neededmetadata.json— artifact metadata and OpenCTI labelstriage.json— triage routing record
- No
dynamic-analysis.mdorcape-report.json— CAPE skipped (no Windows guest). - Tools: file v5.44, pefile 2023.2.7, ExifTool 12.76, radare2 5.9.2, capa v8.0.1, flare-floss (failed invocation), binwalk 2.3.2, yara 4.5.0