62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9aquasar: 62f608d6 — Stock v1.4.1.0 build with fabricated "MICROSOFT PUBLISHING / NamCO" version-info masquerade
Executive Summary — A stock build of the open-source Quasar RAT (v1.4.1.0, compiled March 2023) identical in code to sibling 0347df42, but with a fabricated VS_VERSIONINFO resource masquerading as a Microsoft/NamCO product (Latest_unreleased-v1.3.45). The on-disk filename (Xeno-v1.3.50.exe) borrows from the XenoRAT branding trend. No packing, no obfuscation, no anti-analysis. Static-only (CAPE skipped — no Windows guest).
What It Is
- File:
Xeno-v1.3.50.exe, 3.5 MB (3,544,576 bytes) ^[file.txt] - Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
- Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Assembly version:
Client, Version=1.4.1.0^[strings.txt:98] - Version info (masquerade): CompanyName
MICROSOFT PUBLISHING, FileDescriptionExecutable File, LegalCopyrightNamCO, ProductNameLatest_unreleased-v1.3.45, FileVersion1.3.4.0^[exiftool.json:37-44] - Version info (honest branding absent): No
Quasar Client,MaxXor, orClient.exestrings in the version block. OriginalFilename and InternalName are blank. ^[exiftool.json:40-43] - Signed: No ^[rabin2-info.txt:27]
- Packed / obfuscated: None. ^[pefile.txt:92] Entropy 6.08 (typical unobfuscated CIL).
- Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]
Family attribution is high-confidence: the unobfuscated CIL metadata contains literal namespace strings Quasar.Client, Quasar.Common, Quasar.Common.Messages, Quasar.Common.Enums, and Quasar.Client.Recovery.Browsers. ^[strings.txt:101] ^[strings.txt:11343] ^[strings.txt:11365] ^[strings.txt:12126] ^[strings.txt:12406] The embedded assembly Quasar.Common, Version=1.4.1.0 confirms the build. ^[strings.txt:101]
How It Works
This sample is a cluster sibling of the primary deep-dive at 0347df42. For a full module-by-module breakdown of Quasar v1.4.1.0 behavior — keylogging, credential harvesting, remote shell, file manager, reverse proxy, registry persistence, and protobuf-net/BouncyCastle cryptography — see that report. ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]
The delta for this sample is purely in the operator's opsec layer:
| Attribute | 0347df42 (honest) |
62f608d6 (masquerade) |
|---|---|---|
| On-disk filename | nungcac.exe |
Xeno-v1.3.50.exe |
| CompanyName | MaxXor |
MICROSOFT PUBLISHING |
| FileDescription | Quasar Client |
Executable File |
| ProductName | Quasar |
Latest_unreleased-v1.3.45 |
| LegalCopyright | Copyright © MaxXor 2023 |
NamCO |
| OriginalFilename | Client.exe |
(blank) |
| InternalName | (blank) | (blank) |
The binary itself — namespaces, libraries, message types, and capa fingerprint — is unchanged. This is a builder-configured rebrand, not a forked or modified codebase.
The masquerade strings are typical of commodity threat-actor tooling: plausible-sounding but slightly off (NamCO instead of Namco Bandai; MICROSOFT PUBLISHING instead of Microsoft Corporation; Latest_unreleased as a product name). The blank OriginalFilename and InternalName fields are common when operators use a resource editor to overwrite only the visible fields without understanding the full VS_VERSIONINFO structure.
Decompiled Behavior
Not applicable — pure .NET CIL. Ghidra does not produce meaningful pseudo-C from CIL. Because the assembly is completely unobfuscated, all behavior is recoverable directly from static strings, capa, and pefile metadata. See the 0347df42 deep-dive for the unobfuscated behavior catalogue. ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]
C2 Infrastructure
Not recoverable statically. Quasar builder injects C2 host/port/password at build time; no hardcoded C2 credentials are visible in the string table. The Xeno-v1.3.50.exe filename suggests the operator may be borrowing XenoRAT branding for social engineering, but the binary is Quasar, not XenoRAT.
Interesting Tidbits
- Builder timestamp twin: Compiled at the exact same second as
0347df42(Sun Mar 12 16:16:39 2023 UTC). These two samples were likely produced in the same builder session. ^[pefile.txt:34] - FLOSS failure: flare-floss invocation failed with an argument-parsing error (
--noflag collision with the sample path). ^[floss.txt] Unnecessary — the assembly is unobfuscated. - No anti-anything: No anti-VM, anti-debug, sandbox detection, sleep gates, or WMI checks. Stock open-source build dropped straight onto a victim.
- Resource bloat unchanged: 3.5 MB is still dominated by embedded BouncyCastle.Crypto + protobuf-net; the version-info change adds ~0 bytes to size.
- "NamCO" copyright: A typo-level masquerade string. Namco (now Bandai Namco) is a Japanese game publisher; this string may be an attempt to sound like a legitimate software vendor while being generic enough to evade a Google search.
How To Mess With It (Homelab Replication)
See the 0347df42 deep-dive for the full Quasar build-and-compare recipe. ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]
To replicate this specific masquerade:
- Build Quasar Client v1.4.1.0 in Release mode.
- Open the output
Client.exein Resource Hacker or CFF Explorer. - Navigate to the VS_VERSIONINFO block under
Version Info. - Edit the string fields:
- CompanyName →
MICROSOFT PUBLISHING - FileDescription →
Executable File - LegalCopyright →
NamCO - ProductName →
Latest_unreleased-v1.3.45 - Clear OriginalFilename and InternalName.
- CompanyName →
- Save the modified executable.
- Verification: Run
capa modified.exe. The capability table should be identical to this sample'scapa.txt(~60+ host-interaction hits, same ATT&CK coverage), confirming the code is unchanged. - Learning outcome: You will see how trivial it is to alter version-info without touching the malware logic — a common opsec step in commodity campaigns.
Deployable Signatures
YARA rule
rule quasar_rat_masquerade_namco
{
meta:
description = "Quasar RAT client with NamCO / MICROSOFT PUBLISHING version-info masquerade"
author = "Titus"
date = "2026-09-08"
sha256 = "62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a"
strings:
$quasar_client = "Quasar.Client" ascii wide
$quasar_common = "Quasar.Common" ascii wide
$quasar_messages = "Quasar.Common.Messages" ascii wide
$quasar_enums = "Quasar.Common.Enums" ascii wide
$version_masq1 = "MICROSOFT PUBLISHING" wide
$version_masq2 = "NamCO" wide
$version_masq3 = "Latest_unreleased" wide
$pb_net = "protobuf-net, Version=" ascii wide
$bc_crypto = "BouncyCastle.Crypto, Version=" ascii wide
$mousehook = "Gma.System.MouseKeyHook, Version=" ascii wide
$msg_doshell = "DoShellExecute" ascii wide
$msg_startupadd = "DoStartupItemAdd" ascii wide
condition:
uint16(0) == 0x5A4D and
filesize < 5MB and
3 of ($quasar_*) and
2 of ($version_masq*) and
2 of ($pb_net, $bc_crypto, $mousehook) and
1 of ($msg_*)
}
Sigma rule
title: Quasar RAT Masquerade Execution - NamCO / MICROSOFT PUBLISHING
logsource:
category: process_creation
product: windows
detection:
selection_pe:
- Company: 'MICROSOFT PUBLISHING'
- Product: 'Latest_unreleased-v1.3.45'
- Description: 'Executable File'
- LegalCopyright: 'NamCO'
selection_img:
Image|contains:
- 'Xeno'
- 'xeno'
selection_dll_load:
ImageLoaded|contains:
- 'Gma.System.MouseKeyHook'
- 'protobuf-net'
- 'BouncyCastle.Crypto'
selection_network:
Initiated: true
UserAgent|contains: 'Quasar'
condition: 1 of selection_*
falsepositives:
- None known for the masquerade strings; "MICROSOFT PUBLISHING" and "NamCO" together are unique to this campaign.
level: high
IOC list
| Type | Value | Notes |
|---|---|---|
| SHA256 | 62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a |
This sample |
| File name | Xeno-v1.3.50.exe |
Observed on disk |
| Assembly version | Client, Version=1.4.1.0 |
.NET metadata |
| Library | protobuf-net, Version=2.4.0.0 |
Embedded serialization lib |
| Library | BouncyCastle.Crypto, Version=1.9.0.0 |
Embedded crypto lib |
| Library | Gma.System.MouseKeyHook, Version=5.6.130.0 |
Global hook lib |
| Library | Quasar.Common, Version=1.4.1.0 |
Core RAT assembly |
| Registry keys | HKLM\Software\Microsoft\Windows\CurrentVersion\Run |
Startup persistence (generic) |
| Registry keys | HKCU\Software\Microsoft\Windows\CurrentVersion\Run |
Startup persistence (generic) |
| Version info | CompanyName MICROSOFT PUBLISHING |
Masquerade indicator |
| Version info | LegalCopyright NamCO |
Masquerade indicator |
| Version info | ProductName Latest_unreleased-v1.3.45 |
Masquerade indicator |
Behavioral fingerprint
This binary is an unobfuscated .NET Framework PE32 executable whose CIL metadata identifies it as Quasar v1.4.1.0 (open-source RAT by MaxXor). The VS_VERSIONINFO resource block has been overwritten with fabricated fields (MICROSOFT PUBLISHING, NamCO, Latest_unreleased-v1.3.45) while the underlying code remains untouched. On execution it will load Gma.System.MouseKeyHook for global keyboard capture, initialise a protobuf-net TCP transport layer, and open outbound TCP connections to an operator-configured C2 server. It enumerates the local system, logs keystrokes, captures screenshots and webcam frames, supports remote shell execution and file-manager operations, and establishes persistence via registry Run keys or scheduled tasks. No sandbox evasion, no anti-debug, and no packing is present.
Detection Signatures
capa → MITRE ATT&CK mapping (static-only, no runtime confirmation from CAPE):
| capa capability | ATT&CK Technique |
|---|---|
| gather chrome based browser login information | T1555.003 |
| log keystrokes via polling | T1056.001 |
| reference WMI statements / access WMI data | T1047 |
| schedule task via schtasks | T1053.005 |
| encode/decode data using Base64 | T1140 / T1027 |
| encrypt data using DPAPI | T1553.005 (Mark-of-the-Web bypass context) |
| create TCP socket / send data / receive data | — (generic communication) |
| query or enumerate registry key/value | T1012 |
| create process in .NET | T1129 |
| set registry value | T1112 |
| enumerate processes | T1057 |
| get OS version / get hostname / get MAC address | T1082 |
| get geographical location | T1614 |
| bypass Mark of the Web | T1553.005 |
References
- Open-source project: https://github.com/quasar/Quasar (MaxXor)
- Primary deep-dive sibling:
0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html] - Artifact ID:
b888539e-879f-4478-949d-4a97c942793d - Source: OpenCTI → MalwareBazaar
- Family page: quasar
- Technique page: version-info-masquerade
Provenance
- This report synthesized from static analysis outputs in
raw/analyses/62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a/:file.txt,pefile.txt,exiftool.json,rabin2-info.txt— build metadata and version infostrings.txt— unobfuscated .NET namespace and message-type enumerationcapa.txt— capability detection and ATT&CK mapping (static scope)binwalk.txt— embedded crypto constants from BouncyCastlefloss.txt— command-line invocation failure; no decoded strings neededdynamic-analysis.md— CAPE skipped (no Windows guest)
- Tools: file v5.44, pefile 2023.2.7, ExifTool 12.76, radare2 5.9.2, capa v8.0.1, flare-floss (failed invocation), binwalk 2.3.2