typeanalysisfamilyquasarconfidencehighcreated2026-09-08updated2026-09-08dotnetratmalware-familyc2persistencecollectiondefense-evasiondiscoveryexecutionmitre-attckevasion
SHA-256: 62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a

quasar: 62f608d6 — Stock v1.4.1.0 build with fabricated "MICROSOFT PUBLISHING / NamCO" version-info masquerade

Executive Summary — A stock build of the open-source Quasar RAT (v1.4.1.0, compiled March 2023) identical in code to sibling 0347df42, but with a fabricated VS_VERSIONINFO resource masquerading as a Microsoft/NamCO product (Latest_unreleased-v1.3.45). The on-disk filename (Xeno-v1.3.50.exe) borrows from the XenoRAT branding trend. No packing, no obfuscation, no anti-analysis. Static-only (CAPE skipped — no Windows guest).

What It Is

  • File: Xeno-v1.3.50.exe, 3.5 MB (3,544,576 bytes) ^[file.txt]
  • Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Assembly version: Client, Version=1.4.1.0 ^[strings.txt:98]
  • Version info (masquerade): CompanyName MICROSOFT PUBLISHING, FileDescription Executable File, LegalCopyright NamCO, ProductName Latest_unreleased-v1.3.45, FileVersion 1.3.4.0 ^[exiftool.json:37-44]
  • Version info (honest branding absent): No Quasar Client, MaxXor, or Client.exe strings in the version block. OriginalFilename and InternalName are blank. ^[exiftool.json:40-43]
  • Signed: No ^[rabin2-info.txt:27]
  • Packed / obfuscated: None. ^[pefile.txt:92] Entropy 6.08 (typical unobfuscated CIL).
  • Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]

Family attribution is high-confidence: the unobfuscated CIL metadata contains literal namespace strings Quasar.Client, Quasar.Common, Quasar.Common.Messages, Quasar.Common.Enums, and Quasar.Client.Recovery.Browsers. ^[strings.txt:101] ^[strings.txt:11343] ^[strings.txt:11365] ^[strings.txt:12126] ^[strings.txt:12406] The embedded assembly Quasar.Common, Version=1.4.1.0 confirms the build. ^[strings.txt:101]

How It Works

This sample is a cluster sibling of the primary deep-dive at 0347df42. For a full module-by-module breakdown of Quasar v1.4.1.0 behavior — keylogging, credential harvesting, remote shell, file manager, reverse proxy, registry persistence, and protobuf-net/BouncyCastle cryptography — see that report. ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]

The delta for this sample is purely in the operator's opsec layer:

Attribute 0347df42 (honest) 62f608d6 (masquerade)
On-disk filename nungcac.exe Xeno-v1.3.50.exe
CompanyName MaxXor MICROSOFT PUBLISHING
FileDescription Quasar Client Executable File
ProductName Quasar Latest_unreleased-v1.3.45
LegalCopyright Copyright © MaxXor 2023 NamCO
OriginalFilename Client.exe (blank)
InternalName (blank) (blank)

The binary itself — namespaces, libraries, message types, and capa fingerprint — is unchanged. This is a builder-configured rebrand, not a forked or modified codebase.

The masquerade strings are typical of commodity threat-actor tooling: plausible-sounding but slightly off (NamCO instead of Namco Bandai; MICROSOFT PUBLISHING instead of Microsoft Corporation; Latest_unreleased as a product name). The blank OriginalFilename and InternalName fields are common when operators use a resource editor to overwrite only the visible fields without understanding the full VS_VERSIONINFO structure.

Decompiled Behavior

Not applicable — pure .NET CIL. Ghidra does not produce meaningful pseudo-C from CIL. Because the assembly is completely unobfuscated, all behavior is recoverable directly from static strings, capa, and pefile metadata. See the 0347df42 deep-dive for the unobfuscated behavior catalogue. ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]

C2 Infrastructure

Not recoverable statically. Quasar builder injects C2 host/port/password at build time; no hardcoded C2 credentials are visible in the string table. The Xeno-v1.3.50.exe filename suggests the operator may be borrowing XenoRAT branding for social engineering, but the binary is Quasar, not XenoRAT.

Interesting Tidbits

  • Builder timestamp twin: Compiled at the exact same second as 0347df42 (Sun Mar 12 16:16:39 2023 UTC). These two samples were likely produced in the same builder session. ^[pefile.txt:34]
  • FLOSS failure: flare-floss invocation failed with an argument-parsing error (--no flag collision with the sample path). ^[floss.txt] Unnecessary — the assembly is unobfuscated.
  • No anti-anything: No anti-VM, anti-debug, sandbox detection, sleep gates, or WMI checks. Stock open-source build dropped straight onto a victim.
  • Resource bloat unchanged: 3.5 MB is still dominated by embedded BouncyCastle.Crypto + protobuf-net; the version-info change adds ~0 bytes to size.
  • "NamCO" copyright: A typo-level masquerade string. Namco (now Bandai Namco) is a Japanese game publisher; this string may be an attempt to sound like a legitimate software vendor while being generic enough to evade a Google search.

How To Mess With It (Homelab Replication)

See the 0347df42 deep-dive for the full Quasar build-and-compare recipe. ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]

To replicate this specific masquerade:

  1. Build Quasar Client v1.4.1.0 in Release mode.
  2. Open the output Client.exe in Resource Hacker or CFF Explorer.
  3. Navigate to the VS_VERSIONINFO block under Version Info.
  4. Edit the string fields:
    • CompanyName → MICROSOFT PUBLISHING
    • FileDescription → Executable File
    • LegalCopyright → NamCO
    • ProductName → Latest_unreleased-v1.3.45
    • Clear OriginalFilename and InternalName.
  5. Save the modified executable.
  6. Verification: Run capa modified.exe. The capability table should be identical to this sample's capa.txt (~60+ host-interaction hits, same ATT&CK coverage), confirming the code is unchanged.
  7. Learning outcome: You will see how trivial it is to alter version-info without touching the malware logic — a common opsec step in commodity campaigns.

Deployable Signatures

YARA rule

rule quasar_rat_masquerade_namco
{
    meta:
        description = "Quasar RAT client with NamCO / MICROSOFT PUBLISHING version-info masquerade"
        author = "Titus"
        date = "2026-09-08"
        sha256 = "62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a"
    strings:
        $quasar_client = "Quasar.Client" ascii wide
        $quasar_common = "Quasar.Common" ascii wide
        $quasar_messages = "Quasar.Common.Messages" ascii wide
        $quasar_enums = "Quasar.Common.Enums" ascii wide
        $version_masq1 = "MICROSOFT PUBLISHING" wide
        $version_masq2 = "NamCO" wide
        $version_masq3 = "Latest_unreleased" wide
        $pb_net = "protobuf-net, Version=" ascii wide
        $bc_crypto = "BouncyCastle.Crypto, Version=" ascii wide
        $mousehook = "Gma.System.MouseKeyHook, Version=" ascii wide
        $msg_doshell = "DoShellExecute" ascii wide
        $msg_startupadd = "DoStartupItemAdd" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        filesize < 5MB and
        3 of ($quasar_*) and
        2 of ($version_masq*) and
        2 of ($pb_net, $bc_crypto, $mousehook) and
        1 of ($msg_*)
}

Sigma rule

title: Quasar RAT Masquerade Execution - NamCO / MICROSOFT PUBLISHING
logsource:
    category: process_creation
    product: windows
detection:
    selection_pe:
        - Company: 'MICROSOFT PUBLISHING'
        - Product: 'Latest_unreleased-v1.3.45'
        - Description: 'Executable File'
        - LegalCopyright: 'NamCO'
    selection_img:
        Image|contains:
            - 'Xeno'
            - 'xeno'
    selection_dll_load:
        ImageLoaded|contains:
            - 'Gma.System.MouseKeyHook'
            - 'protobuf-net'
            - 'BouncyCastle.Crypto'
    selection_network:
        Initiated: true
        UserAgent|contains: 'Quasar'
    condition: 1 of selection_*
falsepositives:
    - None known for the masquerade strings; "MICROSOFT PUBLISHING" and "NamCO" together are unique to this campaign.
level: high

IOC list

Type Value Notes
SHA256 62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a This sample
File name Xeno-v1.3.50.exe Observed on disk
Assembly version Client, Version=1.4.1.0 .NET metadata
Library protobuf-net, Version=2.4.0.0 Embedded serialization lib
Library BouncyCastle.Crypto, Version=1.9.0.0 Embedded crypto lib
Library Gma.System.MouseKeyHook, Version=5.6.130.0 Global hook lib
Library Quasar.Common, Version=1.4.1.0 Core RAT assembly
Registry keys HKLM\Software\Microsoft\Windows\CurrentVersion\Run Startup persistence (generic)
Registry keys HKCU\Software\Microsoft\Windows\CurrentVersion\Run Startup persistence (generic)
Version info CompanyName MICROSOFT PUBLISHING Masquerade indicator
Version info LegalCopyright NamCO Masquerade indicator
Version info ProductName Latest_unreleased-v1.3.45 Masquerade indicator

Behavioral fingerprint

This binary is an unobfuscated .NET Framework PE32 executable whose CIL metadata identifies it as Quasar v1.4.1.0 (open-source RAT by MaxXor). The VS_VERSIONINFO resource block has been overwritten with fabricated fields (MICROSOFT PUBLISHING, NamCO, Latest_unreleased-v1.3.45) while the underlying code remains untouched. On execution it will load Gma.System.MouseKeyHook for global keyboard capture, initialise a protobuf-net TCP transport layer, and open outbound TCP connections to an operator-configured C2 server. It enumerates the local system, logs keystrokes, captures screenshots and webcam frames, supports remote shell execution and file-manager operations, and establishes persistence via registry Run keys or scheduled tasks. No sandbox evasion, no anti-debug, and no packing is present.

Detection Signatures

capa → MITRE ATT&CK mapping (static-only, no runtime confirmation from CAPE):

capa capability ATT&CK Technique
gather chrome based browser login information T1555.003
log keystrokes via polling T1056.001
reference WMI statements / access WMI data T1047
schedule task via schtasks T1053.005
encode/decode data using Base64 T1140 / T1027
encrypt data using DPAPI T1553.005 (Mark-of-the-Web bypass context)
create TCP socket / send data / receive data — (generic communication)
query or enumerate registry key/value T1012
create process in .NET T1129
set registry value T1112
enumerate processes T1057
get OS version / get hostname / get MAC address T1082
get geographical location T1614
bypass Mark of the Web T1553.005

References

  • Open-source project: https://github.com/quasar/Quasar (MaxXor)
  • Primary deep-dive sibling: 0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52 ^[/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html]
  • Artifact ID: b888539e-879f-4478-949d-4a97c942793d
  • Source: OpenCTI → MalwareBazaar
  • Family page: quasar
  • Technique page: version-info-masquerade

Provenance

  • This report synthesized from static analysis outputs in raw/analyses/62f608d61b28702ca4adadd574f3761c79860bd08da402e3129ab19176f7da9a/:
    • file.txt, pefile.txt, exiftool.json, rabin2-info.txt — build metadata and version info
    • strings.txt — unobfuscated .NET namespace and message-type enumeration
    • capa.txt — capability detection and ATT&CK mapping (static scope)
    • binwalk.txt — embedded crypto constants from BouncyCastle
    • floss.txt — command-line invocation failure; no decoded strings needed
    • dynamic-analysis.md — CAPE skipped (no Windows guest)
  • Tools: file v5.44, pefile 2023.2.7, ExifTool 12.76, radare2 5.9.2, capa v8.0.1, flare-floss (failed invocation), binwalk 2.3.2