7cc18c8995f128cd34217627dd67041d6ba798bcaf277a38c9eec3ae8b5389c5quasar: 7cc18c89 — Quasar RAT v1.4.1.0 with blanked VS_VERSIONINFO masquerade
Executive Summary — Confirmed ninth sibling of the quasar v1.4.1.0 cluster (build timestamp 2023-03-12 16:16:39 UTC). Identical unobfuscated .NET Framework PE32 footprint to 0347df42, but with a stripped VS_VERSIONINFO block: all descriptive fields (CompanyName, FileDescription, LegalCopyright, ProductName) are empty, and only InternalName / OriginalFilename retain the string meridablancainc. No packing, no obfuscation, no CAPE detonation. Static-only.
What It Is
- File:
meridablancainc.it.com, 3.3 MB (3,266,048 bytes) ^[file.txt] - Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
- Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
- Assembly version: 1.4.1.0 (same as
0347df42cluster) ^[strings.txt:97] - Version info (masquerade): FileDescription
, CompanyName, LegalCopyright, LegalTrademarks, OriginalFilenamemeridablancainc, ProductName ``, AssemblyVersion0.1.0.1^[exiftool.json:37-46] ^[pefile.txt:233-243] - Signed: No ^[rabin2-info.txt:27]
- Packed / obfuscated: None. No ConfuserEx, SmartAssembly, Xenocode, or dotfuscator.
.textentropy 6.08 — typical unobfuscated CIL. ^[pefile.txt:92] - Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]
Family attribution is high-confidence: the binary carries the literal namespace Quasar.Common, Version=1.4.1.0 ^[strings.txt:100] and the identical embedded library quartet (BouncyCastle.Crypto v1.9.0.0, protobuf-net v2.4.0.0, Gma.System.MouseKeyHook v5.6.130.0, Client v1.4.1.0) ^[strings.txt:96-100] that fingerprint the Quasar cluster. The build timestamp matches the 0347df42 sibling to the second. Capa fingerprint is identical (86 capabilities, zero deviation from primary sibling). ^[capa.txt]
How It Works
This sample is a cluster sibling of 0347df42. For the full module inventory — keylogging, credential harvesting, remote shell, file manager, desktop/webcam capture, reverse proxy, system discovery, registry manipulation, persistence, and self-uninstall — see the primary deep-dive at raw/analyses/0347df428374.../report.md and the family page quasar.
Per-sample delta (this sibling):
The only meaningful deviation from the stock Quasar build is the blanked version-info masquerade. Instead of the default Quasar Client / Copyright © MaxXor / Client.exe branding (or the Vietnamese gambling-site re-brand seen in 0464caa1), the actor stripped almost every field in the VS_VERSIONINFO block:
| Field | Stock Quasar (0347df42) |
This Sample (7cc18c89) |
|---|---|---|
| FileDescription | Quasar Client |
(empty) |
| CompanyName | (empty / MaxXor) | (empty) |
| LegalCopyright | Copyright © MaxXor 2023 |
(empty) |
| LegalTrademarks | Copyright © MaxXor 2023 |
(empty) |
| OriginalFilename | Client.exe |
meridablancainc |
| ProductName | Quasar |
(empty) |
| AssemblyVersion | 1.4.1.0 |
0.1.0.1 |
The AssemblyVersion bump to 0.1.0.1 and the replacement of Client.exe with meridablancainc are the only edits in the resource block; the actual .NET assembly metadata still reports Client, Version=1.4.1.0 ^[strings.txt:97], confirming the underlying binary is unmodified stock code.
The filename meridablancainc.it.com uses a compound masquerade: meridablancainc mimics a legitimate company name (Blanca is a common surname; Merida Blanca is a plausible business entity), while the .it.com TLD is a subdomain of it.com (a domain registrar) — not a true country-code TLD, but visually close enough to .it (Italy) to confuse casual inspection. This is a social-engineering-filename-lure paired with version-info-masquerade.
No new capa capabilities were detected beyond the standard Quasar bundle. ^[capa.txt]
Decompiled Behavior
Not applicable — pure .NET CIL. See 0347df42 deep-dive. ILSpy/dnSpy would be the correct tool; the assembly is unobfuscated and all behaviour is recoverable from strings and capa.
C2 Infrastructure
Not recoverable statically. Quasar builder injects C2 host/port at build time; no plaintext C2 strings in the binary. No IP addresses, domains, or URL patterns found. See 0347df42 report for identical assessment.
Interesting Tidbits
- Blanked version-info masquerade: Unlike
0464caa1(active gambling-site re-brand), this actor simply wiped the version-info fields rather than substituting new ones. The result is a PE that looks orphaned — no company, no product, no copyright — which is itself suspicious in a mature EDR context. ^[exiftool.json:37-44] .it.comTLD trick: The filename extensionmeridablancainc.it.comis notit.comas a true TLD but rather a subdomain of theit.comregistrar. Victims may mistake it for an Italian business domain. ^[metadata.json]- AssemblyVersion mismatch: VS_VERSIONINFO says
0.1.0.1, but the .NET manifest still says1.4.1.0. Same lazy-edit pattern as0464caa1. ^[strings.txt:97] ^[exiftool.json:46] - Identical capa fingerprint: Every capability hit in this sample matches the
0347df42sibling line-for-line (86 capabilities, same match counts). Confirms zero code change. ^[capa.txt] - No evasion: No anti-VM, anti-debug, sandbox gates, or sleep loops. Stock open-source build. ^[capa.txt]
- FLOSS failure: Same command-line invocation error as other Quasar siblings (
--noflag collision). Unobfuscated anyway. ^[floss.txt]
How To Mess With It (Homelab Replication)
See 0347df42 report for full replication steps — clone the Quasar repo, build the Client project, and compare capa fingerprints. The only additional step for this variant is:
- After building
Client.exe, use a resource editor (e.g., Resource Hacker, CFF Explorer) to edit the VS_VERSIONINFO block. - Delete the contents of FileDescription, CompanyName, LegalCopyright, LegalTrademarks, and ProductName.
- Replace
OriginalFilename→meridablancainc. - Bump the numeric version fields to
0.1.0.1. - Re-save the PE.
- Rename the file to
meridablancainc.it.com. - Run
capaon the modified binary — the capability table will be identical to the original, proving that version-info masquerade does not alter runtime behaviour.
Deployable Signatures
YARA rule — Quasar cluster with blanked version-info variant
rule quasar_v1410_blanked_masquerade : rat dotnet {
meta:
description = "Quasar RAT v1.4.1.0 cluster with blanked VS_VERSIONINFO masquerade"
author = "PacketPursuit"
date = "2026-08-18"
sha256 = "7cc18c8995f128cd34217627dd67041d6ba798bcaf277a38c9eec3ae8b5389c5"
family = "quasar"
confidence = "high"
strings:
$asm1 = "Client, Version=1.4.1.0, Culture=neutral, PublicKeyToken=null" ascii wide
$asm2 = "Quasar.Common, Version=1.4.1.0, Culture=neutral, PublicKeyToken=null" ascii wide
$lib1 = "BouncyCastle.Crypto, Version=1.9.0.0" ascii wide
$lib2 = "protobuf-net, Version=2.4.0.0" ascii wide
$lib3 = "Gma.System.MouseKeyHook, Version=5.6.130.0" ascii wide
$ns1 = "Quasar.Client.Recovery.Browsers" ascii wide
$ns2 = "Quasar.Common.Messages" ascii wide
$ns3 = "Quasar.Common.Enums" ascii wide
$hook1 = "Gma.System.MouseKeyHook.WinApi" ascii wide
$hook2 = "Gma.System.MouseKeyHook.Implementation" ascii wide
// Blank version-info indicator: empty fields adjacent to "meridablancainc"
$orig = "OriginalFilename: meridablancainc" ascii wide
condition:
uint16(0) == 0x5A4D and
( $asm1 or $asm2 ) and
( $lib1 or $lib2 or $lib3 ) and
( $ns1 or $ns2 or $ns3 ) and
( $hook1 or $hook2 ) and
$orig
}
Sigma rule — Quasar client process creation with blank metadata
title: Quasar RAT Client Execution - Blank Version Info Masquerade
status: experimental
description: Detects execution of Quasar RAT client with blanked VS_VERSIONINFO fields and meridablancainc filename pattern.
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith:
- 'meridablancainc.it.com'
- 'meridablancainc.exe'
CommandLine|contains:
- 'meridablancainc'
quasar_indicators:
- CommandLine|contains:
- 'Client.exe'
- ParentImage|endswith:
- 'explorer.exe'
- 'cmd.exe'
filter_known_good:
- Image|startswith:
- 'C:\\Program Files\\'
- 'C:\\Program Files (x86)\\'
condition: selection and quasar_indicators and not filter_known_good
falsepositives:
- None expected; "meridablancainc" is not a legitimate software product.
level: high
IOC list
| Indicator | Type | Note |
|---|---|---|
7cc18c8995f128cd34217627dd67041d6ba798bcaf277a38c9eec3ae8b5389c5 |
SHA-256 | This sample |
meridablancainc.it.com |
Filename | Blank-version-info masquerade variant |
meridablancainc |
VS_VERSIONINFO OriginalFilename / InternalName | Stripped branding |
Client, Version=1.4.1.0 |
.NET Assembly Name | Stock Quasar client assembly |
Quasar.Common, Version=1.4.1.0 |
.NET Assembly Name | Common library assembly |
BouncyCastle.Crypto, Version=1.9.0.0 |
Embedded Library | TLS + certificate handling |
protobuf-net, Version=2.4.0.0 |
Embedded Library | TCP message framing |
Gma.System.MouseKeyHook, Version=5.6.130.0 |
Embedded Library | Global keyboard hooks |
Quasar.Client.Recovery.Browsers |
Namespace | Credential harvesting module |
Quasar.Common.Messages |
Namespace | C2 message types |
Quasar.Common.Enums |
Namespace | Enumeration definitions |
Behavioral fingerprint statement
This binary is a near-stock build of the open-source Quasar RAT client (v1.4.1.0, March 2023). It loads the .NET CLR via mscoree.dll!_CorExeMain, then initialises a protobuf-net TCP channel, BouncyCastle TLS stack, and global keyboard hooks via Gma.System.MouseKeyHook. The VS_VERSIONINFO block has been deliberately blanked — all descriptive fields are empty except OriginalFilename and InternalName, which read meridablancainc. No anti-analysis measures are present. The binary enumerates processes, queries the registry, manipulates startup items, and communicates over TCP — all standard Quasar modules. Detection should focus on the assembly-metadata quartet (Client + Quasar.Common + BouncyCastle.Crypto + protobuf-net + Gma.System.MouseKeyHook) rather than version-info strings, which are easily altered.
Detection Signatures
| ATT&CK Tactic | Technique | Evidence |
|---|---|---|
| COLLECTION | T1213 Data from Information Repositories | reference SQL statements ^[capa.txt] |
| COLLECTION | T1056.001 Input Capture::Keylogging | log keystrokes via polling (2 matches) ^[capa.txt] |
| CREDENTIAL ACCESS | T1555.003 Credentials from Web Browsers | gather chrome based browser login information ^[capa.txt] |
| DEFENSE EVASION | T1140 Deobfuscate/Decode Files or Information | Base64 encode/decode, DPAPI ^[capa.txt] |
| DEFENSE EVASION | T1027 Obfuscated Files or Information | Blank version-info masquerade (static observation) |
| DEFENSE EVASION | T1553.005 Mark-of-the-Web Bypass | bypass Mark of the Web ^[capa.txt] |
| DEFENSE EVASION | T1620 Reflective Code Loading | invoke .NET assembly method (13 matches), generate method via reflection (38 matches) ^[capa.txt] |
| DISCOVERY | T1087 Account Discovery | enumerate processes, get session user name ^[capa.txt] |
| DISCOVERY | T1010 Application Window Discovery | get graphical window text, enumerate gui resources ^[capa.txt] |
| DISCOVERY | T1083 File and Directory Discovery | enumerate files, enumerate drives ^[capa.txt] |
| DISCOVERY | T1057 Process Discovery | enumerate processes, find process by name ^[capa.txt] |
| DISCOVERY | T1012 Query Registry | query or enumerate registry key (12 matches) ^[capa.txt] |
| DISCOVERY | T1518 Software Discovery | get OS version, query environment variable ^[capa.txt] |
| DISCOVERY | T1082 System Information Discovery | get OS version, get hostname, get MAC address ^[capa.txt] |
| DISCOVERY | T1614 System Location Discovery | get geographical location (3 matches) ^[capa.txt] |
| DISCOVERY | T1016 System Network Configuration Discovery | list TCP connections, get networking interfaces ^[capa.txt] |
| DISCOVERY | T1033 System Owner/User Discovery | get session user name ^[capa.txt] |
| EXECUTION | T1129 Shared Modules | invoke .NET assembly method ^[capa.txt] |
| EXECUTION | T1047 Windows Management Instrumentation | access WMI data in .NET (9 matches) ^[capa.txt] |
| PERSISTENCE | T1053.005 Scheduled Task/Job | schedule task via schtasks (2 matches) ^[capa.txt] |
References
- Primary deep-dive sibling:
/intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html - Gambling-site masquerade sibling:
/intel/analyses/0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216.html - Family entity page: quasar
- Version-info masquerade technique: version-info-masquerade
- Filename lure concept: social-engineering-filename-lure
- Quasar GitHub repository: https://github.com/quasar/Quasar
- Artifact ID:
43f82170-d960-4ce1-be0d-c8adf09544c7
Provenance
Analysis generated from static artefacts collected by the triage pipeline on 2026-05-29 and reviewed on 2026-08-18. No dynamic execution (CAPE skipped — no Windows guest). Tools: file (file type), exiftool (metadata), pefile (PE header), radare2 (rabin2 -I header summary), capa v7 (capability detection), strings (ASCII/Unicode string extraction). FLOSS invocation failed due to CLI flag collision; unobfuscated sample rendered this non-blocking. Provenance markers in ^[] format throughout.