typeanalysisfamilyquasarconfidencehighcreated2026-08-18updated2026-08-18dotnetratmalware-familyc2persistencecollectiondefense-evasiondiscoveryexecutionmitre-attck
SHA-256: 7cc18c8995f128cd34217627dd67041d6ba798bcaf277a38c9eec3ae8b5389c5

quasar: 7cc18c89 — Quasar RAT v1.4.1.0 with blanked VS_VERSIONINFO masquerade

Executive Summary — Confirmed ninth sibling of the quasar v1.4.1.0 cluster (build timestamp 2023-03-12 16:16:39 UTC). Identical unobfuscated .NET Framework PE32 footprint to 0347df42, but with a stripped VS_VERSIONINFO block: all descriptive fields (CompanyName, FileDescription, LegalCopyright, ProductName) are empty, and only InternalName / OriginalFilename retain the string meridablancainc. No packing, no obfuscation, no CAPE detonation. Static-only.

What It Is

  • File: meridablancainc.it.com, 3.3 MB (3,266,048 bytes) ^[file.txt]
  • Format: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, 3 sections ^[file.txt]
  • Compiler / toolchain: .NET Framework CIL, linker v8.0, compiled Sun Mar 12 16:16:39 2023 UTC ^[pefile.txt:34] ^[rabin2-info.txt:11]
  • Assembly version: 1.4.1.0 (same as 0347df42 cluster) ^[strings.txt:97]
  • Version info (masquerade): FileDescription , CompanyName , LegalCopyright , LegalTrademarks , OriginalFilename meridablancainc, ProductName ``, AssemblyVersion 0.1.0.1 ^[exiftool.json:37-46] ^[pefile.txt:233-243]
  • Signed: No ^[rabin2-info.txt:27]
  • Packed / obfuscated: None. No ConfuserEx, SmartAssembly, Xenocode, or dotfuscator. .text entropy 6.08 — typical unobfuscated CIL. ^[pefile.txt:92]
  • Dynamic analysis: Skipped — no CAPE Windows guest available. ^[dynamic-analysis.md]

Family attribution is high-confidence: the binary carries the literal namespace Quasar.Common, Version=1.4.1.0 ^[strings.txt:100] and the identical embedded library quartet (BouncyCastle.Crypto v1.9.0.0, protobuf-net v2.4.0.0, Gma.System.MouseKeyHook v5.6.130.0, Client v1.4.1.0) ^[strings.txt:96-100] that fingerprint the Quasar cluster. The build timestamp matches the 0347df42 sibling to the second. Capa fingerprint is identical (86 capabilities, zero deviation from primary sibling). ^[capa.txt]

How It Works

This sample is a cluster sibling of 0347df42. For the full module inventory — keylogging, credential harvesting, remote shell, file manager, desktop/webcam capture, reverse proxy, system discovery, registry manipulation, persistence, and self-uninstall — see the primary deep-dive at raw/analyses/0347df428374.../report.md and the family page quasar.

Per-sample delta (this sibling):

The only meaningful deviation from the stock Quasar build is the blanked version-info masquerade. Instead of the default Quasar Client / Copyright © MaxXor / Client.exe branding (or the Vietnamese gambling-site re-brand seen in 0464caa1), the actor stripped almost every field in the VS_VERSIONINFO block:

Field Stock Quasar (0347df42) This Sample (7cc18c89)
FileDescription Quasar Client (empty)
CompanyName (empty / MaxXor) (empty)
LegalCopyright Copyright © MaxXor 2023 (empty)
LegalTrademarks Copyright © MaxXor 2023 (empty)
OriginalFilename Client.exe meridablancainc
ProductName Quasar (empty)
AssemblyVersion 1.4.1.0 0.1.0.1

The AssemblyVersion bump to 0.1.0.1 and the replacement of Client.exe with meridablancainc are the only edits in the resource block; the actual .NET assembly metadata still reports Client, Version=1.4.1.0 ^[strings.txt:97], confirming the underlying binary is unmodified stock code.

The filename meridablancainc.it.com uses a compound masquerade: meridablancainc mimics a legitimate company name (Blanca is a common surname; Merida Blanca is a plausible business entity), while the .it.com TLD is a subdomain of it.com (a domain registrar) — not a true country-code TLD, but visually close enough to .it (Italy) to confuse casual inspection. This is a social-engineering-filename-lure paired with version-info-masquerade.

No new capa capabilities were detected beyond the standard Quasar bundle. ^[capa.txt]

Decompiled Behavior

Not applicable — pure .NET CIL. See 0347df42 deep-dive. ILSpy/dnSpy would be the correct tool; the assembly is unobfuscated and all behaviour is recoverable from strings and capa.

C2 Infrastructure

Not recoverable statically. Quasar builder injects C2 host/port at build time; no plaintext C2 strings in the binary. No IP addresses, domains, or URL patterns found. See 0347df42 report for identical assessment.

Interesting Tidbits

  • Blanked version-info masquerade: Unlike 0464caa1 (active gambling-site re-brand), this actor simply wiped the version-info fields rather than substituting new ones. The result is a PE that looks orphaned — no company, no product, no copyright — which is itself suspicious in a mature EDR context. ^[exiftool.json:37-44]
  • .it.com TLD trick: The filename extension meridablancainc.it.com is not it.com as a true TLD but rather a subdomain of the it.com registrar. Victims may mistake it for an Italian business domain. ^[metadata.json]
  • AssemblyVersion mismatch: VS_VERSIONINFO says 0.1.0.1, but the .NET manifest still says 1.4.1.0. Same lazy-edit pattern as 0464caa1. ^[strings.txt:97] ^[exiftool.json:46]
  • Identical capa fingerprint: Every capability hit in this sample matches the 0347df42 sibling line-for-line (86 capabilities, same match counts). Confirms zero code change. ^[capa.txt]
  • No evasion: No anti-VM, anti-debug, sandbox gates, or sleep loops. Stock open-source build. ^[capa.txt]
  • FLOSS failure: Same command-line invocation error as other Quasar siblings (--no flag collision). Unobfuscated anyway. ^[floss.txt]

How To Mess With It (Homelab Replication)

See 0347df42 report for full replication steps — clone the Quasar repo, build the Client project, and compare capa fingerprints. The only additional step for this variant is:

  1. After building Client.exe, use a resource editor (e.g., Resource Hacker, CFF Explorer) to edit the VS_VERSIONINFO block.
  2. Delete the contents of FileDescription, CompanyName, LegalCopyright, LegalTrademarks, and ProductName.
  3. Replace OriginalFilename → meridablancainc.
  4. Bump the numeric version fields to 0.1.0.1.
  5. Re-save the PE.
  6. Rename the file to meridablancainc.it.com.
  7. Run capa on the modified binary — the capability table will be identical to the original, proving that version-info masquerade does not alter runtime behaviour.

Deployable Signatures

YARA rule — Quasar cluster with blanked version-info variant

rule quasar_v1410_blanked_masquerade : rat dotnet {
    meta:
        description = "Quasar RAT v1.4.1.0 cluster with blanked VS_VERSIONINFO masquerade"
        author      = "PacketPursuit"
        date        = "2026-08-18"
        sha256      = "7cc18c8995f128cd34217627dd67041d6ba798bcaf277a38c9eec3ae8b5389c5"
        family      = "quasar"
        confidence  = "high"
    strings:
        $asm1 = "Client, Version=1.4.1.0, Culture=neutral, PublicKeyToken=null" ascii wide
        $asm2 = "Quasar.Common, Version=1.4.1.0, Culture=neutral, PublicKeyToken=null" ascii wide
        $lib1 = "BouncyCastle.Crypto, Version=1.9.0.0" ascii wide
        $lib2 = "protobuf-net, Version=2.4.0.0" ascii wide
        $lib3 = "Gma.System.MouseKeyHook, Version=5.6.130.0" ascii wide
        $ns1   = "Quasar.Client.Recovery.Browsers" ascii wide
        $ns2   = "Quasar.Common.Messages" ascii wide
        $ns3   = "Quasar.Common.Enums" ascii wide
        $hook1 = "Gma.System.MouseKeyHook.WinApi" ascii wide
        $hook2 = "Gma.System.MouseKeyHook.Implementation" ascii wide
        // Blank version-info indicator: empty fields adjacent to "meridablancainc"
        $orig  = "OriginalFilename: meridablancainc" ascii wide
    condition:
        uint16(0) == 0x5A4D and
        ( $asm1 or $asm2 ) and
        ( $lib1 or $lib2 or $lib3 ) and
        ( $ns1 or $ns2 or $ns3 ) and
        ( $hook1 or $hook2 ) and
        $orig
}

Sigma rule — Quasar client process creation with blank metadata

title: Quasar RAT Client Execution - Blank Version Info Masquerade
status: experimental
description: Detects execution of Quasar RAT client with blanked VS_VERSIONINFO fields and meridablancainc filename pattern.
logsource:
    category: process_creation
    product: windows
detection:
    selection:
        Image|endswith:
            - 'meridablancainc.it.com'
            - 'meridablancainc.exe'
        CommandLine|contains:
            - 'meridablancainc'
    quasar_indicators:
        - CommandLine|contains:
            - 'Client.exe'
        - ParentImage|endswith:
            - 'explorer.exe'
            - 'cmd.exe'
    filter_known_good:
        - Image|startswith:
            - 'C:\\Program Files\\'
            - 'C:\\Program Files (x86)\\'
    condition: selection and quasar_indicators and not filter_known_good
falsepositives:
    - None expected; "meridablancainc" is not a legitimate software product.
level: high

IOC list

Indicator Type Note
7cc18c8995f128cd34217627dd67041d6ba798bcaf277a38c9eec3ae8b5389c5 SHA-256 This sample
meridablancainc.it.com Filename Blank-version-info masquerade variant
meridablancainc VS_VERSIONINFO OriginalFilename / InternalName Stripped branding
Client, Version=1.4.1.0 .NET Assembly Name Stock Quasar client assembly
Quasar.Common, Version=1.4.1.0 .NET Assembly Name Common library assembly
BouncyCastle.Crypto, Version=1.9.0.0 Embedded Library TLS + certificate handling
protobuf-net, Version=2.4.0.0 Embedded Library TCP message framing
Gma.System.MouseKeyHook, Version=5.6.130.0 Embedded Library Global keyboard hooks
Quasar.Client.Recovery.Browsers Namespace Credential harvesting module
Quasar.Common.Messages Namespace C2 message types
Quasar.Common.Enums Namespace Enumeration definitions

Behavioral fingerprint statement

This binary is a near-stock build of the open-source Quasar RAT client (v1.4.1.0, March 2023). It loads the .NET CLR via mscoree.dll!_CorExeMain, then initialises a protobuf-net TCP channel, BouncyCastle TLS stack, and global keyboard hooks via Gma.System.MouseKeyHook. The VS_VERSIONINFO block has been deliberately blanked — all descriptive fields are empty except OriginalFilename and InternalName, which read meridablancainc. No anti-analysis measures are present. The binary enumerates processes, queries the registry, manipulates startup items, and communicates over TCP — all standard Quasar modules. Detection should focus on the assembly-metadata quartet (Client + Quasar.Common + BouncyCastle.Crypto + protobuf-net + Gma.System.MouseKeyHook) rather than version-info strings, which are easily altered.

Detection Signatures

ATT&CK Tactic Technique Evidence
COLLECTION T1213 Data from Information Repositories reference SQL statements ^[capa.txt]
COLLECTION T1056.001 Input Capture::Keylogging log keystrokes via polling (2 matches) ^[capa.txt]
CREDENTIAL ACCESS T1555.003 Credentials from Web Browsers gather chrome based browser login information ^[capa.txt]
DEFENSE EVASION T1140 Deobfuscate/Decode Files or Information Base64 encode/decode, DPAPI ^[capa.txt]
DEFENSE EVASION T1027 Obfuscated Files or Information Blank version-info masquerade (static observation)
DEFENSE EVASION T1553.005 Mark-of-the-Web Bypass bypass Mark of the Web ^[capa.txt]
DEFENSE EVASION T1620 Reflective Code Loading invoke .NET assembly method (13 matches), generate method via reflection (38 matches) ^[capa.txt]
DISCOVERY T1087 Account Discovery enumerate processes, get session user name ^[capa.txt]
DISCOVERY T1010 Application Window Discovery get graphical window text, enumerate gui resources ^[capa.txt]
DISCOVERY T1083 File and Directory Discovery enumerate files, enumerate drives ^[capa.txt]
DISCOVERY T1057 Process Discovery enumerate processes, find process by name ^[capa.txt]
DISCOVERY T1012 Query Registry query or enumerate registry key (12 matches) ^[capa.txt]
DISCOVERY T1518 Software Discovery get OS version, query environment variable ^[capa.txt]
DISCOVERY T1082 System Information Discovery get OS version, get hostname, get MAC address ^[capa.txt]
DISCOVERY T1614 System Location Discovery get geographical location (3 matches) ^[capa.txt]
DISCOVERY T1016 System Network Configuration Discovery list TCP connections, get networking interfaces ^[capa.txt]
DISCOVERY T1033 System Owner/User Discovery get session user name ^[capa.txt]
EXECUTION T1129 Shared Modules invoke .NET assembly method ^[capa.txt]
EXECUTION T1047 Windows Management Instrumentation access WMI data in .NET (9 matches) ^[capa.txt]
PERSISTENCE T1053.005 Scheduled Task/Job schedule task via schtasks (2 matches) ^[capa.txt]

References

  • Primary deep-dive sibling: /intel/analyses/0347df42837474af34bf984b151e6d34bc46c02082ce01a36296d384a1244e52.html
  • Gambling-site masquerade sibling: /intel/analyses/0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216.html
  • Family entity page: quasar
  • Version-info masquerade technique: version-info-masquerade
  • Filename lure concept: social-engineering-filename-lure
  • Quasar GitHub repository: https://github.com/quasar/Quasar
  • Artifact ID: 43f82170-d960-4ce1-be0d-c8adf09544c7

Provenance

Analysis generated from static artefacts collected by the triage pipeline on 2026-05-29 and reviewed on 2026-08-18. No dynamic execution (CAPE skipped — no Windows guest). Tools: file (file type), exiftool (metadata), pefile (PE header), radare2 (rabin2 -I header summary), capa v7 (capability detection), strings (ASCII/Unicode string extraction). FLOSS invocation failed due to CLI flag collision; unobfuscated sample rendered this non-blocking. Provenance markers in ^[] format throughout.