61db1447817fd3b40db67ed261238e15f6338dc642a7a5a4bbf0c0ea5248594eBuild / RE
Toolchain
MinGW-w64 GCC 15.2.0 (x86_64-posix-seh-rev0), C++17 STL, Windows GUI subsystem. ^[exiftool.json:18] ^[strings.txt:1974] Linker version 2.45 (GNU ld, not MSVC). ^[exiftool.json:18] No packer or protector; entropy is flat (0.44–0.46) across all sections. ^[binwalk.txt] Binary size 1,012,944 bytes.
Code Quality
Modern C++: heavy use of std::basic_string, std::vector, std::fstream, range-checked append (vector::_M_realloc_append). ^[strings.txt:1475] Clean error-handling strings ("HTTP send/recv error %lu from %s", "CRASH DETECTED — previous instance did not exit cleanly"). Structured logging to %TEMP%\agent.log. ^[strings.txt:1391–1393]
Anti-Analysis
None observed statically. No IsDebuggerPresent, no NtGlobalFlag, no VM checks, no timing gates. The binary is not stripped — C++ STL and GCC runtime symbols are present. No section encryption or self-modifying code.
Notable Functions
| Address | Role | Evidence |
|---|---|---|
0x1400058e3 |
Application main | GetTempPathA, fopen/fread/fclose on %TEMP%\agent.log, prints "Agent starting v1.0.0", crash-recovery loop. ^[r2:fcn.1400058e3] ^[strings.txt:1391] |
0x140002af4 |
HTTP transport | Full WinHttp client: WinHttpCrackUrl, WinHttpOpen, WinHttpConnect, WinHttpOpenRequest, WinHttpSendRequest, WinHttpReceiveResponse, chunked download with 0x6400000 byte cap. ^[r2:fcn.140002af4] |
0x14000455a |
C2 beacon builder | Builds JSON payload {"agent_id":"...","hostname":"...","username":"...","os":"windows","ip":"...","pid":...,"elevated":false,"version":"...","crash_log":"..."}. ^[r2:fcn.14000455a] ^[strings.txt:1367–1375] |
0x1400c6c90 |
Dynamic API loader | GetModuleHandleA("kernelbase.dll") → GetProcAddress("SetThreadDescription"). ^[r2:fcn.1400c6c90] ^[strings.txt:1772–1773] |
Imports
WINHTTP.dll (WinHttpOpen, WinHttpCrackUrl, WinHttpSetOption, WinHttpConnect, WinHttpOpenRequest, WinHttpAddRequestHeaders, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpQueryHeaders, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpCloseHandle), bcrypt.dll (BCryptOpenAlgorithmProvider), KERNEL32.dll (CreateProcessA, GetProcAddress, GetModuleHandleA, GetTempPathA, GetStartupInfoA, GetCurrentProcessId, GetModuleFileNameA, CreatePipe, WaitForMultipleObjects, Sleep), ADVAPI32.dll (registry), api-ms-win-crt-* (stdio, heap, filesystem). ^[pefile.txt]
Signing
Unsigned. No authenticode, no Rich header. Timestamp 2026-05-27 10:39:38 UTC. ^[exiftool.json:15]
Deploy / ATT&CK
Initial Access
Dropped by gcleaner distribution infrastructure per OpenCTI label dropped-by-gcleaner. ^[triage.json]
Execution
- T1059.003 —
cmd.exe/whoami/tasklist /FO CSV /NHinvoked viaCreateProcessA+CreatePipe. ^[strings.txt:1422–1426] ^[r2:fcn.1400058e3] - T1106 —
CreateProcessAfor payload launch ("DEPLOY launched PID=%lu"). ^[strings.txt:1363] - T1053.005 —
schtasks /create /tn WindowsCacheTask /tr "..." /sc ONLOGON /f /rl HIGHEST. ^[strings.txt:1433] ^[procedures/schtasks-onlogon-persistence.md]
Persistence
- T1053.005 — Scheduled task
WindowsCacheTasktriggers at logon with highest privileges. Payload copies itself to%TEMP%\Microsoft\Windows\Caches\svchost.exe. ^[strings.txt:1430–1440] - T1547.001 —
unpersistcommand removes the task viaschtasks /delete /tn WindowsCacheTask /f. ^[strings.txt:1439]
Defense Evasion
- T1027.002 — AES payload decryption (
aesEncrypt,"Invalid AES key — using fallback"). ^[strings.txt:1380–1413]bcrypt.dllimported; likely CNG AES-GCM or AES-CBC. ^[pefile.txt] ^[techniques/bcrypt-aes-gcm-payload-decryption.md] - T1036.005 — Masquerades as
svchost.exein%TEMP%\Microsoft\Windows\Caches\. ^[strings.txt:1440] - T1036.004 — User-agent masquerade:
ValetGate/2.0 (Windows NT 10.0; Kiosk). ^[strings.txt] ^[r2:fcn.140002af4]
Discovery
- T1082 —
whoami,tasklist, system info gathered for C2 beacon. ^[strings.txt:1422–1424] - T1033 — Username and hostname in beacon JSON. ^[strings.txt:1368–1369]
Collection
- T1074.001 — Task results batched in JSON array and exfiltrated. ^[strings.txt:1376–1379]
- T1560 — AES encryption of outbound task results (
aesEncrypt). ^[strings.txt:1380]
C2 — Command & Control
- T1071.001 — HTTPS C2 to
https://pankebab.com. ^[strings.txt:1366] ^[r2:fcn.14000455a] - T1071.001 — REST API paths masqueraded as vehicle/valet operations:
GET /api/v1/vehicle/entry(beacon / check-in)POST /api/v1/vehicle/exit(task results / exfil)GET /api/v1/parking/spot/status(poll for new tasks) ^[strings.txt:1464–1466] ^[r2:fcn.14000455a]
- T1573.002 — Custom request header
X-Vehicle-ID. ^[strings.txt:1385] - T1001.002 — Stacked JSON fields:
agent_id,hostname,username,os,ip,pid,elevated,version,crash_log,results[]withtask_id,type,data. ^[strings.txt:1367–1379]
Exfiltration
Task results (results[]) returned via encrypted HTTPS POST. ^[strings.txt:1376–1380] ^[r2:fcn.140002af4]
Impact
- T1496 —
update,update-enc,deploy,deploy-enc,dexeccommands for secondary payload delivery and execution. ^[strings.txt:1442–1457] - T1490 — Self-update capability (
vg_upd.batbatch script for staged restart). ^[strings.txt:1341–1347]
Attribution
- Family: Tentatively
ValetGateper the hardcoded user-agent string and vehicle-themed C2 API paths. Confidence low — single sample, static-only, no CAPE detonation. Could be a custom build or a renamed open-source RAT. - Distribution: gcleaner multi-payload pipeline (OpenCTI
dropped-by-gcleaner). ^[triage.json] ^[entities/gcleaner.md] - Builder: MinGW-w64 GCC 15.2.0 on Windows (or cross-compiled from Linux). Timestamp 2026-05-27.
Static-only analysis. No CAPE detonation available. Dynamic inferences are conservative — runtime may reveal additional TTPs (e.g., registry writes, file drops, network resolution patterns).